瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】无法清除Trojan.DL.Delf.bex!!!

1   1  /  1  页   跳转

【求助】无法清除Trojan.DL.Delf.bex!!!

【求助】无法清除Trojan.DL.Delf.bex!!!

5月12号中的毒,据说是线程插入技术哇,不添加自启动项、没有进程。
我用网络版查杀,每次能发现,但都说需要解压,既不能杀,又不能删。
查的时候虽然能发现在IE临时文件夹里,但进去连文件都找不到(系统、隐藏都显示了)!!!
最后编辑2006-05-20 13:05:55
分享到:
gototop
 

2006-05-18,19:24:01

System Repair Engineer 2.0.12.350 (2.0 RC 1)
    Windows XP Professional Service Pack 1 - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <DrvMon.exe><C:\WINDOWS\System32\DrvMon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NB Probe><C:\Program Files\ASUS\NB Probe\NBProbe.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <DAEMON Tools-1033><"D:\Program Files\D-Tools\daemon.exe"  -lang 1033>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NeroCheck><C:\WINDOWS\System32\\NeroCheck.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <InCD><D:\Program Files\Ahead\InCD\InCD.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <IntelZeroConfig><C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <EOUApp><C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RavTray><D:\Program Files\Rising\Rav\RavTray.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <PCSuiteTrayApplication><D:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <DataLayer><C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RavMon><D:\Program Files\Rising\Rav\RavMon.exe -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><C:\WINDOWS\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><>

==================================
启动文件夹
服务
[Apache / Apache]
  <"D:\Apache\Apache.exe" --ntservice><N/A>
[EvtEng / EvtEng]
  <C:\Program Files\Intel\Wireless\Bin\EvtEng.exe><Intel Corporation>
[InCD File System Service / InCDsrv]
  <D:\Program Files\Ahead\InCD\InCDsrv.exe><N/A>
[MySql / MySql]
  <D:/mysql/bin/mysqld-nt.exe><N/A>
[OwnershipProtocol / OwnershipProtocol]
  <C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe><Intel Corporation>
[RavService / RavService]
  <"D:\Program Files\Rising\Rav\RavService.exe" /service><Beijing Rising Technology Co., Ltd.>
[RegSrvc / RegSrvc]
  <C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe><Intel Corporation>
[Rising Process Communication Center / RsCCenter]
  <D:\Program Files\Rising\Rav\CCenter.exe><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <D:\PROGRAM FILES\RISING\RAV\Ravmond.exe><Beijing Rising Technology Co., Ltd.>
[Spectrum24 Event Monitor / S24EventMonitor]
  <C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe><Intel Corporation >
[spmgr / spmgr]
  <C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe><>

==================================
gototop
 

浏览器加载项
[Adobe PDF Reader Link Helper]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[NTIECatcher Class]
  {C56CB6B0-0D96-11D6-8C65-B2868B609932} <D:\Program Files\NetTransport\NTIEHelper.dll, Xi>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[WebActivater Control]
  {3D8F74EE-8692-4F8F-B8D2-7522E732519E} <C:\WINDOWS\System32\WEBACT~1.OCX, QQ>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\macromed\flash\Flash.ocx, Macromedia, Inc.>
[上传到QQ网络硬盘]
  <D:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用影音传送带下载]
  <D:\Program Files\NetTransport\NTAddLink.html, N/A>
[使用影音传送带下载全部链接]
  <D:\Program Files\NetTransport\NTAddList.html, N/A>
[添加到QQ自定义面板]
  <D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 840][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 924][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 948][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\Program Files\Intel\Wireless\Bin\LgNotify.dll]  <Intel Corporation><9, 0, 2, 11>
[PID: 992][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1004][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
    [C:\WINDOWS\System32\wa_api60.dll]  <N/A><N/A>
[PID: 1172][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\System32\wa_api60.dll]  <N/A><N/A>
[PID: 1236][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
    [C:\WINDOWS\System32\wa_api60.dll]  <N/A><N/A>
[PID: 1272][C:\Program Files\Intel\Wireless\Bin\EvtEng.exe]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
[PID: 1448][C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe]  <Intel Corporation ><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
[PID: 1688][C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\MurocApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\C1XStngs.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  <N/A><N/A>
    [C:\Program Files\Intel\Wireless\Bin\C8021CHS.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\LSAWRAPI.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\ZcSvcCHS.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL]  <N/A><N/A>
[PID: 1724][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1808][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2800.1106 (xpsp1.020828-1920)>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><7.0.7.2006011200>
    [D:\Program Files\NetTransport\NTIEHelper.dll]  <Xi><1.60.11>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
[PID: 1848][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 2012][C:\WINDOWS\System32\conime.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 476][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  <Windows (R) 2000 DDK provider><5.00.2195.1620>
[PID: 748][C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe]  <Intel><9, 0, 2, 11>
    [C:\PROGRA~1\Intel\Wireless\Bin\IntelAE5.dll]  <Meetinghouse Data Communications><3, 0, 0, 60>
    [C:\PROGRA~1\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
    [C:\PROGRA~1\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL]  <N/A><N/A>
[PID: 828][D:\Program Files\Ahead\InCD\InCD.exe]  <Ahead Software AG><4, 0, 0, 37>
    [D:\Program Files\Ahead\InCD\InCDapi.dll]  <N/A><N/A>
    [D:\Program Files\Ahead\InCD\InCDunt.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Ahead\Lib\DriveLocker.dll]  <Ahead Software AG><1, 0, 0, 8>
    [D:\Program Files\Ahead\InCD\incdshx.dll]  <Ahead Software, Karlsbad, Germany><4, 0, 0, 37>
[PID: 864][C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\EOUAPCfg.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\ownprot.DLL]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\MurocApi.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\C1XStngs.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  <N/A><N/A>
    [C:\Program Files\Intel\Wireless\Bin\C8021CHS.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\LSAWRAPI.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\EOUWzCHS.dll]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL]  <N/A><N/A>
[PID: 1260][D:\Program Files\Rising\Rav\RavTray.exe]  <Rising><17, 0, 0, 32>
    [D:\Program Files\Rising\Rav\RavTray936.dll]  <Rising><17, 0, 0, 28>
    [D:\Program Files\Rising\Rav\RsCommx.dll]  <rising><17, 0, 0, 3>
[PID: 1304][D:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe]  <Nokia><6, 41, 22, 3>
    [D:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll]  <Nokia><6, 41, 22, 0>
    [D:\Program Files\Nokia\Nokia PC Suite 6\PCSL.dll]  <Nokia><6, 41, 3, 0>
    [D:\Program Files\Nokia\Nokia PC Suite 6\Lang\LaunchApplication2_chi-sc.NLR]  <><6, 41, 4, 0>
    [C:\Program Files\Common Files\PCSuite\ConfServer\ConfServer.dll]  <Nokia><6, 41, 6, 0>
    [C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll]  <Design Science, Inc.><2004.8.26.0  >
[PID: 1312][C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE]  <Nokia Mobile Phones Ltd.><6, 41, 85, 8>
    [C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\Lang\DataLayer_chi-sc.nlr]  <Nokia><6, 41, 5, 0>
    [C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll]  <Design Science, Inc.><2004.8.26.0  >
[PID: 1660][C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE]  <Nokia.><6, 41, 20, 0>
    [C:\Program Files\Common Files\PCSuite\Transports\NCLIrDAMM.dll]  <Nokia Corp.><6, 41, 11, 0>
    [C:\Program Files\Common Files\PCSuite\Transports\NclTools.dll]  <Nokia.><6, 41, 5, 1>
    [C:\Program Files\Common Files\PCSuite\Transports\NCLRSMM.dll]  <Nokia><6, 41, 15, 0>
    [C:\Program Files\Common Files\PCSuite\Transports\NCLUSBMM.dll]  <Nokia><6, 41, 17, 0>
    [C:\WINDOWS\System32\wa_api60.dll]  <N/A><N/A>
[PID: 336][D:\Program Files\Rising\Rav\RavMon.exe]  <Beijing Rising Technology Co., Ltd.><17, 0, 1, 39>
    [D:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 40>
    [D:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Rising Corp.><17, 0, 0, 7>
    [D:\Program Files\Rising\Rav\CfgDll.dll]  <Rising Corp.><17, 0, 1, 71>
    [D:\Program Files\Rising\Rav\RsCommX.dll]  <rising><17, 0, 0, 3>
[PID: 348][C:\WINDOWS\System32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 440][D:\Program Files\Ahead\InCD\InCDsrv.exe]  <N/A><N/A>
    [D:\Program Files\Ahead\InCD\InCDunt.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Ahead\Lib\DriveLocker.dll]  <Ahead Software AG><1, 0, 0, 8>
    [D:\Program Files\Ahead\InCD\incdshx.dll]  <Ahead Software, Karlsbad, Germany><4, 0, 0, 37>
[PID: 464][C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  <N/A><N/A>
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  <Intel Corporation><9, 0, 2, 11>
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  <Intel Corporation><9, 0, 2, 11>
[PID: 580][D:\Program Files\Rising\Rav\RavService.exe]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 73>
    [D:\Program Files\Rising\Rav\RsCommX.dll]  <rising><17, 0, 0, 3>
    [C:\WINDOWS\System32\wa_api60.dll]  <N/A><N/A>
[PID: 1356][C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe]  <Intel Corporation><9, 0, 2, 11>
[PID: 1380][C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe]  <><1, 0, 0, 1>
    [C:\Program Files\ASUS\NB Probe\SPM\spdisk.dll]  <N/A><N/A>
    [C:\Program Files\ASUS\NB Probe\SPM\DiscMan.dll]  <N/A><N/A>
    [C:\Program Files\ASUS\NB Probe\SPM\spos.dll]  <N/A><N/A>
    [C:\Program Files\ASUS\NB Probe\SPM\spnbacpi.dll]  <N/A><N/A>
[PID: 1396][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1424][C:\WINDOWS\System32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 3048][C:\WINDOWS\System32\wbem\wmiprvse.exe]  <Microsoft Corporation><5.1.2600.1106 (xpsp1.020828-1920)>
[PID: 2052][J:\sreng2\SREng.exe]  <Smallfrogs Studio><2.0.12.350>
    [C:\WINDOWS\System32\wa_api60.dll]  <N/A><N/A>

==================================
gototop
 

文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  Error. ["D:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" "%1"]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD Tcpip [UDP/IP]
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD Tcpip [RAW/IP]
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
RSVP UDP Service Provider
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
RSVP TCP Service Provider
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD nwlnkipx [IPX]
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD nwlnkspx [SPX]
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD nwlnkspx [SPX] [Pseudo Stream]
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD nwlnkspx [SPX II]
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD nwlnkspx [SPX II] [Pseudo Stream]
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NwlnkNb] SEQPACKET 5
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NwlnkNb] DATAGRAM 5
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{9318E461-5CDB-4ED4-839B-64132E3A4C49}] SEQPACKET 8
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{9318E461-5CDB-4ED4-839B-64132E3A4C49}] DATAGRAM 8
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{EF759B40-CB4A-449B-A723-AAEE28240DD8}] SEQPACKET 0
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{EF759B40-CB4A-449B-A723-AAEE28240DD8}] DATAGRAM 0
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{93535B24-A91F-49C2-9242-04CF48FFAA04}] SEQPACKET 1
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{93535B24-A91F-49C2-9242-04CF48FFAA04}] DATAGRAM 1
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{472A6565-133A-4DBA-B882-37C7920472C6}] SEQPACKET 4
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{472A6565-133A-4DBA-B882-37C7920472C6}] DATAGRAM 4
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E76843B6-C120-416B-9AA2-FDEE2B30D620}] SEQPACKET 2
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E76843B6-C120-416B-9AA2-FDEE2B30D620}] DATAGRAM 2
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7EA4F0BC-4279-4AF8-888A-2F30EBFD9CD3}] SEQPACKET 3
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7EA4F0BC-4279-4AF8-888A-2F30EBFD9CD3}] DATAGRAM 3
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{F0B0D01D-D8CD-41B8-8321-388858E344C3}] SEQPACKET 6
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{F0B0D01D-D8CD-41B8-8321-388858E344C3}] DATAGRAM 6
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{F0039432-0C4C-4A9E-931E-8585C50749A2}] SEQPACKET 7
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD NetBIOS [\Device\NetBT_Tcpip_{F0039432-0C4C-4A9E-931E-8585C50749A2}] DATAGRAM 7
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)
MSAFD Irda [IrDA]
    C:\WINDOWS\System32\wa_api60.dll(N/A, N/A)

==================================
gototop
 

把临时文件都删除后查毒查不到了
但是瑞星的监控还是不行,绿伞还是出不来
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT