我公司有个 cfgnetmeeting.exe ,这大便出血是什么原因软件啊?

我要问题描述
查看: 4783|回复: 13
还不知道是什么病毒
UID: 56463
论坛新人, 积分 0, 距离下一级还需 50 积分
瑞星杀毒软件可以打开,但是无法启动杀毒功能;卡卡助手的防护功能全部被关闭;并且,瑞星及卡卡助手是设定为开机自动运行的,但是开机无法运行,人工可以启动;流氓软件清理助手、冰刃和网上下载的专杀工具等软件也无法启动;按ctrl+alt+del进程无法显示;想进入安全模式就蓝屏,关机时候后台运行程序无法结束,只能强行关机;C:\\Documents and Settings\\账户文件夹下很快生成大量__rar_00.000(后缀名为序列号)的垃圾文件,很快就把C盘的剩余空间占据完,其中有个“聚友娱乐视频棋牌”的连接网络游戏删除后重启就会再次出来,QQ在关闭的情况下提示过一次出现盗号木马。请各位朋友支招,怎么解决?
UID: 105292
在安全模式下用
机器狗/AV终结者/磁碟机专杀
WINDOWS清理助手一次用下
thunder://QUFodHRwOi8veHVubGVpMTEuZ3JlZW5kb3duLmNuLy8yMDA5MDEvYXJzd3AyLnppcFpa
打得开杀软后就开杀软清。。。。。
最后可以用下SRENG修复下。。。。。
UID: 56463
论坛新人, 积分 0, 距离下一级还需 50 积分
谢谢!可是现在安全模式无法进入啊!而且清理助手这些软件根本无法启动。[s:476]
UID: 105292
在正常模式下操作~
下载附件SRENG2
修复下安全模式
13:37 上传
点击文件名下载附件
844 KB, 下载次数: 1
UID: 56463
论坛新人, 积分 0, 距离下一级还需 50 积分
还是无法解决,进入安全模式就蓝屏,修复后一样出问题,提示信息如下:
STOP:0××F78A2524,0×C××)
正常启动机器,用《机器狗/AV终结者/磁碟机专杀》查出问题,但是提示重启电脑,重启了几次还是不行,不过这次可以启动《冰刃》了,从冰刃里面可以看到进程里面有N多个RAR.EXE的进程在同时进行,估计C:\Documents and Settings\个人账户下的多个临时莫名生成的_rar文件就是那多个进程干的。瑞星的防护全部被关闭,并且无法重新开启。现在只是用冰刃把那些垃圾文件暂时清理掉了,不然C盘根本就没用空间来运行了。下面是sreng的报告
因为回帖支持不了那么大的字节,另外发上来
UID: 56463
论坛新人, 积分 0, 距离下一级还需 50 积分
SRENG报告:
System Repair Engineer 2.7.0.1210
Smallfrogs ()
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
Winsock 提供者
Autorun.inf
HOSTS 文件
进程特权扫描
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
&ctfmon.exe&&C:\WINDOWS\system32\ctfmon.exe&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
&DAEMON Tools-1033&&&C:\Program Files\D-Tools\daemon.exe&-lang 1033&[DAEMON'S HOME]
&RavTray&&&C:\Program Files\Rising\Rav\RsTray.exe& -system&[(Verified)Beijing Rising Information Technology Corporation Limited]
&RFWTray&&&C:\Program Files\Rising\Rfw\RsTray.exe& -system&[(Verified)Beijing Rising Information Technology Corporation Limited]
&NvCplDaemon&&RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&[(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
&gem&&C:\WINDOWS\TEMP\sv1D.tmp&[File is missing]
&Alcmtr&&anymie360.exe&[]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
&shell&&Explorer.exe&[(Verified)Microsoft Windows Component Publisher]
&Userinit&&C:\WINDOWS\system32\userinit.exe,&[]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
&AppInit_DLLs&&sinx32.dll,nlokehnb.dll,pinklije.dll,ajbhhfcb.dll,jmpelhic.dll,mlepbfai.dll,ohgechff.dll,dlemkhjl.dll,kdcbbjlo.dll,dkkjlcnk.dll,ebofckaf.dll,jpdblkka.dll,gagpjmck.dll,igbfbncn.dll,cmoihiah.dll,miipocgb.dll,choijnpg.dll,cmdgknbe.dll,ningdeid.dll&[N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
&UIHost&&logonui.exe&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
&{AEB-11d0-97EE-00C04FD91972}&&shell32.dll&[(Verified)Microsoft Windows Component Publisher]
&{32CD708B-60A7-4C00-9377-D73EAA495F0F}&&C:\WINDOWS\system32\RavExt.dll&[(Verified)Beijing Rising Information Technology Corporation Limited]
&{7584E17B-D544-4A20-8687-EE5BD54B2036}&&C:\WINDOWS\system32\nlokehnb.dll&[File is missing]
&{9274523E-C31A-499F-A4D9-80F84CA1487D}&&C:\WINDOWS\system32\pinklije.dll&[]
&{A3B11FCB-8A40-84F2D2FB3F}&&C:\WINDOWS\system32\ajbhhfcb.dll&[]
&{369E512C-7DF0--ADC9AAA8C39C}&&C:\WINDOWS\system32\jmpelhic.dll&[]
&{65E9BFA2-B86B-4004-84BB-28FD40055A71}&&C:\WINDOWS\system32\mlepbfai.dll&[]
&{810EC1FF-9FC7-4CB5-A77F-721A0AEA958F}&&C:\WINDOWS\system32\ohgechff.dll&[]
&{D5E-CCAFE18A140}&&C:\WINDOWS\system32\dlemkhjl.dll&[]
&{4DCBB358-FEB9-45C9-B825-F8}&&C:\WINDOWS\system32\kdcbbjlo.dll&[]
&{D4435C74-EF1D-}&&C:\WINDOWS\system32\dkkjlcnk.dll&[]
&{EB8FC4AF-8EF8-}&&C:\WINDOWS\system32\ebofckaf.dll&[]
&{39DB544A-57C0-4F0F-9A12-C9B2A447C6D3}&&C:\WINDOWS\system32\jpdblkka.dll&[]
&{0AB75-47F7-ED22A5}&&C:\WINDOWS\system32\gagpjmck.dll&[]
&{20BFB7C7-7E80-4CA1-84E8-EF7C0BC7D237}&&C:\WINDOWS\system32\igbfbncn.dll&[]
&{CAF--B}&&C:\WINDOWS\system32\cmoihiah.dll&[]
&{62298C0B-A2E7-49F0-A5C1-1B54ED49D77A}&&C:\WINDOWS\system32\miipocgb.dll&[]
&{C1823790-BFE3-4ECB-92A1-C2A3A385CF12}&&C:\WINDOWS\system32\choijnpg.dll&[]
&{C6D047BE-AC40-4FB7-8AAF-22F2336ECCE3}&&C:\WINDOWS\system32\cmdgknbe.dll&[]
&{08-427D-8096-B4BAD0DF0784}&&C:\WINDOWS\system32\ningdeid.dll&[]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
&PostBootReminder&&%SystemRoot%\system32\SHELL32.dll&[(Verified)Microsoft Windows Component Publisher]
&CDBurn&&%SystemRoot%\system32\SHELL32.dll&[(Verified)Microsoft Windows Component Publisher]
&WebCheck&&%SystemRoot%\system32\webcheck.dll&[(Verified)Microsoft Windows Publisher]
&SysTray&&C:\WINDOWS\system32\stobject.dll&[(Verified)Microsoft Windows Publisher]
&DFB0160B&&&[N/A]
&DB02069D&&&[N/A]
&E2AFA318&&&[N/A]
&160D1B7F&&&[N/A]
&6556578A&&&[N/A]
&8CB8874E&&&[N/A]
&3742B0AA&&&[N/A]
&9ACC42A3&&&[N/A]
&A638696A&&&[N/A]
&47997C9F&&&[N/A]
&2FCD281F&&&[N/A]
&C903590D&&&[N/A]
&B43F1EF8&&&[N/A]
&D6667E4E&&&[N/A]
&B9D927A6&&&[N/A]
&52D7D9B4&&&[N/A]
&F709823B&&&[N/A]
&558CA071&&&[N/A]
&DF2F84A2&&&[N/A]
&5CA030AB&&&[N/A]
&8BCF1530&&&[N/A]
&B16160DF&&&[N/A]
&DBEBD293&&&[N/A]
&34502BF3&&&[N/A]
&8ECA0AA8&&&[N/A]
&68DA561D&&&[N/A]
&4E1758CC&&&[N/A]
&26DBD8AA&&&[N/A]
&5B61DE76&&&[N/A]
&1D19B7A9&&&[N/A]
&08FE6604&&&[N/A]
&ED67CA2D&&&[N/A]
&4272BA3F&&&[N/A]
&ED4A94FB&&&[N/A]
&0AF7FD9D&&&[N/A]
&2E13CE81&&&[N/A]
&04C350EC&&&[N/A]
&DB0A2648&&&[N/A]
&3BDAB254&&&[N/A]
&81326D8B&&&[N/A]
&A4EFEA80&&&[N/A]
&D912AB11&&&[N/A]
&F6578688&&&[N/A]
&CEE9DBB8&&&[N/A]
&5195014E&&&[N/A]
&ADC9A95F&&&[N/A]
&B83B19C5&&&[N/A]
&93E5ED84&&&[N/A]
&F1357F59&&&[N/A]
&2DC73C12&&&[N/A]
&E037A793&&&[N/A]
&C9D535F6&&&[N/A]
&C44505EA&&&[N/A]
&7584E17B&&C:\WINDOWS\system32\nlokehnb.dll&[File is missing]
&9274523E&&C:\WINDOWS\system32\pinklije.dll&[]
&A3B11FCB&&C:\WINDOWS\system32\ajbhhfcb.dll&[]
&369E512C&&C:\WINDOWS\system32\jmpelhic.dll&[]
&65E9BFA2&&C:\WINDOWS\system32\mlepbfai.dll&[]
&810EC1FF&&C:\WINDOWS\system32\ohgechff.dll&[]
&D5E64135&&C:\WINDOWS\system32\dlemkhjl.dll&[]
&4DCBB358&&C:\WINDOWS\system32\kdcbbjlo.dll&[]
&D4435C74&&C:\WINDOWS\system32\dkkjlcnk.dll&[]
&EB8FC4AF&&C:\WINDOWS\system32\ebofckaf.dll&[]
&39DB544A&&C:\WINDOWS\system32\jpdblkka.dll&[]
&0A0936C4&&C:\WINDOWS\system32\gagpjmck.dll&[]
&20BFB7C7&&C:\WINDOWS\system32\igbfbncn.dll&[]
&C68212A1&&C:\WINDOWS\system32\cmoihiah.dll&[]
&62298C0B&&C:\WINDOWS\system32\miipocgb.dll&[]
&C1823790&&C:\WINDOWS\system32\choijnpg.dll&[]
&C6D047BE&&C:\WINDOWS\system32\cmdgknbe.dll&[]
&7270DE2D&&C:\WINDOWS\system32\ningdeid.dll&[]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
&WinlogonNotify: crypt32chain&&crypt32.dll&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
&WinlogonNotify: cryptnet&&cryptnet.dll&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
&WinlogonNotify: cscdll&&cscdll.dll&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
&WinlogonNotify: ScCertProp&&wlnotify.dll&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
&WinlogonNotify: Schedule&&wlnotify.dll&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
&WinlogonNotify: sclgntfy&&sclgntfy.dll&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
&WinlogonNotify: SensLogn&&WlNotify.dll&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
&WinlogonNotify: termsrv&&wlnotify.dll&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
&WinlogonNotify: wlballoon&&wlnotify.dll&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
&{-A8BA-11D1-B96B-00A0C90312E1}&&%SystemRoot%\system32\browseui.dll&[(Verified)Microsoft Windows Component Publisher]
&{8C7461EF-2B13-11d2-BE35-0}&&%SystemRoot%\system32\browseui.dll&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\&{22d6f312-b0f6-11d0-94ab-e95}]
&Microsoft Windows Media Player&&C:\WINDOWS\inf\unregmp2.exe /ShowWMP&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\&{d38-484f-9b9e-dec}]
&Internet Explorer&&%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE&[File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\&{60B49E34-C7CC-11D0-C90347FF}MICROS]
&浏览器自定义组件&&RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\&{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
&Outlook Express&&%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE&[File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09--FED}]
&Themes Setup&&%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll&[File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
&Microsoft Outlook Express 6&&&%ProgramFiles%\Outlook Express\setup50.exe& /APP:OE /CALLER:WINNT /user /install&[File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
&NetMeeting 3.01&&rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{e7d-11d1-bc44-00c04fd912be}]
&Windows Messenger 4.7&&rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
&Microsoft Windows Media Player&&rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{71-11d2-AF11-00C04FA35D02}]
&通讯簿 6&&&%ProgramFiles%\Outlook Express\setup50.exe& /APP:WAB /CALLER:WINNT /user /install&[File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{-ECBD-11cf-8B85-00AA005B4340}]
&Windows 桌面更新&&regsvr32.exe /s /n /i:U shell32.dll&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{-ECBD-11cf-8B85-00AA005B4383}]
&Internet Explorer 6&&%SystemRoot%\system32\ie4uinit.exe&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe]
&IFEO[360rpt.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.exe]
&IFEO[360Safe.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe]
&IFEO[360safebox.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe]
&IFEO[360tray.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adam.exe]
&IFEO[adam.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AgentSvr.exe]
&IFEO[AgentSvr.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiArp.exe]
&IFEO[AntiArp.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppSvc32.exe]
&IFEO[AppSvc32.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\arswp.exe]
&IFEO[arswp.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AST.exe]
&IFEO[AST.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe]
&IFEO[autoruns.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe]
&IFEO[avcenter.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe]
&IFEO[avconsol.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe]
&IFEO[avgnt.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrssvc.exe]
&IFEO[avgrssvc.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.exe]
&IFEO[AvMonitor.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution ]
&]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe]
&IFEO[avp.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe]
&IFEO[CCenter.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe]
&IFEO[ccSvcHst.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DrvAnti.exe]
&IFEO[DrvAnti.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EGHOST.exe]
&IFEO[EGHOST.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileDsty.exe]
&IFEO[FileDsty.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\filemon.exe]
&IFEO[filemon.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FTCleanerShell.exe]
&IFEO[FTCleanerShell.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FYFireWall.exe]
&IFEO[FYFireWall.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GFRing3.exe]
&IFEO[GFRing3.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GFUpd.exe]
&IFEO[GFUpd.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe]
&IFEO[HijackThis.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword.exe]
&IFEO[IceSword.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iparmo.exe]
&IFEO[iparmo.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.exe]
&IFEO[Iparmor.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\isPwdSvc.exe]
&IFEO[isPwdSvc.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kabaload.exe]
&IFEO[kabaload.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASMain.exe]
&IFEO[KASMain.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASTask.exe]
&IFEO[KASTask.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAV32.exe]
&IFEO[KAV32.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVDX.exe]
&IFEO[KAVDX.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPF.exe]
&IFEO[KAVPF.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPFW.exe]
&IFEO[KAVPFW.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVSetup.exe]
&IFEO[KAVSetup.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVStart.exe]
&IFEO[KAVStart.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KISLnchr.exe]
&IFEO[KISLnchr.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMailMon.exe]
&IFEO[KMailMon.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMFilter.exe]
&IFEO[KMFilter.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32.exe]
&IFEO[KPFW32.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32X.exe]
&IFEO[KPFW32X.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPfwSvc.exe]
&IFEO[KPfwSvc.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Kregex.exe]
&IFEO[Kregex.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution ]
&]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KsLoader.exe]
&IFEO[KsLoader.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvDetect.exe]
&IFEO[KvDetect.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvfwMcl.exe]
&IFEO[KvfwMcl.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvol.exe]
&IFEO[kvol.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvolself.exe]
&IFEO[kvolself.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVSrvXP.exe]
&IFEO[KVSrvXP.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvupload.exe]
&IFEO[kvupload.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvwsc.exe]
&IFEO[kvwsc.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP.kxp]
&IFEO[KvXP.kxp]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch.exe]
&IFEO[KWatch.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch9x.exe]
&IFEO[KWatch9x.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatchX.exe]
&IFEO[KWatchX.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MagicSet.exe]
&IFEO[MagicSet.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcconsol.exe]
&IFEO[mcconsol.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McNASvc.exe]
&IFEO[McNASvc.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McProxy.exe]
&IFEO[McProxy.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Mcshield.exe]
&IFEO[Mcshield.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsysmon.exe]
&IFEO[mcsysmon.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmqczj.exe]
&IFEO[mmqczj.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmsk.exe]
&IFEO[mmsk.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpfSrv.exe]
&IFEO[MpfSrv.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapsvc.exe]
&IFEO[Navapsvc.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapw32.exe]
&IFEO[Navapw32.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVSetup.exe]
&IFEO[NAVSetup.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe]
&IFEO[nod32.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32krn.exe]
&IFEO[nod32krn.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32kui.exe]
&IFEO[nod32kui.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPFMntor.exe]
&IFEO[NPFMntor.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.exe]
&IFEO[PFW.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFWLiveUpdate.exe]
&IFEO[PFWLiveUpdate.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ProcessSafe.exe]
&IFEO[ProcessSafe.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe]
&IFEO[procexp.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QHSET.exe]
&IFEO[QHSET.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctor.exe]
&IFEO[QQDoctor.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctorMain.exe]
&IFEO[QQDoctorMain.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQKav.exe]
&IFEO[QQKav.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ras.exe]
&IFEO[Ras.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe]
&IFEO[Rav.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe]
&IFEO[RavMon.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe]
&IFEO[RavMonD.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe]
&IFEO[RavStub.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe]
&IFEO[RavTask.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RawCopy.exe]
&IFEO[RawCopy.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegClean.exe]
&IFEO[RegClean.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regmon.exe]
&IFEO[regmon.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegTool.exe]
&IFEO[RegTool.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe]
&IFEO[rfwcfg.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe]
&IFEO[rfwmain.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwProxy.exe]
&IFEO[rfwProxy.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe]
&IFEO[rfwsrv.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwstub.exe]
&IFEO[rfwstub.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsAgent.exe]
&IFEO[RsAgent.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rsaupd.exe]
&IFEO[Rsaupd.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RStray.exe]
&IFEO[RStray.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe]
&IFEO[rstrui.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rtvscan.exe]
&IFEO[Rtvscan.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe]
&IFEO[runiep.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray.exe]
&IFEO[safeboxTray.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safelive.exe]
&IFEO[safelive.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe]
&IFEO[scan32.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SelfUpdate.exe]
&IFEO[SelfUpdate.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shcfg32.exe]
&IFEO[shcfg32.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe]
&IFEO[SmartUp.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREng.exe]
&IFEO[SREng.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SuperKiller.exe]
&IFEO[SuperKiller.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe]
&IFEO[symlcsvc.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SysSafe.exe]
&IFEO[SysSafe.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
&IFEO[taskmgr.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanDetector.exe]
&IFEO[TrojanDetector.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Trojanwall.exe]
&IFEO[Trojanwall.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.exe]
&IFEO[TrojDie.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UIHost.exe]
&IFEO[UIHost.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAgent.exe]
&IFEO[UmxAgent.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAttachment.exe]
&IFEO[UmxAttachment.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxCfg.exe]
&IFEO[UmxCfg.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxFwHlp.exe]
&IFEO[UmxFwHlp.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxPol.exe]
&IFEO[UmxPol.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\upiea.exe]
&IFEO[upiea.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UpLive.exe]
&IFEO[UpLive.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USBCleaner.exe]
&IFEO[USBCleaner.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe]
&IFEO[vsstat.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe]
&IFEO[webscanx.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WoptiClean.exe]
&IFEO[WoptiClean.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zxsweep.exe]
&IFEO[zxsweep.exe]&&ntsd -d&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
&Alcmtr&&; ALCMTR.EXE&[(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
&BgMonitor_{C6C-4d9f-84C7-88D8A56B10AA}&&; &C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe&&[(Verified)Nero AG]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
&IMJPMIG8.1&&; &C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE& /Spoil /RemAdvDef /Migration32&[(Verified)Microsoft Windows Publisher]
&IMSCMig&&; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload&[(Verified)Microsoft Corporation]
&Logitech Utility&&; Logi_MwX.Exe&[(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
&MSMSGS&&; &C:\Program Files\Messenger\msmsgs.exe& /background&[(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
&NeroFilterCheck&&; C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe&[(Verified)Nero AG]
&NvCplDaemon&&; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&[(Verified)Microsoft Windows Hardware Compatibility Publisher]
&NvMediaCenter&&; RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit&[(Verified)Microsoft Windows Hardware Compatibility Publisher]
&nwiz&&; nwiz.exe /install&[]
&PHIME2002A&&; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName&[(Verified)Microsoft Windows Publisher]
&PHIME2002ASync&&; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC&[(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
&QQDownload&&; &C:\Program Files\Tencent\QQDownload\QQDownload.exe& autostart&[File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
&QuickTime Task&&; &C:\Program Files\QuickTime\QTTask.exe& -atboottime&[Apple Inc.]
&RTHDCPL&&; RTHDCPL.EXE&[(Verified)Microsoft Windows Hardware Compatibility Publisher]
&runeip&&; &C:\Program Files\Rising\AntiSpyware\rstray.exe& /startup&[]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
&svchest.exe&&; C:\WINDOWS\system32\svchest.exe&[番茄花园]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
&SysExplr&&; C:\HEROSOFT\Hero3000\SYSEXPLR.EXE&[]
&TVTray&&; &[N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
&WangWang&&; &C:\Program Files\Alisoft\WangWang\WangWang.exe&&[(Verified)&Alibaba Software(Shanghai)Co,. Ltd&]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
&zBrowser Launcher&&; C:\Program Files\Logitech\iTouch\iTouch.exe&[Logitech Inc.]
==================================
启动文件夹
UID: 56463
论坛新人, 积分 0, 距离下一级还需 50 积分
==================================
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
&&C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&&&Adobe Systems&
[Contrl Center of Storm Media / ccosm][Running/Auto Start]
&C:\Program Files\StormII\stormliv.exe /asservice&&北京暴风网际科技有限公司&
[ervice / ervice][Running/Auto Start]
&C:\WINDOWS\system32\sv1F.tmp.exe&&N/A&
[Human Interface Device Access / HidServ][Stopped/Disabled]
&C:\WINDOWS\System32\svchost.exe -k netsvcs--&%SystemRoot%\System32\hidserv.dll&&N/A&
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
&&C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&&&Macrovision Corporation&
[NBService / NBService][Stopped/Manual Start]
&C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe&&Nero AG&
[NMIndexingService / NMIndexingService][Stopped/Manual Start]
&&C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe&&&Nero AG&
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
&C:\WINDOWS\system32\nvsvc32.exe&&NVIDIA Corporation&
[Rav Process Communication Center / RavCCenter][Stopped/Auto Start]
&C:\Program Files\Rising\Rav\CCENTER.EXE&&Beijing Rising Information Technology Co., Ltd.&
[Rising RavTask Manager / RavTask][Stopped/Auto Start]
&&C:\Program Files\Rising\Rav\RavTask.exe& RavTask&&Beijing Rising Information Technology Co., Ltd.&
[Rfw Process Communication Center / RfwCCenter][Stopped/Auto Start]
&C:\Program Files\Rising\Rfw\CCENTER.EXE&&Beijing Rising Information Technology Co., Ltd.&
[Rising Personal Firewall Service / RfwService][Stopped/Auto Start]
&C:\Program Files\Rising\Rfw\rfwsrv.exe&&N/A&
[Rising RfwTask Manager / RfwTask][Stopped/Auto Start]
&&C:\Program Files\Rising\Rfw\RavTask.exe& RfwTask&&Beijing Rising Information Technology Co., Ltd.&
[Rising RealTime Monitor / RsRavMon][Stopped/Auto Start]
&C:\Program Files\Rising\Rav\RavMonD.exe&&N/A&
[Rising Scan Service / RsScanSrv][Stopped/Auto Start]
&C:\Program Files\Rising\Rav\ScanFrm.exe&&N/A&
[WatchData ccb V3.2 / WDMonitorCCB][Running/Auto Start]
&C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\WDKeyMonitorCCB.exe&&Beijing WatchData System Co., Ltd.&
==================================
[AMD Processor Driver / AmdK8][Running/System Start]
&system32\DRIVERS\AmdK8.sys&&Advanced Micro Devices&
[cdrblock / cdrblock][Running/System Start]
&system32\DRIVERS\cdrblock.sys&&Canopus Co,. Ltd.&
[cdrport / cdrport][Running/System Start]
&system32\DRIVERS\cdrport.sys&&Canopus Co,. Ltd.&
[gdrv / gdrv][Stopped/Manual Start]
&\??\C:\WINDOWS\gdrv.sys&&Windows (R) 2000 DDK provider&
[Hardlock / Hardlock][Running/Auto Start]
&\??\C:\WINDOWS\system32\drivers\hardlock.sys&&Aladdin Knowledge Systems Ltd.&
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
&system32\DRIVERS\HDAudBus.sys&&Windows (R) Server 2003 DDK provider&
[HookCont / HookCont][Running/System Start]
&system32\drivers\HookCont.sys&&Beijing Rising Information Technology Co., Ltd.&
[HookSys / HookSys][Stopped/Disabled]
&system32\drivers\HookSys.sys&&Beijing Rising Information Technology Co., Ltd.&
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
&system32\drivers\RtkHDAud.sys&&Realtek Semiconductor Corp.&
[iTouch Keyboard Filter / itchfltr][Running/Manual Start]
&system32\DRIVERS\itchfltr.sys&&Logitech, Inc.&
[KAVSafe / KAVSafe][Stopped/Auto Start]
&\??\C:\WINDOWS\system32\Drivers\KAVSafe.sys&&Kingsoft Corporation&
[Logitech PS/2 Mouse Filter Driver / L8042pr2][Running/Manual Start]
&system32\DRIVERS\L8042pr2.Sys&&Logitech, Inc.&
[Logitech Mouse Class Filter Driver / LMouFlt2][Running/Manual Start]
&system32\DRIVERS\LMouFlt2.Sys&&Logitech, Inc.&
[msiffei / msiffei][Stopped/Manual Start]
&System32\Drivers\msiffei.sys&&N/A&
[npkcrypt / npkcrypt][Stopped/Manual Start]
&\??\C:\WINDOWS\system32\npkcrypt.sys&&N/A&
[npkycryp / npkycryp][Stopped/Manual Start]
&\??\C:\WINDOWS\system32\npkycryp.sys&&N/A&
[nv / nv][Running/Manual Start]
&system32\DRIVERS\nv4_mini.sys&&NVIDIA Corporation&
[NVIDIA nForce Networking Controller Driver / NVENETFD][Stopped/Manual Start]
&system32\DRIVERS\NVENETFD.sys&&NVIDIA Corporation&
[NVIDIA Network Bus Enumerator / nvnetbus][Stopped/Manual Start]
&system32\DRIVERS\nvnetbus.sys&&NVIDIA Corporation&
[PavSRK.sys / PavSRK.sys][Stopped/Manual Start]
&\??\C:\WINDOWS\system32\PavSRK.sys&&N/A&
[Padus ASPI Shell / pfc][Running/Manual Start]
&system32\drivers\pfc.sys&&Padus, Inc.&
[pnpshark / pnpshark][Running/Boot Start]
&\SystemRoot\system32\DRIVERS\pnpshark.sys&&&
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
&system32\DRIVERS\ptilink.sys&&Parallel Technologies, Inc.&
[PxHelp20 / PxHelp20][Running/Boot Start]
&\SystemRoot\system32\DRIVERS\PxHelp20.sys&&Sonic Solutions&
[QKeyServiceDisplay / QKeyService][Running/Boot Start]
&\SystemRoot\system32\KeyCrypt.sys&&Tencent Technology (Shenzhen) Company Limited&
[Rising RfwBase Driver / RfwBase9][Running/Manual Start]
&system32\DRIVERS\rfwbase.sys&&Beijing Rising Information Technology Co., Ltd.&
[rfwtdi / rfwtdi][Running/Auto Start]
&\??\C:\Program Files\Rising\Rfw\rfwtdi.sys&&Beijing Rising Information Technology Co., Ltd.&
[RsFwDrv / RsFwDrv][Running/System Start]
&\??\C:\Program Files\Rising\Rfw\rsfwdrv.sys&&Beijing Rising Information Technology Co., Ltd.&
[RsNTGDI / RsNTGDI][Running/Boot Start]
&\SystemRoot\system32\Drivers\RsNTGdi.sys&&Beijing Rising Information Technology Co., Ltd.&
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
&system32\DRIVERS\RTL8139.SYS&&Realtek Semiconductor Corporation&
[Secdrv / Secdrv][Stopped/Manual Start]
&system32\DRIVERS\secdrv.sys&&Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.&
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
&system32\DRIVERS\SONYPVU1.SYS&&Sony Corporation&
[st3shark / st3shark][Running/Boot Start]
&\SystemRoot\system32\DRIVERS\st3shark.sys&&&
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
&system32\DRIVERS\tcpip.sys&&Microsoft Corporation&
[TesSafe / TesSafe][Stopped/Manual Start]
&\??\C:\WINDOWS\system32\TesSafe.sys&&TENCENT&
[10moons UT330 / TridVid][Running/Manual Start]
&system32\DRIVERS\TridVid.sys&&10moons&
==================================
浏览器加载项
[EWPBrowseObject Class]
{68F-48E4-9AAF-4BC42A6A46BE} &C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll, &
[卡卡上网安全助手]
{98B7C13A-E9CD--FBEAB41E42A8} &C:\WINDOWS\system32\urlFilter.dll, (Signed) Beijing Rising Information Technology Co., Ltd.&
{367E0A21-C9A-153BF5ACA118} &C:\HEROSOFT\Hero3000\MPLAYER.EXE, N/A&
[信息检索(&R)]
{CC-41C8-B9BE-3C9C571A8263} &C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, (Signed) Microsoft Corporation&
[Messenger]
{FB5Fd2-BB9E-00C04F795683} &C:\Program Files\Messenger\msmsgs.exe, (Signed) Microsoft Corporation&
[Easy-WebPrint]
{327Cc37-AA9D-10AC9BABA46C} &C:\Program Files\Canon\Easy-WebPrint\Toolband.dll, &
[EditCtrl Class]
{488AB3-8F27-FA1AECAA8844} &C:\WINDOWS\system32\aliedit\aliedit.dll, (Signed) &
[Tencent Safety Online Base Module]
{C09B522F-8AED-4E21-A65C-DC1AB652BAEE} &C:\WINDOWS\DOWNLO~1\TSOBase.ocx, (Signed) Tencent Corporation&
[WebActivater Control]
{C661F36D-DF85-4EF4-83C7-E107B83D04B1} &C:\WINDOWS\system32\3DShowVM.ocx, QQ&
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-} &C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx, (Signed) Adobe Systems, Inc.&
[QQCycloneHelper Class]
{C9--D2} &C:\Program Files\Tencent\QQDownload\QQIEHelper02.dll, (Signed) 腾讯公司&
{03507A1A-E0C5-4404-AA26-2D} &, &
[iTrusPTA Class]
{1E0DFFCF-27FF-007349FEDA} &C:\WINDOWS\system32\aliedit\pta.dll, (Signed) &
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-E95} &C:\WINDOWS\system32\wmpdxm.dll, (Signed) Microsoft Corporation&
{2375BEE5-F175-4F1C-81EC-8E4E2E72E2DD} &, &
[HTML Document]
{F9-11CF-8FD0-00AA00686F13} &%SystemRoot%\system32\mshtml.dll, (Signed) N/A&
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} &C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, (Signed) Microsoft Corporation&
{2EEDA47E-8D5C-4d7e-B4B6-E16E} &, &
[Easy-WebPrint]
{327CC37-AA9D-10AC9BABA46C} &C:\Program Files\Canon\Easy-WebPrint\Toolband.dll, &
{32D-42B5-8980-FB561D1BE2D0} &, &
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-} &C:\WINDOWS\system32\tdc.ocx, (Signed) Microsoft Corporation&
{367E0A21-C9A-153BF5ACA118} &, &
[QuickTime Object]
{B08-470D-A0D5-B37161CFFD69} &C:\Program Files\QuickTime\QTPlugin.ocx, (Signed) Apple Inc.&
[XML Document]
{4D9-11D1-A6B3-00C04FD91555} &C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation&
[EditCtrl Class]
{488AB3-8F27-FA1AECAA8844} &C:\WINDOWS\system32\aliedit\aliedit.dll, (Signed) &
[Shell Name Space]
{DE-11D1-B9F2-00A0C98BC547} &%SystemRoot%\system32\shdocvw.dll, (Signed) N/A&
[XMP Class]
{8-4C41-AACC-52D4D7845851} &C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, &
[EWPBrowseObject Class]
{68F-48E4-9AAF-4BC42A6A46BE} &C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll, &
[QQMusicCreator Class]
{A89--9} &, &
{693571CB-54A3-4E90-9D52-EEAE} &C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work, &
[StormPlayer Object]
{6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB} &C:\Program Files\StormII\mps.dll, 北京暴风网际科技有限公司&
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} &C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation&
[WangWangObj Class]
{6E213FC7-DD5A--D4CE} &C:\Program Files\Alisoft\WangWang\WangWangX6.dll, (Signed) 阿里巴巴软件(上海)有限公司&
{73E4740C-08EB-D0A7C9EE3CD} &, &
[Microsoft Web 浏览器]
{A-11D0-A96B-00C04FD705A2} &C:\WINDOWS\system32\shdocvw.dll, (Signed) Microsoft Corporation&
{8D9E0B29-563C--5FF2AE77E1D2} &, &
{CC-41C8-B9BE-3C9C571A8263} &, &
{962EFB8E--AC74-AAA4C759B9C6} &, &
[卡卡上网安全助手]
{98B7C13A-E9CD--FBEAB41E42A8} &C:\WINDOWS\system32\urlFilter.dll, (Signed) Beijing Rising Information Technology Co., Ltd.&
[WMEncProfileManager Class]
{A8D3AD02--B2E9-AD33F087F43C} &C:\Program Files\Windows Media Components\Encoder\WMEX.dll, Microsoft Corporation&
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} &C:\WINDOWS\system32\msnetobj.dll, (Signed) Microsoft Corporation&
{ACACC6EB-1FBA-4E13-A729-53AEB2DF54F8} &, &
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-} &C:\WINDOWS\system32\mshtml.dll, (Signed) Microsoft Corporation&
{B234553D-A066-3F7BAB47F7} &, &
[SearchAssistantOC]
{B45FF030--85DE-00C04FA35C89} &%SystemRoot%\system32\shdocvw.dll, (Signed) N/A&
[Messenger Object]
{BE-4B48-836C-BC} &C:\Program Files\Messenger\msgsc.dll, (Signed) Microsoft Corporation&
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} &C:\Program Files\Common Files\System\msadc\msadco.dll, (Signed) Microsoft Corporation&
[ScreenCapture Class]
{BFB79EE1-04AE-4D4A-B85E-27EE5F30C095} &C:\WINDOWS\system32\TXGYMailActiveX.dll, (Signed) Tencent Inc.&
[Tencent Safety Online Base Module]
{C09B522F-8AED-4E21-A65C-DC1AB652BAEE} &C:\WINDOWS\DOWNLO~1\TSOBase.ocx, (Signed) Tencent Corporation&
[WebActivater Control]
{C661F36D-DF85-4EF4-83C7-E107B83D04B1} &C:\WINDOWS\system32\3DShowVM.ocx, QQ&
[VIDEO__X_MS_ASF Moniker Class]
{CD3AFA8F-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation&
[VIDEO__X_MS_WMV Moniker Class]
{CD3AFA94-B84F-48F0-9393-7EDC} &C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation&
[WDCCBCtrl Class]
{CEBD-4DC1-A046-0BDCB5A06CEB} &C:\WINDOWS\system32\wdccb.dll, (Signed) &
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} &C:\Program Files\StormII\Codec\rmoc3260.dll, (Signed) RealNetworks, Inc.&
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-} &C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx, (Signed) Adobe Systems, Inc.&
[Easy-WebPrint Helper]
{D5E20F5B-9DB8-4230-BA09-7B8DB43D83EE} &C:\Program Files\Canon\Easy-WebPrint\TemplateHelper.dll, &
[TencentVmpCtl Class]
{DB-B} &C:\Program Files\Tencent\Viewpoint Media Player\AxMetaStream.dll, Viewpoint Corporation&
[PlayerCtrl Class]
{E05BC2A3-9A46-4A32-80C9-023A473F5B23} &D:\学习资料(俺的)\QzoneMusic.dll, (Signed) 深圳腾讯科技&
[QvodCtrl Class]
{F3D0D36F-23F8-C92B03D4AF} &C:\Program Files\QvodPlayer\QvodInsert.dll, N/A&
{F3E70CEA-956E-49CC-B444-73AFE593AD7F} &, &
{FB5FD2-BB9E-00C04F795683} &, &
[&使用超级旋风下载]
&C:\Program Files\Tencent\QQDownload\geturl.htm, N/A&
[&使用超级旋风下载全部链接]
&C:\Program Files\Tencent\QQDownload\getAllurl.htm, N/A&
[Easy-WebPrint打印]
&res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html, N/A&
[Easy-WebPrint添加到打印列表]
&res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html, N/A&
[Easy-WebPrint预览]
&res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html, N/A&
[Easy-WebPrint高速打印]
&res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html, N/A&
[导出到 Microsoft Office Excel(&X)]
&res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A&
[添加到QQ表情]
&C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A&
[解霸实时播放]
&C:\HEROSOFT\Hero3000\MPURLGET.HTM, N/A&
UID: 56463
论坛新人, 积分 0, 距离下一级还需 50 积分
==================================
正在运行的进程
[PID: 720 / SYSTEM][\SystemRoot\System32\smss.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 788 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 812 / SYSTEM][\??\C:\WINDOWS\SYSTEM32\winlogon.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 856 / SYSTEM][C:\WINDOWS\system32\services.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 868 / SYSTEM][C:\WINDOWS\system32\lsass.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 1036 / SYSTEM][C:\WINDOWS\system32\svchost.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[C:\WINDOWS\system32\anymie360.dll][N/A, ]
[PID: 1092 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 1204 / SYSTEM][C:\WINDOWS\System32\svchost.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 1332 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 1368 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 1624 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_gdr.9)]
[C:\WINDOWS\system32\CNMLM87.DLL][CANON INC., 2.00.4.13]
[C:\WINDOWS\system32\mdimon.dll][Microsoft Corporation, 11.3.1897.0]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\CNMPD87.DLL][CANON INC., 2.00.4.13]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll][Microsoft Corporation, 11.3.1897.0]
[PID: 1784 / zhangqianchun][C:\WINDOWS\system32\userinit.exe][N/A, ]
[C:\WINDOWS\TEMP\ZPWGameRecord.dll][N/A, ]
[C:\WINDOWS\TEMP\wooolinit.dat][N/A, ]
[C:\WINDOWS\TEMP\elementgj.dll][N/A, ]
[C:\WINDOWS\TEMP\WowInitcode.dat][N/A, ]
[PID: 1904 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 1932 / SYSTEM][C:\Program Files\StormII\stormliv.exe][北京暴风网际科技有限公司, 3, 8, 12, 12]
[C:\Program Files\StormII\bfoptdll.dll][北京暴风网际科技有限公司, 3, 8, 7, 16]
[C:\Program Files\StormII\box\BoxLog.dll][北京暴风网际科技有限公司, 3, 8, 12, 12]
[PID: 1972 / SYSTEM][C:\WINDOWS\system32\sv1F.tmp.exe][N/A, ]
[PID: 136 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe][NVIDIA Corporation, 6.14.11.5822]
[C:\WINDOWS\system32\nvapi.dll][NVIDIA Corporation, 6.14.11.5822]
[PID: 528 / SYSTEM][C:\WINDOWS\system32\svchost.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 548 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe][Microsoft Corporation, 5.2. built by: dnsrv(bld4act)]
[PID: 608 / SYSTEM][C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\WDKeyMonitorCCB.exe][ Beijing WatchData System Co., Ltd., 3, 2, 0, 0]
[C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\TokenMgr.dll][ Beijing WatchData System Co., Ltd., 3, 6, 3, 2]
[C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\WDAlg.DLL][ Beijing WatchData System C0., Ltd., 3, 5, 12, 20]
[C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\wdkmgr.dll][Watchdata, 1, 0, 0, 11]
[C:\WINDOWS\system32\WatchData\Watchdata CCB CSP v3.2\WDPKCS.dll][ Beijing WatchData System Co., Ltd., 3, 6, 2, 15]
[PID: 1316 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 1848 / zhangqianchun][C:\WINDOWS\explorer.exe][(Verified) Microsoft Corporation, 6.00. (xpsp_sp2_gdr.4)]
[C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll][Nero AG, 2, 0, 0, 8]
[C:\Program Files\Common Files\Ahead\Lib\MFC71.DLL][Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Common Files\Ahead\Lib\MSVCR71.dll][Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Common Files\Ahead\Lib\MSVCP71.dll][Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MFC71CHS.DLL][Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\RavExt.dll][Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12]
[C:\WINDOWS\system32\pinklije.dll][N/A, ]
[C:\WINDOWS\system32\ajbhhfcb.dll][N/A, ]
[C:\WINDOWS\system32\jmpelhic.dll][N/A, ]
[C:\WINDOWS\system32\mlepbfai.dll][N/A, ]
[C:\WINDOWS\system32\ohgechff.dll][N/A, ]
[C:\WINDOWS\system32\dlemkhjl.dll][N/A, ]
[C:\WINDOWS\system32\kdcbbjlo.dll][N/A, ]
[C:\WINDOWS\system32\dkkjlcnk.dll][N/A, ]
[C:\WINDOWS\system32\ebofckaf.dll][N/A, ]
[C:\WINDOWS\system32\jpdblkka.dll][N/A, ]
[C:\WINDOWS\system32\gagpjmck.dll][N/A, ]
[C:\WINDOWS\system32\igbfbncn.dll][N/A, ]
[C:\WINDOWS\system32\cmoihiah.dll][N/A, ]
[C:\WINDOWS\system32\miipocgb.dll][N/A, ]
[C:\WINDOWS\system32\choijnpg.dll][N/A, ]
[C:\WINDOWS\TEMP\ZPWGameRecord.dll][N/A, ]
[C:\WINDOWS\TEMP\wooolinit.dat][N/A, ]
[C:\WINDOWS\TEMP\elementgj.dll][N/A, ]
[C:\WINDOWS\TEMP\WowInitcode.dat][N/A, ]
[C:\WINDOWS\system32\anymie360.dll][N/A, ]
[C:\WINDOWS\system32\cmdgknbe.dll][N/A, ]
[C:\WINDOWS\system32\ningdeid.dll][N/A, ]
[C:\WINDOWS\system32\plelfmlm.dll][N/A, ]
[PID: 2004 / zhangqianchun][C:\WINDOWS\system32\conime.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[C:\WINDOWS\TEMP\ZPWGameRecord.dll][N/A, ]
[PID: 204 / zhangqianchun][C:\Program Files\D-Tools\daemon.exe][DAEMON'S HOME, 3.41.0.0]
[C:\WINDOWS\daemon.dll][, 3.41.0.0]
[C:\Program Files\D-Tools\PFCTOC.DLL][Padus(R), Inc., 1, 0, 0, 12]
[C:\Program Files\D-Tools\Plugins\Images\ccdmount.dll][GENERIC, 1.01.0.0]
[C:\Program Files\D-Tools\Plugins\Images\mdsmount.dll][GENERIC, 1.01.0.0]
[C:\Program Files\D-Tools\Plugins\Images\pdimount.dll][GENERIC, 1.01.0.0]
[C:\Program Files\D-Tools\Plugins\Images\nrgmount.dll][GENERIC, 1.01.0.0]
[C:\WINDOWS\TEMP\ZPWGameRecord.dll][N/A, ]
[PID: 376 / zhangqianchun][C:\WINDOWS\system32\ctfmon.exe][(Verified) Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[C:\WINDOWS\TEMP\ZPWGameRecord.dll][N/A, ]
[C:\WINDOWS\TEMP\wooolinit.dat][N/A, ]
[C:\WINDOWS\TEMP\elementgj.dll][N/A, ]
[C:\WINDOWS\TEMP\WowInitcode.dat][N/A, ]
[PID: 3540 / zhangqianchun][C:\Program Files\Rising\Rfw\rsnetsvr.exe][Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12]
[C:\Program Files\Rising\Rfw\NComm.dll][Beijing Rising Information Technology Co., Ltd., 6.0.0.9]
[C:\Program Files\Rising\Rfw\Syslay.dll][Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
[C:\WINDOWS\system32\pinklije.dll][N/A, ]
[C:\WINDOWS\system32\ajbhhfcb.dll][N/A, ]
[C:\WINDOWS\system32\jmpelhic.dll][N/A, ]
[C:\WINDOWS\system32\mlepbfai.dll][N/A, ]
[C:\WINDOWS\system32\ohgechff.dll][N/A, ]
[C:\WINDOWS\system32\dlemkhjl.dll][N/A, ]
[C:\WINDOWS\system32\kdcbbjlo.dll][N/A, ]
[C:\WINDOWS\system32\dkkjlcnk.dll][N/A, ]
[C:\WINDOWS\system32\ebofckaf.dll][N/A, ]
[C:\Program Files\Rising\Rfw\comx3.dll][Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
[C:\Program Files\Rising\Rfw\ProcComm.dll][Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46]
[C:\WINDOWS\system32\MSVCR71.dll][Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\MSVCP71.dll][Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\TEMP\ZPWGameRecord.dll][N/A, ]
[C:\WINDOWS\TEMP\wooolinit.dat][N/A, ]
[C:\WINDOWS\TEMP\elementgj.dll][N/A, ]
[C:\WINDOWS\TEMP\WowInitcode.dat][N/A, ]
[PID: 3796 / zhangqianchun][C:\Program Files\Internet Explorer\iexplore.exe][Microsoft Corporation, 6.00. (xpsp_sp2_rtm.8)]
[C:\WINDOWS\system32\pinklije.dll][N/A, ]
[C:\WINDOWS\system32\ajbhhfcb.dll][N/A, ]
[C:\WINDOWS\system32\jmpelhic.dll][N/A, ]
[C:\WINDOWS\system32\mlepbfai.dll][N/A, ]
[C:\WINDOWS\system32\ohgechff.dll][N/A, ]
[C:\WINDOWS\system32\dlemkhjl.dll][N/A, ]
[C:\WINDOWS\system32\kdcbbjlo.dll][N/A, ]
[C:\WINDOWS\system32\dkkjlcnk.dll][N/A, ]
[C:\WINDOWS\system32\ebofckaf.dll][N/A, ]
[C:\WINDOWS\system32\jpdblkka.dll][N/A, ]
[C:\WINDOWS\system32\gagpjmck.dll][N/A, ]
[C:\WINDOWS\system32\igbfbncn.dll][N/A, ]
[C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll][, 2, 6, 4, 1]
[C:\WINDOWS\system32\MSVCR71.dll][Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Canon\Easy-WebPrint\EWPCore.dll][, 2, 6, 4, 1]
[C:\WINDOWS\system32\MSVCP71.dll][Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\urlFilter.dll][Beijing Rising Information Technology Co., Ltd., 6, 0, 0, 15]
[C:\Program Files\Rising\AntiSpyware\UrlRule.dll][Beijing Rising Information Technology Co., Ltd., 1.0.0.15]
[C:\Program Files\Rising\Rav\RavScrCh.dll][Beijing Rising Information Technology Co., Ltd., 21.0.0.60]
[C:\WINDOWS\system32\cmoihiah.dll][N/A, ]
[C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx][Adobe Systems, Inc., 10,0,12,36]
[C:\WINDOWS\system32\miipocgb.dll][N/A, ]
[C:\WINDOWS\system32\choijnpg.dll][N/A, ]
[C:\WINDOWS\TEMP\ZPWGameRecord.dll][N/A, ]
[C:\WINDOWS\TEMP\wooolinit.dat][N/A, ]
[C:\WINDOWS\TEMP\elementgj.dll][N/A, ]
[C:\WINDOWS\TEMP\WowInitcode.dat][N/A, ]
[C:\WINDOWS\system32\plelfmlm.dll][N/A, ]
[C:\WINDOWS\system32\ningdeid.dll][N/A, ]
[C:\WINDOWS\system32\cmdgknbe.dll][N/A, ]
[PID: 2180 / zhangqianchun][C:\Program Files\WinRAR\WinRAR.exe][N/A, ]
[C:\WINDOWS\system32\pinklije.dll][N/A, ]
[C:\WINDOWS\system32\ajbhhfcb.dll][N/A, ]
[C:\WINDOWS\system32\jmpelhic.dll][N/A, ]
[C:\WINDOWS\system32\mlepbfai.dll][N/A, ]
[C:\WINDOWS\system32\ohgechff.dll][N/A, ]
[C:\WINDOWS\system32\dlemkhjl.dll][N/A, ]
[C:\WINDOWS\system32\kdcbbjlo.dll][N/A, ]
[C:\WINDOWS\system32\dkkjlcnk.dll][N/A, ]
[C:\WINDOWS\system32\ebofckaf.dll][N/A, ]
[C:\WINDOWS\system32\jpdblkka.dll][N/A, ]
[C:\WINDOWS\system32\gagpjmck.dll][N/A, ]
[C:\WINDOWS\system32\igbfbncn.dll][N/A, ]
[C:\WINDOWS\system32\cmoihiah.dll][N/A, ]
[C:\WINDOWS\system32\miipocgb.dll][N/A, ]
[C:\WINDOWS\system32\choijnpg.dll][N/A, ]
[C:\WINDOWS\TEMP\wooolinit.dat][N/A, ]
[C:\WINDOWS\TEMP\ZPWGameRecord.dll][N/A, ]
[C:\WINDOWS\TEMP\elementgj.dll][N/A, ]
[C:\WINDOWS\TEMP\WowInitcode.dat][N/A, ]
[C:\WINDOWS\system32\plelfmlm.dll][N/A, ]
[C:\WINDOWS\system32\ningdeid.dll][N/A, ]
[C:\WINDOWS\system32\cmdgknbe.dll][N/A, ]
[PID: 2632 / zhangqianchun][C:\WINDOWS\TEMP\Rar$EX00.094\SREngLdr.EXE][Smallfrogs Studio, 2.7.0.1210]
[C:\WINDOWS\system32\dlemkhjl.dll][N/A, ]
[C:\WINDOWS\system32\ohgechff.dll][N/A, ]
[C:\WINDOWS\system32\mlepbfai.dll][N/A, ]
[C:\WINDOWS\system32\ajbhhfcb.dll][N/A, ]
[C:\WINDOWS\system32\pinklije.dll][N/A, ]
[C:\WINDOWS\system32\jmpelhic.dll][N/A, ]
[C:\WINDOWS\system32\ebofckaf.dll][N/A, ]
[C:\WINDOWS\system32\dkkjlcnk.dll][N/A, ]
[C:\WINDOWS\system32\cmoihiah.dll][N/A, ]
[C:\WINDOWS\system32\choijnpg.dll][N/A, ]
[C:\WINDOWS\system32\miipocgb.dll][N/A, ]
[C:\WINDOWS\system32\igbfbncn.dll][N/A, ]
[C:\WINDOWS\system32\gagpjmck.dll][N/A, ]
[C:\WINDOWS\system32\jpdblkka.dll][N/A, ]
[C:\WINDOWS\system32\kdcbbjlo.dll][N/A, ]
[PID: 2692 / zhangqianchun][C:\WINDOWS\TEMP\Rar$EX00.094\SRE6a9d7856.EXE][Smallfrogs Studio, 2.7.0.1210]
[C:\WINDOWS\system32\dlemkhjl.dll][N/A, ]
[C:\WINDOWS\system32\ohgechff.dll][N/A, ]
[C:\WINDOWS\system32\mlepbfai.dll][N/A, ]
[C:\WINDOWS\system32\ajbhhfcb.dll][N/A, ]
[C:\WINDOWS\system32\pinklije.dll][N/A, ]
[C:\WINDOWS\system32\jmpelhic.dll][N/A, ]
[C:\WINDOWS\system32\ebofckaf.dll][N/A, ]
[C:\WINDOWS\system32\dkkjlcnk.dll][N/A, ]
[C:\WINDOWS\system32\cmoihiah.dll][N/A, ]
[C:\WINDOWS\system32\choijnpg.dll][N/A, ]
[C:\WINDOWS\system32\miipocgb.dll][N/A, ]
[C:\WINDOWS\system32\igbfbncn.dll][N/A, ]
[C:\WINDOWS\system32\gagpjmck.dll][N/A, ]
[C:\WINDOWS\system32\jpdblkka.dll][N/A, ]
[C:\WINDOWS\system32\kdcbbjlo.dll][N/A, ]
[C:\WINDOWS\TEMP\wooolinit.dat][N/A, ]
[C:\WINDOWS\TEMP\ZPWGameRecord.dll][N/A, ]
[C:\WINDOWS\TEMP\Rar$EX00.094\Upload\3rdUpd.DLL][Smallfrogs Studio, 2, 1, 0, 15]
[C:\WINDOWS\TEMP\elementgj.dll][N/A, ]
[C:\WINDOWS\TEMP\WowInitcode.dat][N/A, ]
[C:\WINDOWS\system32\cmdgknbe.dll][N/A, ]
[C:\WINDOWS\system32\ningdeid.dll][N/A, ]
[C:\WINDOWS\system32\plelfmlm.dll][N/A, ]
==================================
.TXTOK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXEOK. [&%1& %*]
.COMOK. [&%1& %*]
.PIFOK. [&%1& %*]
.REGOK. [regedit.exe &%1&]
.BATOK. [&%1& %*]
.SCROK. [&%1& /S]
.CHMOK. [&C:\WINDOWS\hh.exe& %1]
.HLPOK. [%SystemRoot%\System32\winhlp32.exe %1]
.INIOK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INFOK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBSOK. [%SystemRoot%\System32\WScript.exe &%1& %*]
.JS OK. [%SystemRoot%\System32\WScript.exe &%1& %*]
.LNKOK. [{0-}]
==================================
Winsock 提供者
==================================
Autorun.inf
==================================
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 1784, C:\WINDOWS\SYSTEM32\USERINIT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 608, C:\WINDOWS\SYSTEM32\WATCHDATA\WATCHDATA CCB CSP V3.2\WDKEYMONITORCCB.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 204, C:\PROGRAM FILES\D-TOOLS\DAEMON.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2180, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2180, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2632, C:\WINDOWS\TEMP\RAR$EX00.094\SRENGLDR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2632, C:\WINDOWS\TEMP\RAR$EX00.094\SRENGLDR.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 3252, C:\WINDOWS\TEMP\SVCHOST.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 2460, C:\WINDOWS\TEMP\SVCHOST.EXE]
==================================
==================================
==================================
==================================
UID: 105292
呵呵,怪不得开不了杀软了
有很多劫持项目。。。。。
先解决劫持项目吧~
方法很多。最简单的方法是直接把[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]项删除即可
或者用AUTORUS来解决,打开AUTORUNS,点击菜单栏的“选项”,选中选中“隐藏微软项目,然后点工具栏上的“刷新”按钮,再把“映像胁持”里所有项目删除即可。。。。。
然后再清理别的病毒。。。。。
1.建议使用XDelBox删除以下文件:()
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择剪贴板导入不检查路径,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。
c:\windows\system32\ajbhhfcb.dll
c:\windows\system32\anymie360.dll
c:\windows\system32\choijnpg.dll
c:\windows\system32\cmdgknbe.dll
c:\windows\system32\cmoihiah.dll
c:\windows\system32\dkkjlcnk.dll
c:\windows\system32\dlemkhjl.dll
c:\windows\system32\ebofckaf.dll
c:\windows\system32\gagpjmck.dll
c:\windows\system32\igbfbncn.dll
c:\windows\system32\jmpelhic.dll
c:\windows\system32\jpdblkka.dll
c:\windows\system32\kdcbbjlo.dll
c:\windows\system32\miipocgb.dll
c:\windows\system32\mlepbfai.dll
c:\windows\system32\ningdeid.dll
c:\windows\system32\ohgechff.dll
c:\windows\system32\pinklije.dll
c:\windows\system32\plelfmlm.dll
c:\windows\temp\elementgj.dll
c:\windows\temp\wooolinit.dat
c:\windows\temp\wowinitcode.dat
c:\windows\temp\zpwgamerecord.dll
c:\windows\system32\sv1f.tmp.exe
c:\windows\system32\drivers\msiffei.sys
2.删除重启后使用SREng修复下面各项:
启动项目 -- 注册表之如下项删除:
[7270DE2D]&C:\WINDOWS\system32\ningdeid.dll&
[C6D047BE]&C:\WINDOWS\system32\cmdgknbe.dll&
[C1823790]&C:\WINDOWS\system32\choijnpg.dll&
启动项目 -- 服务 -- Win32服务应用程序之如下项禁用:
[ervice / ervice]&C:\WINDOWS\system32\sv1F.tmp.exe&
启动项目 -- 服务-- 驱动程序之如下项禁用:
[msiffei / msiffei]&System32\Drivers\msiffei.sys&
**************以上分析报告由SREngLog分析助手提供******************
分析:菜鸟又怎样
SREngLog分析助手 1.3 ( 更新 BY 草莽书生)
UID: 134205
中级会员, 积分 641, 距离下一级还需 359 积分
你重新装一下,看看是不是软件的故障
Powered by}

我要回帖

更多关于 微信是什么 的文章

更多推荐

版权声明:文章内容来源于网络,版权归原作者所有,如有侵权请点击这里与我们联系,我们将及时删除。

点击添加站长微信