123   3  /  3  页   跳转

svvedy57.sys文件有毒,但杀不了

[PID: 1184 / SYSTEM][C:\Program Files\CMBCHINA\WebProtect\WPService.exe]  [China Merchants Bank, 1, 0, 0, 1]
    [c:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.9]
    [c:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.4]
    [C:\Program Files\CMBCHINA\WebProtect\WebProtectPlus.dll]  [China Merchants Bank, 1, 0, 0, 1]
[PID: 256 / SYSTEM][C:\Program Files\10Moons\RemoteService\RS.exe]  [, 1, 0, 0, 1]
    [C:\Program Files\10Moons\RemoteService\TMRemote.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\10Moons\RemoteService\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
    [c:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.9]
    [c:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.4]
[PID: 2052 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [c:\program files\rising\rfw\ijt_base.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.9]
    [c:\program files\rising\rfw\olemon.dll]  [Beijing Rising Technology Co., Ltd., 7.0.0.4]
[PID: 2720 / Administrator][C:\Program Files\Rising\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 20.0.0.22]
    [C:\Program Files\Rising\Rav\ProcCom.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [C:\Program Files\Rising\Rav\RsCommX2.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 19]
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 16]
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 20.0.0.0]
    [C:\Program Files\Rising\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 20.0.0.10]
[PID: 2752 / Administrator][C:\PROGRA~1\10Moons\TTVMAS~1\TVTray.exe]  [, 1, 2, 0, 0]
    [C:\PROGRA~1\10Moons\TTVMAS~1\RtSmartComm.dll]  [N/A, ]
    [C:\PROGRA~1\10Moons\TTVMAS~1\MSVCP60.dll]  [Microsoft Corporation, 6.00.8972.0]
    [C:\PROGRA~1\10Moons\TTVMAS~1\TVTrayRsc.dll]  [, 1, 2, 0, 0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\Prop7134.dll]  [Philips Semiconductors, 2, 3, 1, 2]
[PID: 2768 / Administrator][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.34]
[PID: 2808 / Administrator][C:\WINDOWS\system32\CSPContext.exe]  [中文之星, 1, 0, 0, 1]
[PID: 2832 / Administrator][C:\WINDOWS\VM_STI.EXE]  [Vimicro, 4, 2, 1124, 6]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\Prop7134.dll]  [Philips Semiconductors, 2, 3, 1, 2]
    [C:\WINDOWS\system32\VM31bPrp.Ax]  [Vimicro, 1.00.01.00]
[PID: 2864 / Administrator][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe]  [GRISOFT s.r.o., 7, 5, 1, 43]
    [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll]  [GRISOFT s.r.o., 4, 2, 0, 19]
[PID: 2876 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2900 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3576 / Administrator][F:\TOOLS\系统\totalcmd\totalcmd\Totalcmd.exe]  [C. Ghisler & Co., 7.01]
    [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
[PID: 3996 / Administrator][D:\下载\sreng2\SREngPS.EXE]  [Smallfrogs Studio, 2.5.16.900]
    [D:\下载\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
[PID: 2200 / Administrator][F:\TOOLS\网络\GreenBrowser\GreenBrowser.exe]  [MoreQuick, 1, 0, 0, 0]
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 20, 0, 0, 3]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx]  [Adobe Systems, Inc., 9,0,45,0]
    [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\Program Files\Ringz Studio\Storm Codec\Codecs\VSFilter.dll]  [Gabest, 1, 0, 1, 3]
    [C:\Program Files\Ringz Studio\Storm Codec\Codecs\PmpSplt.ax]  [cooleyes, 1, 0, 0, 8]
    [C:\WINDOWS\system32\ffdshow.ax]  [, 1.0.2.2028]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
gototop
 

==================================
文件关联
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. ["hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 2752, C:\PROGRA~1\10MOONS\TTVMAS~1\TVTRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2200, F:\TOOLS\网络\GREENBROWSER\GREENBROWSER.EXE]

==================================
API HOOK
N/A

==================================
隐藏进程
N/A

==================================


[/CODE]
gototop
 

引用:
【天月来了的贴子】以附件形式发来
………………

来了

附件附件:

下载次数:92
文件类型:application/octet-stream
文件大小:
上传时间:2008-1-1 17:13:27
描述:

gototop
 

C:\Program Files\10Moons\RemoteService\RS.exe
是电视卡
[3sh / 3shs][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\3shs.sys><N/A>
[svvedy5 / svvedy57][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\svvedy57.sys><N/A>
这两项无法修改和删除
杀毒提示svvedy57有毒
gototop
 

用Xdelbox把其他的都删除了,就是svvedy57.sys仍在。郁闷!!!
gototop
 

"在扫日志的SRENG工具》启动项目》服务》驱动程序》里面找下面各项,将启动类型改为“Disabled”
[svvedy5 / svvedy57][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\svvedy57.sys><N/A>

然后重启电脑,再看效果怎样。

如果还不行,就再用Xdelbox重启删除C:\WINDOWS\System32\DRIVERS\svvedy57.sys"
没用的。
gototop
 
123   3  /  3  页   跳转
页面顶部
Powered by Discuz!NT