查看: 3243|回复: 14
收起左侧

[已解决] 求 高手帮忙解决 中毒后 如何杀掉~!

 关闭 [复制链接]
3955312
发表于 2007-4-6 07:10:12 | 显示全部楼层 |阅读模式
我中的是 :Backdoor.Agent.ahj
               Trojan.OnLineGames.mf
Trojan.OnLineGames.es            Trojan.OnLineGames.lc
Trojan.OnLineGames.mq
我用AVG 在安全模式下都杀2遍了 还用卡吧 杀了2遍 又在普通模式下也杀了2遍   AVG和卡吧 都更新到最新了 可是还是杀不掉他们 还是嗷嗷的拖慢机器 在桌面出3个网页文件  在收藏架也出3个网页文件~!
求高手帮忙解决 如何杀掉他们啊 都困惑我3天了~!
有同病相连的朋友 把杀它们的经验告诉我谢谢了~!
chr707
发表于 2007-4-6 07:44:47 | 显示全部楼层
有这么厉害的????
  

佩服了,我现在不用avg了,用 apy emergency  

你用360了没有?要不试试其它的杀  

你这个好像有点重,但是也不要害怕,总有解决的方法
一天一天过
发表于 2007-4-6 08:27:37 | 显示全部楼层
1、网上有清理垃圾文件的批处理,可以找一下,然后用系统盘启动到dos下,运行这个批处理清理一下;
2、对于这些木马,记下对应的文件,然后到注册表里搜索这些文件,找到的项目都删除,然后再删除这些文件;如遇不能删除的,就用Icesword冰刃删除
剑指七星
发表于 2007-4-6 08:30:58 | 显示全部楼层
3955312
 楼主| 发表于 2007-4-6 18:41:27 | 显示全部楼层
请问下有简单点办法 杀掉他们吗?
我这回把 他们在AVG里的 显示都写下来了 请高手帮忙找个简单点的杀法
c:\Syswm1i\svchost.exe                                     Trojan.OnLineGames.mf
c:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\uppxdnd.exe             Trojan.OnLineGames.es
c:\WINDOWS\fcmdbcs.exe                                     Trojan.OnLineGames.lc
c:\WINDOWS\system32\AAC5A259.exe                           Backdoor.Agent.ahj
c:\Syswm1i\svchost.exe                                     Trojan.OnLineGames.mf
c:\WINDOWS\systen32\g1175813586.exe                        Trojan.OnLineGames.es
c:\WINDOWS\cmdbcsg.exe                                     Trojan.OnLineGames.lc
c:\WINDOWS\winform.exe                                     Trojan.OnLineGames.mq
c:\WINDOWS\system32\winform.dll                            Trojan.OnLineGames.mq
c:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxsdnd.exe             Trojan.OnLineGames.es
c:\WINDOWS\cmdbcsg.exe                                     Trojan.OnLineGames.lc
3955312
 楼主| 发表于 2007-4-6 18:42:48 | 显示全部楼层
望了 告诉大家了 卡吧对这些毒 屏蔽和隔离不了 AVG 可以隔离  之后就不在 桌面和收藏夹里现在那3个网页文件了
wangjay1980
发表于 2007-4-6 20:01:41 | 显示全部楼层
扫个报告
3955312
 楼主| 发表于 2007-4-6 22:15:45 | 显示全部楼层
各位高手:
非常感谢您留心我这份系统诊断报告,小菜鸟十万火急等待您的帮助!
该诊断报告由360安全卫士提供 http://www.360safe.com
诊断时间: 2007-04-06  22:15:05
诊断平台: Microsoft Windows XP  Service Pack 2
IE版本: Internet Explorer V6.0.2900.2180 Build:62900.2180
计算机物理内存:511MB - 当前可用内存:343MB

100 - 未知 - Process: MemorySaviour.exe [] - E:\吞食资料\MemorySaviour_1_0\MemorySaviour.exe
100 - 未知 - Process: avgas.exe [AVG Anti-Spyware] - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
100 - 未知 - Process: guard.exe [AVG Anti-Spyware guard] -
100 - 未知 - Process: nortones.exe [] - C:\WINDOWS\nortones.exe @C:\WINDOWS\system32\g11758683671.exe@3940
O3 - 未知 - Toolbar: (第三方IE工具栏) - [无效的CLSID:{1E796980-9CC5-11D1-A83F-00C04FC99D61}] - {1E796980-9CC5-11D1-A83F-00C04FC99D61} -
O4 - 未知 - HKLM\..\Run: [Memory Saviour] [] E:\吞食资料\MemorySaviour_1_0\MemorySaviour.exe /autorun
O4 - 未知 - HKLM\..\Run: [msccrt] [] C:\WINDOWS\msccrt.exe
O8 - 未知 - Extra context menu item: 使用Web迅雷下载 - e:\Program Files\Thunder Network\WebThunder\GetUrl.htm
O8 - 未知 - Extra context menu item: 使用Web迅雷下载全部链接 - e:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm
O9 - 未知 - Extra button: 启动Web迅雷(HKLM) - http://my.xunlei.com
O23 - 未知 - Service: 5CADA776 [5CADA776] - C:\WINDOWS\system32\5CADA776.EXE -service - (not running)
O23 - 未知 - Service: AVG Anti-Spyware Guard [AVG Anti-Spyware Guard] - d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe - (running)
O23 - 未知 - Service: E020FC6A [E020FC6A] - C:\WINDOWS\system32\E020FC6A.EXE -service - (not running)
O23 - 未知 - Service: ewido anti-spyware 4.0 guard [ewido anti-spyware 4.0 guard] - E:\ewido_4.0.0.172c_3.3\ewido_4.0.0.172c_3.3\guard.exe - (not running)
O23 - 未知 - Service: kavsvc [kavsvc] - "e:\Kaspersky Anti-Virus Personal\kavsvc.exe" - (not running)

=======================================

100 - 安全 - Process: smss.exe [进程为会话管理子系统用以初始化系统变量,ms-dos驱动名称类似lpt1以及com,调用win32壳子系统和运行在windows登陆过程。] - C:\WINDOWS\System32\smss.exe
100 - 安全 - Process: csrss.exe [客户端服务子系统,用以控制windows图形相关子系统。] - C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=base
100 - 安全 - Process: winlogon.exe [windows nt用户登陆程序。] - C:\WINDOWS\system32\winlogon.exe
100 - 安全 - Process: services.exe [用于管理windows服务系统进程。] - C:\WINDOWS\system32\services.exe
100 - 安全 - Process: lsass.exe [本地安全权限服务控制windows安全机制。] - C:\WINDOWS\system32\lsass.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k DcomLaunch
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost -k rpcss
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\System32\svchost.exe -k netsvcs
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k NetworkService
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k LocalService
100 - 安全 - Process: spoolsv.exe [windows打印任务控制程序,用以打印机就绪。] - C:\WINDOWS\system32\spoolsv.exe
100 - 安全 - Process: 360tray.exe [360安全卫士实时保护模块] - D:\Program Files\360safe\safemon\360Tray.exe
100 - 安全 - Process: nvsvc32.exe [nvidia driver helper service在nvida显卡驱动中被安装。] - C:\WINDOWS\system32\nvsvc32.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] - C:\WINDOWS\system32\svchost.exe -k imgsvc
100 - 安全 - Process: wdfmgr.exe [windows media player播放器相关程序。] - C:\WINDOWS\system32\wdfmgr.exe
100 - 安全 - Process: alg.exe [这是一个应用层网关服务用于网络共享。] - C:\WINDOWS\System32\alg.exe
100 - 安全 - Process: explorer.exe [windows program manager或者windows explorer用于控制windows图形shell,包括开始菜单、任务栏,桌面和文件管理。] - C:\WINDOWS\explorer.exe
100 - 安全 - Process: conime.exe [console ime ime输入法控制台软件。] - C:\WINDOWS\system32\conime.exe
100 - 安全 - Process: IEXPLORE.EXE [microsoft internet explorer浏览器用于浏览网页。] - C:\Program Files\Internet Explorer\iexplore.exe
100 - 安全 - Process: 360Safe.exe [360安全卫士] - D:\Program Files\360safe\360safe.exe
O2 - 安全 - BHO: (WebThunder Browser Helper) - [Web迅雷, 支持多资源超线程技术的下载工具。] - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - e:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll
O2 - 安全 - BHO: (Thunder Browser Helper) - [迅雷附带下载监视器相关文件。] - {889D2FEB-5411-4565-8998-1DD2C5261283} - e:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll
O4 - 安全 - HKLM\..\Run: [!AVG Anti-Spyware] [一款杀毒软件AVG的相关启动程序。] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - 安全 - HKLM\..\Run: [360Safetray] [360safe实时保护功能模块。] D:\Program Files\360safe\safemon\360Tray.exe /start
O8 - 安全 - Extra context menu item: &使用迅雷下载 - e:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - 安全 - Extra context menu item: &使用迅雷下载全部链接 - e:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O16 - 安全 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (中国工商银行个人银行) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O23 - 安全 - Service: NVSvc [是NVIDIA显示卡相关程序。] - C:\WINDOWS\system32\nvsvc32.exe - (running)

=======================================

O40 - csrss.exe -  - E:\吞食资料\MemorySaviour_1_0\ClnMem.dll -  - 07e0cb83698048fc1ecbe98acdd9dfc7
O40 - csrss.exe - Microsoft Corporation - C:\WINDOWS\system32\E020FC6A.DLL -  - 9f87e40fef471cf9f5564c847dcb3226
O40 - winlogon.exe -  - E:\吞食资料\MemorySaviour_1_0\ClnMem.dll -  - 07e0cb83698048fc1ecbe98acdd9dfc7
O40 - winlogon.exe - Microsoft Corporation - C:\WINDOWS\system32\E020FC6A.DLL -  - 9f87e40fef471cf9f5564c847dcb3226
O40 - services.exe -  - E:\吞食资料\MemorySaviour_1_0\ClnMem.dll -  - 07e0cb83698048fc1ecbe98acdd9dfc7
O40 - services.exe - Microsoft Corporation - C:\WINDOWS\system32\E020FC6A.DLL -  - 9f87e40fef471cf9f5564c847dcb3226
O40 - lsass.exe -  - E:\吞食资料\MemorySaviour_1_0\ClnMem.dll -  - 07e0cb83698048fc1ecbe98acdd9dfc7
O40 - lsass.exe - Microsoft Corporation - C:\WINDOWS\system32\E020FC6A.DLL -  - 9f87e40fef471cf9f5564c847dcb3226
O40 - svchost.exe -  - E:\吞食资料\MemorySaviour_1_0\ClnMem.dll -  - 07e0cb83698048fc1ecbe98acdd9dfc7
O40 - svchost.exe - Microsoft Corporation - C:\WINDOWS\system32\E020FC6A.DLL -  - 9f87e40fef471cf9f5564c847dcb3226
O40 - svchost.exe -  - E:\吞食资料\MemorySaviour_1_0\ClnMem.dll -  - 07e0cb83698048fc1ecbe98acdd9dfc7
O40 - svchost.exe - Microsoft Corporation - C:\WINDOWS\system32\E020FC6A.DLL -  - 9f87e40fef471cf9f5564c847dcb3226
O40 - svchost.exe -  - E:\吞食资料\MemorySaviour_1_0\ClnMem.dll -  - 07e0cb83698048fc1ecbe98acdd9dfc7
O40 - svchost.exe - Microsoft Corporation - C:\WINDOWS\system32\E020FC6A.DLL -  - 9f87e40fef471cf9f5564c847dcb3226
O40 - svchost.exe -  - E:\吞食资料\MemorySaviour_1_0\ClnMem.dll -  - 07e0cb83698048fc1ecbe98acdd9dfc7
O40 - svchost.exe - Microsoft Corporation - C:\WINDOWS\system32\E020FC6A.DLL -  - 9f87e40fef471cf9f5564c847dcb3226
O40 - svchost.exe -  - E:\吞食资料\MemorySaviour_1_0\ClnMem.dll -  - 07e0cb83698048fc1ecbe98acdd9dfc7
O40 - svchost.exe - Microsoft Corporation - C:\WINDOWS\system32\E020FC6A.DLL -  - 9f87e40fef471cf9f5564c847dcb3226
O40 - svchost.exe -  - E:\吞食资料\MemorySaviour_1_0\ClnMem.dll -  - 07e0cb83698048fc1ecbe98acdd9dfc7
O40 - explorer.exe - Microsoft Corporation - C:\WINDOWS\system32\E020FC6A.DLL -  - 9f87e40fef471cf9f5564c847dcb3226
O40 - explorer.exe -  - E:\吞食资料\MemorySaviour_1_0\ClnMem.dll -  - 07e0cb83698048fc1ecbe98acdd9dfc7
O40 - explorer.exe -  - C:\WINDOWS\system32\winform.dll -  - 388ed0bf0fc21ea8138f91e7a73cb63d
O40 - explorer.exe -  - C:\WINDOWS\system32\fcmdbcs.dll -  - 9b411b779fb8271318c2a1b6aba2cc3b
O40 - explorer.exe -  - C:\WINDOWS\system32\msccrt.dll -  - 1941c04ae6d2b8ac7b0b30e5bd647583
O40 - explorer.exe -  - d:\3721\ske\contmenu.dll -  - 5f635161a9494952faf6b64f91a60fd5
O40 - explorer.exe - Kaspersky Lab - e:\Kaspersky Anti-Virus Personal\shellex.dll - Kasperksy Anti-Virus Shell Extension - 1c25d279e653701b0b37e2c705e099ca
O40 - explorer.exe - Anti-Malware Development a.s. - d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll - AVG Anti-Spyware shellexecutehook - 4c7f099b3ffde9805ae290de3e593397

=======================================

O41 - AVG Anti-Spyware Driver - AVG Anti-Spyware Driver - d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys - (running) -  -  - 7d78b7fd0ebe00f177b053a08c78e35b
O41 - AvgAsCln - AVG7 Clean Driver - C:\WINDOWS\system32\drivers\AvgAsCln.sys - (running) - AVG7 Clean Driver - GRISOFT, s.r.o. - 6d4a1da6e6d522b3ebbcbff4a3589ec5
O41 - Kl1 - Kaspersky Anti-Hacker Only Driver - C:\WINDOWS\system32\drivers\kl1.sys - (running) - Kaspersky Anti-Hacker Only Driver - Kaspersky Lab - 6d24150141f1ce115552ba3f113b04f3
O41 - Klif - spuper-ptor - C:\WINDOWS\system32\drivers\klif.sys - (running) - spuper-ptor - Kaspersky Labs - fae8aa8488abfd7ccdaee19eea24e7bf
O41 - Klmc - Kaspersky Anti-Virus Mail Checker Proxy - C:\WINDOWS\system32\drivers\klmc.sys - (running) - Kaspersky Anti-Virus Mail Checker Proxy - Kaspersky Lab - 7eb5b5c948f1a8139c0ec1935909f809
O41 - npkcrypt - nProtect KeyCrypt Driver - C:\Program Files\Tencent\QQ\npkcrypt.sys - (running) - nProtect KeyCrypt Driver - INCA Internet Co., Ltd. - 8bcb281a2540e7aff0cd00f9878fe21f
O41 - oreans32 - oreans32 - C:\WINDOWS\system32\drivers\oreans32.sys - (running) -  -  - 63617de4a5178dc455a75c8c2cbfe823
O41 - ewido anti-spyware 4.0 driver - ewido anti-spyware 4.0 driver - E:\ewido_4.0.0.172c_3.3\ewido_4.0.0.172c_3.3\guard.sys - (not running) -  -  -
O41 - kmsinput - kmsinput - C:\WINDOWS\system32\drivers\kmsinput.sys - (not running) -  -  - f8d6ebcb50c02b42c5ffd5393229c6b6
O41 - TSP - spuper-ptor - C:\WINDOWS\system32\drivers\klif.sys - (not running) - spuper-ptor - Kaspersky Labs - fae8aa8488abfd7ccdaee19eea24e7bf
O41 - 27437 - Driver - C:\WINDOWS\system32\drivers\27421.sys - (not running) - Driver - Driver - 44f6eb2567d9479a405635b1cf4d1dbc

=======================================
360Safe.exe=3.2.1.1002
AntiAdwa.dll=3.2.0.1001
AntiEng.dll=3.0.2.2000
AntiActi.dll=2.0.0.3000
CleanHis.dll=3.0.2.1000
safelive.exe=1.0.0.2007
live.dll=1.0.0.1011

=======================================
操作历史报告:
----------查杀恶意软件历史----------

2007-04-06 21:37
查杀恶意软件 - 网络实名 - 危险 - C:\Program Files\3721
查杀恶意软件 - 雅虎助手&上网助手 - 危险 - C:\Program Files\Yahoo!\Assistant
查杀恶意软件 - 广告软件ASN.2 - 危险 - C:\WINDOWS\system32\5CADA776.DLL
查杀恶意软件 - msccrt - 危险 - C:\WINDOWS\system32\msccrt.dll
查杀恶意软件 - mppds木马 - 危险 - C:\WINDOWS\system32\mppds.dll
查杀恶意软件 - GHook - 危险 - C:\Syswm1i
查杀恶意软件 - winform - 危险 - C:\WINDOWS\system32\winform.dll

2007-04-06 22:03
查杀恶意软件 - 广告软件ASN.2 - 危险 -

----------插件卸载操作历史----------

2007-04-06 21:58
插件管理 - 广告软件ASN.2 - C:\WINDOWS\system32\5CADA776.DLL
插件管理 - msccrt - C:\WINDOWS\system32\msccrt.dll
插件管理 - mppds木马 - C:\WINDOWS\system32\mppds.dll
插件管理 - 迷你PP - C:\WINDOWS\system32\XUNLEI~1.DLL
插件管理 - 比特精灵 - C:\Program Files\BitSpirit
插件管理 - 腾讯QQ附带的QQIEHelper插件 -
2007-04-06 22:11
插件管理 - msccrt - C:\WINDOWS\system32\msccrt.dll

----------修复IE浏览器操作历史----------

2007-04-06 21:40
R0 - 危险 - IE首页 - HKLM\Software\Microsoft\Internet Explorer\Main
R0 - 危险 - IE首页 - HKCU\Software\Microsoft\Internet Explorer\Main

=======================================

360安全卫士,彻底查杀各种流氓软件,全面保护系统安全,并赠送正版卡巴斯基V6.0
最新免费下载:http://www.360safe.com
wangjay1980
发表于 2007-4-6 22:35:55 | 显示全部楼层
用SRE扫http://www.kztechs.com/下载地址
3955312
 楼主| 发表于 2007-4-8 07:35:16 | 显示全部楼层
[CODE]

2007-04-08,07:27:05

System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><rem C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><rem "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002ASync><rem C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><rem C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <Memory Saviour><E:\吞食资料\MemorySaviour_1_0\MemorySaviour.exe /autorun>  []
    <TkBellExe><rem "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [N/A]
    <!AVG Anti-Spyware><"D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized>  [Anti-Malware Development a.s.]
    <Antiy Auto Update><rem C:\Program Files\Antiy Labs\Alive\AliveCenter.exe>  [N/A]
    <kernel32><rem C:\WINDOWS\Kernel32.exe>  []
    <360Safetray><D:\Program Files\360safe\safemon\360Tray.exe /start>  [奇虎网]
    <msccrt><C:\WINDOWS\msccrt.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <360Safe><Rundll32.exe D:\PROGRA~1\360safe\AntiAdwa.dll,KillAdware>  [360Safe.com]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [ORIONNET]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}><d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll>  [Anti-Malware Development a.s.]

==================================
启动文件夹
N/A

==================================
服务
[5CADA776 / 5CADA776][Stopped/Auto Start]
  <C:\WINDOWS\system32\5CADA776.EXE -service><N/A>
[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
  <d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
[E020FC6A / E020FC6A][Stopped/Auto Start]
  <C:\WINDOWS\system32\E020FC6A.EXE -service><Microsoft Corporation>
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard][Stopped/Auto Start]
  <E:\ewido_4.0.0.172c_3.3\ewido_4.0.0.172c_3.3\guard.exe><N/A>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[kavsvc / kavsvc][Stopped/Manual Start]
  <"e:\Kaspersky Anti-Virus Personal\kavsvc.exe"><Kaspersky Lab>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>

==================================
驱动程序
[27437 / 27437][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\Drivers\27421.sys><Driver>
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Running/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
  <\??\d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
[AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
  <System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
[ewido anti-spyware 4.0 driver / ewido anti-spyware 4.0 driver][Stopped/System Start]
  <\??\E:\ewido_4.0.0.172c_3.3\ewido_4.0.0.172c_3.3\guard.sys><N/A>
[hhqlsaze / hhqlsaze][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\hhqlsaze.sys><Yahoo! China Corporation>
[Kl1 / Kl1][Running/Boot Start]
  <\SystemRoot\System32\drivers\kl1.sys><Kaspersky Lab>
[Klif / Klif][Running/System Start]
  <System32\drivers\klif.sys><Kaspersky Labs>
[Klmc / Klmc][Running/System Start]
  <System32\drivers\klmc.sys><Kaspersky Lab>
[kmsinput / kmsinput][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[oreans32 / oreans32][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\oreans32.sys><N/A>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[TSP / TSP][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Labs>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[24250 / 24250][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\Drivers\24234.sys><Driver>
[579468 / 579468][Running/]
  <2 - 系统找不到指定的文件。
><N/A>

==================================
浏览器加载项
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <e:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <e:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[NavigatMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\Program Files\360safe\safemon\safemon.dll, >
[启动Web迅雷]
  {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} <http://my.xunlei.com, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[AxSubmitControl Class]
  {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL, >
[WebThunder Browser Helper]
  {00000AAA-A363-466E-BEF5-9BB68697AA7F} <e:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll, Thunder Networking Technologies,LTD>
[Web Browser Applet Control]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\WINDOWS\system32\Msjava.dll, Microsoft Corporation>
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\Mshtml.dll, N/A>
[DHTML Edit Control Safe for Scripting for IE5]
  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[RealPlayer RAM Download Handler]
  {2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Tabular Data Control]
  {333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[CEditCtrl Object]
  {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\aliedit.dll, www.alipay.com>
[MSN Photo Upload Tool]
  {4F1E5B1A-2A80-42CA-8532-2D05CB959537} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft? Corporation>
[HHCtrl Object]
  {52A2AAAE-085D-4187-97EA-8C30DB990436} <C:\WINDOWS\system32\hhctrl.ocx, Microsoft Corporation>
[Shell Name Space]
  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, N/A>
[GLAvatar Control]
  {61238DE1-3317-4322-89AC-AC844831380D} <d:\GLOBAL~1\Game\share\GLAVAT~1.OCX, >
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AxInputControl Class]
  {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, >
[Microsoft RDP Client Control (redist)]
  {7584C670-2274-4EFB-B00B-D6AABA6D3850} <C:\WINDOWS\Msrdp.ocx, N/A>
[MediaComm Class]
  {7670648D-461B-42AF-BDFE-46D26AF5EFF2} <e:\Program Files\Thunder Network\WebThunder\MediaAddin12.dll, Thunder Networking Technologies,LTD>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Thunder Browser Helper]
  {889D2FEB-5411-4565-8998-1DD2C5261283} <e:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_002.dll, Thunder Networking Technologies,LTD>
[AxSubmitControl Class]
  {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} <C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL, >
[PhotoUploadCtrl Control]
  {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} <C:\PROGRA~1\Tencent\QQ\QZone\PHOTOU~1.OCX, tencent>
[WebVGPlayer Class]
  {AA899B43-24BD-4B6B-BBD0-45557D8D11E0} <C:\PROGRA~1\VIEWGOOD\WEBPLA~1\VGPlayer.dll, >
[Microsoft Scriptlet Component]
  {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\Mshtml.dll, Microsoft Corporation>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[NavigatMon Class]
  {B69F34DD-F0F9-42DC-9EDD-957187DA688D} <D:\Program Files\360safe\safemon\safemon.dll, >
[RDS.DataSpace]
  {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__WAV Moniker Class]
  {CD3AFA7B-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[AUDIO__X_MS_WMA Moniker Class]
  {CD3AFA84-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[VIDEO__X_MS_WMV Moniker Class]
  {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[RealPlayer G2 Control]
  {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[CPasswordEditCtrl Object]
  {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
[&使用迅雷下载]
  <e:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
  <e:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用Web迅雷下载]
  <e:\Program Files\Thunder Network\WebThunder\GetUrl.htm, N/A>
[使用Web迅雷下载全部链接]
  <e:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

==================================
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-25 00:58 , Processed in 0.127230 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表