12345   3  /  5  页   跳转

病毒病毒啊!!!!!高手看下

PID: 1660][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
[PID: 1752][C:\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1972][C:\WINDOWS\system32\Ati2evxx.exe]  <ATI Technologies Inc.><6.14.10.4117>
    [C:\WINDOWS\system32\Ati2edxx.dll]  <ATI Technologies, Inc.><6, 14, 10, 2497>
[PID: 184][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 180][C:\Program Files\LEGEND\联想遥控器驱动\Remdrv.exe]  <N/A><N/A>
    [C:\Program Files\LEGEND\联想遥控器驱动\Remoted.dll]  <N/A><N/A>
    [C:\Program Files\LEGEND\联想遥控器驱动\XPNyGet.dll]  <N/A><N/A>
[PID: 1232][C:\WINDOWS\soundman.exe]  <Avance Logic, Inc.><5, 0, 0, 0>
[PID: 1276][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe]  <ATI Technologies, Inc.><6.14.10.5157>
    [C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll]  <ATI Technologies, Inc.><6.14.10.5157>
    [C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS]  <ATI Technologies, Inc.><6.14.10.5157>
    [C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll]  <ATI Technologies, Inc.><6.14.10.5157>
[PID: 1284][C:\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
    [C:\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
[PID: 1296][C:\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 30>
    [C:\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [C:\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1304][D:\cjjb\SysExplr.EXE]  <N/A><N/A>
    [D:\cjjb\HttpReq.dll]  <N/A><N/A>
    [D:\cjjb\CoolMenu.dll]  <N/A><N/A>
    [D:\cjjb\httphlp.dll]  <N/A><N/A>
    [D:\cjjb\AVCDROM.dll]  <N/A><N/A>
    [D:\cjjb\Sys936.DLL]  <N/A><N/A>
[PID: 1984][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 720][C:\happyhome\幸福飞梭\FlyShuttle.exe]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\CLxUI.dll]  <联想(北京)有限公司><1, 0, 0, 1>
    [C:\WINDOWS\system32\klhome.dll]  <><1, 0, 0, 1>
    [C:\happyhome\幸福飞梭\FlyUI.ui]  <联想(北京)有限公司 ><1, 0, 0, 1>
    [C:\happyhome\幸福飞梭\SKOSD.DLL]  <Silitek Corp.><1, 0, 6, 0>
    [C:\happyhome\幸福飞梭\SKUtil.DLL]  <Silitek Corp.><1, 0, 9, 0>
    [C:\happyhome\幸福飞梭\uiresource.dll]  <><1, 0, 0, 1>
[PID: 428][C:\Program Files\LEGEND\联想标准功能键盘驱动程序安装\Skdaemon.exe]  <><1, 0, 0, 1>
    [C:\Program Files\LEGEND\联想标准功能键盘驱动程序安装\MacFun.dll]  <Silitek><1, 0, 0, 0>
    [C:\Program Files\LEGEND\联想标准功能键盘驱动程序安装\OpenDriver.dll]  <Silitek><1, 0, 0, 0>
    [C:\Program Files\LEGEND\联想标准功能键盘驱动程序安装\OSD.dll]  <silitek><1, 0, 0, 1>
    [C:\WINDOWS\system32\lxkeyled.dll]  <Silitek><1, 0, 0, 1>
[PID: 1588][C:\happyhome\幸福飞梭\lxswitch.exe]  <><1, 0, 0, 1>
[PID: 1912][C:\WINDOWS\system32\nvsvc32.exe]  <NVIDIA Corporation><5.13.01.1520>
[PID: 1992][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 2520][C:\Program Files\ChinaNetSn\bin\Dialterminal.exe]  <西安信利软件科技有限公司><0, 0, 1, 6>
    [C:\Program Files\ChinaNetSn\bin\packet.dll]  <Politecnico di Torino><3, 0, 0, 18>
    [C:\Program Files\ChinaNetSn\bin\Sendarp.dll]  <N/A><N/A>
    [C:\Program Files\ChinaNetSn\bin\detector.dll]  <西安信利软件系统有限公司><1, 0, 0, 2>
    [C:\Program Files\ChinaNetSn\bin\wpcap.dll]  <Politecnico di Torino><3, 0, 0, 18>
    [C:\WINDOWS\system32\pthreadVC.dll]  <N/A><N/A>
    [C:\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 4020][D:\bitcomet\BitComet.exe]  <www.BitComet.com><0.70>
    [C:\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 1676][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
[PID: 3652][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
gototop
 

[C:\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
    [C:\WINDOWS\system32\PNCRT.dll]  <Real Networks, Inc><6.0.0.0>
    [C:\Program Files\Common Files\Real\Common\pnrs3260.dll]  <RealNetworks, Inc.><6.0.9.3985>
    [C:\WINDOWS\system32\rmoc3260.dll]  <RealNetworks, Inc.><6.0.9.2237>
    [D:\real\rpplugins\embd3260.dll]  <RealNetworks, Inc.><6.0.12.1348>
    [C:\Program Files\Common Files\Real\Common\pngu3267.dll]  <RealNetworks, Inc.><6.7.0.2629>
    [C:\Program Files\Common Files\Real\Common\objb3201.dll]  <RealNetworks, Inc.><0.1.0.6244>
    [D:\real\rpplugins\rpcl3260.dll]  <RealNetworks, Inc.><6.0.9.3027>
    [D:\real\rpplugins\rput3260.dll]  <RealNetworks, Inc.><6.0.9.3005>
    [C:\Program Files\Common Files\Real\Common\pnen3260.dll]  <RealNetworks, Inc.><10.0.0.895>
    [C:\Program Files\Common Files\Real\Plugins\zipf3260.dll]  <RealNetworks, Inc.><6.0.8.2469>
    [C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll]  <RealNetworks, Inc.><10.1.0.795>
    [C:\Program Files\Common Files\Real\Plugins\vidsite.dll]  <RealNetworks, Inc.><10.0.0.868>
    [C:\Program Files\Common Files\Real\Plugins\clntxres.dll]  <RealNetworks, Inc.><10.0.0.3446>
    [D:\real\lang\cdplay_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\dbcomp_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\embed_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\gemctl_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\pngui_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\pdgenxfer_cn.dll]  <N/A><N/A>
    [D:\real\lang\rjctl_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rjeq_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rjres_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rjskin_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rjviz_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rjfade_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rjdlg_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rjmisc_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rjprog_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rpapp_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rpclsvc_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rpclutil_cn.dll]  <RealNetworks, Inc.><6.0.12.299>
    [D:\real\lang\rpdemand_cn.dll]  <RealNetworks, Inc.><6.0.12.299>
    [D:\real\lang\rpdsplyr_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rpgutil_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rpmnpane_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rpplylst_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\rpwebctl_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\tcdinfo_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\tclsvc_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\tdwnmgr_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\tmp3_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\twave_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\teasdk_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\tearm_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\tmdedit_cn.dll]  <RealNetworks, Inc.><6.0.12.298>
    [D:\real\lang\mydevices_cn.dll]  <RealNetworks, Inc.><6.0.12.299>
    [C:\Program Files\Common Files\Real\Plugins\memfsys.dll]  <RealNetworks, Inc.><10.0.0.855>
    [C:\Program Files\Common Files\Real\Plugins\authmgr.dll]  <RealNetworks, Inc.><10.0.0.1317>
    [C:\Program Files\Common Files\Real\Codecs\hxltcolor.dll]  <RealNetworks, Inc.><10.0.0.725>
    [C:\Program Files\Common Files\Real\Plugins\ramfformat.dll]  <RealNetworks, Inc.><10.0.0.2111>
    [D:\real\rpplugins\rpap3260.dll]  <RealNetworks, Inc.><6.0.9.2954>
    [C:\Program Files\Common Files\Real\Plugins\ramrender.dll]  <RealNetworks, Inc.><10.0.0.1777>
    [C:\Program Files\Common Files\Real\Plugins\httpfsys.dll]  <RealNetworks, Inc.><10.0.0.2668>
    [C:\Program Files\Common Files\Real\Plugins\rmfformat.dll]  <RealNetworks, Inc.><10.0.0.1089>
    [C:\Program Files\Common Files\Real\Plugins\rarender.dll]  <RealNetworks, Inc.><10.0.0.874>
    [C:\Program Files\Common Files\Real\Codecs\cook.dll]  <RealNetworks, Inc.><10.0.0.1625>
    [C:\Program Files\Common Files\Real\Plugins\rvrender.dll]  <RealNetworks, Inc.><10.0.0.1259>
    [C:\Program Files\Common Files\Real\Codecs\RV40.DLL]  <RealNetworks, Inc.><10.0.0.1355>
    [C:\Program Files\Common Files\Real\Codecs\drvc.dll]  <RealNetworks, Inc.><10.0.0.1355>
[PID: 2252][D:\dl\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
gototop
 

扫描好了,看下!!!!
gototop
 

........
gototop
 

来看下啊
gototop
 

引用:
【我的疑问的贴子】O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll

加群我帮你.LSP-FIX删不掉.
...........................

这个我已经删掉了啊
gototop
 

....有没有人来看啊 ??
gototop
 

扫描的日志在第二页,帮忙看下啊
gototop
 

引用:
【我无邪的贴子】关闭所有浏览窗口以及一些不必要的程序
运行(双击)System Repair Engineer,使用“系统修复,浏览器加载项”来删除以下选项。
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4612.dll
C:\WINDOWS\YayaBands.dll
C:\WINDOWS\Downloaded Program Files\safein.dll
C:\WINDOWS\system32\NaviHelper.dll
C:\WINDOWS\system32\AdsObj.dll
C:\WINDOWS\system32\AdsHlp2.dll
C:\WINDOWS\system32\lxCal.dll
重启后删除
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4612.dll
C:\WINDOWS\YayaBands.dll
C:\WINDOWS\Downloaded Program Files\safein.dll
C:\WINDOWS\system32\NaviHelper.dll
C:\WINDOWS\system32\AdsObj.dll
C:\WINDOWS\system32\AdsHlp2.dll
C:\WINDOWS\system32\lxCal.dll
...........................

其他都删掉了,就C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4612.dll这个死活删不掉.安全模式也进去删过了,显示删除成功,再扫描一次还在的.怎么办啊????
gototop
 

已经在安全模式删过了
文件夹里找不到这个文件
gototop
 
12345   3  /  5  页   跳转
页面顶部
Powered by Discuz!NT