查看: 3769|回复: 15
收起左侧

杀不死地木马

[复制链接]
zch100
发表于 2007-5-27 01:00:16 | 显示全部楼层 |阅读模式
[localimg=700,525]1[/localimg]附件是我的电脑每次开机都被卡巴扫描出来的病毒,但卡巴不能彻底删除它们。求助于大侠们!
csscz.love
发表于 2007-5-27 01:07:31 | 显示全部楼层
附件还是没看到...可能附件大了..分卷传吧
zch100
 楼主| 发表于 2007-5-27 01:09:26 | 显示全部楼层

木马

[localimg=700,525]1[/localimg]
zch100
 楼主| 发表于 2007-5-27 01:24:40 | 显示全部楼层

求助删除木马

刚才文件太大了,发不上来,现在重发,请各位大侠们帮我看看

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
aoyang
头像被屏蔽
发表于 2007-5-27 01:37:15 | 显示全部楼层
我的老大啊,你传这个上来有什么用?

下载执行System Repair Engineer (SREng)

按「智能扫描」,再按「扫描
最后,按「保存报告」,保存到桌面
SREngLOG.log 中内容完整的复制粘贴上来,不要做任何修改。
如出现无法运行,请重命名或修改扩展名,如abc.exe/abc.com/abc.bat/abc.scr等

明天你再来看别人的分析报告,闪了,好运。
zch100
 楼主| 发表于 2007-5-27 02:07:50 | 显示全部楼层

老大你真厉害,还有这样的好东东。下面是我粘上去的扫描报告



  1. 2007-05-27,02:00:46

  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs ([url]http://www.KZTechs.com[/url])

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件


  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  17.     <bxwmfmydx01c8d><C:\DOCUME~1\aaa\LOCALS~1\Temp\1explore.exe>  [N/A]
  18.     <wf5><C:\DOCUME~1\aaa\LOCALS~1\Temp\c0nime.exe>  [N/A]
  19.     <z1uu92jswib><C:\DOCUME~1\aaa\LOCALS~1\Temp\iexpl0re.exe>  [N/A]
  20.     <kkese><C:\DOCUME~1\aaa\LOCALS~1\Temp\Servera.exe>  [N/A]
  21.     <k1c9zxtfxr8><C:\DOCUME~1\aaa\LOCALS~1\Temp\crasos.exe>  [N/A]
  22.     <3q8tye714u991hv><C:\DOCUME~1\aaa\LOCALS~1\Temp\winlog0n.exe>  []
  23.     <dlm><C:\DOCUME~1\aaa\LOCALS~1\Temp\iexp10re.exe>  [N/A]
  24.     <v8kkiu8cr6><C:\DOCUME~1\aaa\LOCALS~1\Temp\exp10rer.exe>  []
  25. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  26.     <load><>  [N/A]
  27. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  28.     <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
  29.     <TVTray><>  [N/A]
  30.     <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [NVIDIA Corporation]
  31.     <AVP><"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe">  [Kaspersky Lab]
  32. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  33.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  34.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  35. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  36.     <AppInit_DLLs><C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll>  [Kaspersky Lab]
  37. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  38.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  39. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  40.     <{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.rxk>  [N/A]
  41. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
  42.     <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [Kaspersky Lab]
  43. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
  44.     <WinlogonNotify: NavLogon><C:\WINDOWS\system32\NavLogon.dll>  []

  45. ==================================
  46. 启动文件夹
  47. N/A

  48. ==================================
  49. 服务
  50. [卡巴斯基互联网安全套装6.0个人版 / AVP][Running/Auto Start]
  51.   <"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r><Kaspersky Lab>
  52. [DefWatch / DefWatch][Stopped/Auto Start]
  53.   <C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe><N/A>
  54. [Human Interface Device Access / HidServ][Stopped/Disabled]
  55.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  56. [LightScribeService Direct Disc Labeling Service / LightScribeService][Running/Auto Start]
  57.   <"C:\Program Files\Common Files\LightScribe\LSSrvc.exe"><Hewlett-Packard Company>
  58. [Distributed Application Client / Mercha2][Stopped/Auto Start]
  59.   <C:\WINDOWS\SYSTEM32\RUNDLL2000.EXE C:\WINDOWS\SYSTEM32\WBEM\QKNVU.DLL,Export 1087><Microsoft Corporation>
  60. [Symantec AntiVirus Client / Norton AntiVirus Server][Stopped/Auto Start]
  61.   <C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe><N/A>
  62. [NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  63.   <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
  64. [P4P Service / P4P Service][Running/Auto Start]
  65.   <C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
  66. [Remote Procedure Call System(RPCSx) / Remo][Stopped/Auto Start]
  67.   <C:\WINDOWS\system32\Rpcsx.exe><N/A>
  68. [Windows DDOS(DOS) / WINDDOS][Stopped/Auto Start]
  69.   <C:\WINDOWS\system32\windoss.exe><N/A>
  70. [Windows RPCS / WINRPCS][Stopped/Auto Start]
  71.   <C:\WINDOWS\system32\winrpcs.exe><N/A>

  72. ==================================
  73. 驱动程序
  74. [a347bus / a347bus][Running/Boot Start]
  75.   <\SystemRoot\system32\DRIVERS\a347bus.sys><>
  76. [a347scsi / a347scsi][Running/Boot Start]
  77.   <\SystemRoot\System32\Drivers\a347scsi.sys><>
  78. [标准 IDE/ESDI 硬盘控制器 / atapi][Running/Boot Start]
  79.   <\SystemRoot\system32\DRIVERS\atapi.sys><N/A>
  80. [Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  81.   <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
  82. [713x_Genius TV Card Capture / Cap7134][Running/Manual Start]
  83.   <system32\DRIVERS\Cap7134.sys><Philips Semiconductors>
  84. [DSDrv4 / DSDrv4][Stopped/Manual Start]
  85.   <\??\C:\PROGRA~1\10Moons\REMOTE~1\DSDrv4.sys><N/A>
  86. [VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Running/Manual Start]
  87.   <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
  88. [GMSIPCI / GMSIPCI][Stopped/Manual Start]
  89.   <\??\G:\INSTALL\GMSIPCI.SYS><N/A>
  90. [kl1 / kl1][Running/Boot Start]
  91.   <\SystemRoot\system32\drivers\kl1.sys><Kaspersky Lab>
  92. [klif / klif][Running/System Start]
  93.   <\??\C:\WINDOWS\system32\drivers\klif.sys><Kaspersky Lab>
  94. [mpjq / mpjqq][Running/Boot Start]
  95.   <\SystemRoot\System32\DRIVERS\mpjqq.sys><N/A>
  96. [MSICPL / MSICPL][Stopped/Manual Start]
  97.   <\??\G:\install4\MSICPL.sys><N/A>
  98. [NAVAP / NAVAP][Stopped/Manual Start]
  99.   <\??\C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAP.sys><N/A>
  100. [NAVAPEL / NAVAPEL][Stopped/Auto Start]
  101.   <\??\C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPEL.SYS><N/A>
  102. [NAVENG / NAVENG][Stopped/Manual Start]
  103.   <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070518.019\NAVENG.sys><Symantec Corporation>
  104. [NAVEX15 / NAVEX15][Stopped/Manual Start]
  105.   <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070518.019\NAVEX15.sys><Symantec Corporation>
  106. [Netgroup Packet Filter / NPF][Stopped/Manual Start]
  107.   <system32\DRIVERS\npf.sys><N/A>
  108. [npkcrypt / npkcrypt][Running/Auto Start]
  109.   <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  110. [NTACCESS / NTACCESS][Stopped/Manual Start]
  111.   <\??\G:\NTACCESS.sys><N/A>
  112. [nv / nv][Running/Manual Start]
  113.   <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
  114. [TV BABY2, WDM TVTuner / PhTVTune][Running/Manual Start]
  115.   <system32\DRIVERS\PhTVTune.sys><Philips Semiconductors>
  116. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  117.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  118. [RsAntiSpyware / RsAntiSpyware][Stopped/Boot Start]
  119.   <\SystemRoot\system32\drivers\RsBoot.sys><N/A>
  120. [Secdrv / Secdrv][Stopped/Manual Start]
  121.   <system32\DRIVERS\secdrv.sys><N/A>
  122. [SetupNTGLM7X / SetupNTGLM7X][Stopped/Manual Start]
  123.   <\??\G:\NTGLM7X.sys><N/A>
  124. [SymEvent / SymEvent][Stopped/Manual Start]
  125.   <\??\C:\Program Files\Symantec\SYMEVENT.SYS><N/A>
  126. [ViaIde / ViaIde][Running/Boot Start]
  127.   <\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
  128. [VIA AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start]
  129.   <system32\drivers\viaudios.sys><VIA Technologies, Inc.>
  130. [World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  131.   <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
  132. [VIMICRO USB PC Camera / ZSMC301b][Running/Manual Start]
  133.   <System32\Drivers\usbVM31b.sys><VM>

  134. ==================================
  135. 浏览器加载项
  136. [Web反病毒统计]
  137.   {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll, Kaspersky Lab>
  138. [WebActivater Control]
  139.   {3D8F74EE-8692-4F8F-B8D2-7522E732519E} <C:\WINDOWS\system32\WEBACT~1.OCX, QQ>
  140. [Windows Media Player]
  141.   {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
  142. [HTML Document]
  143.   {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
  144. [DHTML Edit Control Safe for Scripting for IE5]
  145.   {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
  146. [Windows Media Player]
  147.   {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
  148. [Microsoft Web 浏览器]
  149.   {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
  150. [Microsoft Scriptlet Component]
  151.   {AE24FDAE-03C6-11D1-8B76-0080C744F389} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
  152. [SearchAssistantOC]
  153.   {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
  154. [RDS.DataSpace]
  155.   {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
  156. [RealPlayer G2 Control]
  157.   {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
  158. [Shockwave Flash Object]
  159.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\macromed\flash\flash.ocx, Macromedia, Inc.>
  160. [CPasswordEditCtrl Object]
  161.   {E787FD25-8D7C-4693-AE67-9406BC6E22DF} <C:\WINDOWS\system32\qqedit\qqedit.dll, 腾讯科技(深圳)有限公司>
  162. [导出到 Microsoft Office Excel(&X)]
  163.   <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>
  164. [添加到QQ表情]
  165.   <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
  166. [添加到反广告黑名单]
  167.   <C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\ie_banner_deny.htm, N/A>

  168. ==================================
  169. 正在运行的进程
  170. [PID: 620][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  171. [PID: 696][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  172. [PID: 720][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  173.     [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.2.621]
  174.     [C:\WINDOWS\system32\NavLogon.dll]  [N/A, ]
  175.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  176.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.2.621]
  177. [PID: 764][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  178. [PID: 2768][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  179.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
  180.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\ShellEx.dll]  [Kaspersky Lab, 6.0.2.621]
  181.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\MSVCR80.dll]  [Microsoft Corporation, 8.00.50727.42]
  182.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\MSVCP80.dll]  [Microsoft Corporation, 8.00.50727.42]
  183.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
  184.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  185. [PID: 3552][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  186. [PID: 324][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
  187.     [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]  [Microsoft Corporation, 11.0.5510]
  188.     [C:\Program Files\WinRAR\Formats\tar.fmt]  [N/A, ]
  189.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scrchpg.dll]  [Kaspersky Lab, 6.0.2.621]
  190.     [C:\Program Files\WinRAR\Formats\gz.fmt]  [N/A, ]
  191.     [C:\Program Files\WinRAR\Formats\arj.fmt]  [N/A, ]
  192. [PID: 2492][F:\tools工具软件\杀毒工具\卡巴斯基\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
  193.     [C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.2.621]

  194. ==================================
  195. 文件关联
  196. .TXT  Error. [C:\WINDOWS\notepad.exe %1]
  197. .EXE  OK. ["%1" %*]
  198. .COM  OK. ["%1" %*]
  199. .PIF  OK. ["%1" %*]
  200. .REG  OK. [regedit.exe "%1"]
  201. .BAT  OK. ["%1" %*]
  202. .SCR  OK. ["%1" /S]
  203. .CHM  Error. ["hh.exe" %1]
  204. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  205. .INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
  206. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  207. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  208. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  209. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  210. ==================================
  211. Winsock 提供者
  212. N/A

  213. ==================================
  214. Autorun.inf
  215. N/A

  216. ==================================
  217. HOSTS 文件
  218. 127.0.0.1       localhost

  219. ==================================
  220. API HOOK
  221. RVA  错误: LoadLibraryA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF8002AF0)
  222. RVA  错误: LoadLibraryExA (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF8002CD0)
  223. RVA  错误: LoadLibraryExW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF8002E30)
  224. RVA  错误: LoadLibraryW (危险等级: 一般,  被下面模块所HOOK: Dest Addr: 0xF8002BE0)
  225. RVA  错误: GetProcAddress (危险等级: 高,  被下面模块所HOOK: Dest Addr: 0xF8002DE0)

  226. ==================================
  227. 隐藏进程
  228. N/A

  229. ==================================


复制代码
e-long
发表于 2007-5-27 02:21:17 | 显示全部楼层
着文件怎么使用呀 !我的机器里面也是这样! 都着急上火了!
jlennon
头像被屏蔽
发表于 2007-5-27 04:12:19 | 显示全部楼层
删除下面这些
c:\docume~1\aaa\locals~1\temp\exp10rer.exe
c:\docume~1\aaa\locals~1\temp\iexp10re.exe
c:\docume~1\aaa\locals~1\temp\winlog0n.exe
c:\docume~1\aaa\locals~1\temp\crasos.exe
c:\docume~1\aaa\locals~1\temp\servera.exe
c:\docume~1\aaa\locals~1\temp\iexpl0re.exe
c:\docume~1\aaa\locals~1\temp\c0nime.exe
c:\docume~1\aaa\locals~1\temp\1explore.exe

删除重启后使用SREng修复下面各项:

    启动项目 -- 注册表之如下项删除:
[v8kkiu8cr6]    <C:\DOCUME~1\aaa\LOCALS~1\Temp\exp10rer.exe>
[dlm]    <C:\DOCUME~1\aaa\LOCALS~1\Temp\iexp10re.exe>
[3q8tye714u991hv]    <C:\DOCUME~1\aaa\LOCALS~1\Temp\winlog0n.exe>
[k1c9zxtfxr8]    <C:\DOCUME~1\aaa\LOCALS~1\Temp\crasos.exe>
[kkese]    <C:\DOCUME~1\aaa\LOCALS~1\Temp\Servera.exe>
[z1uu92jswib]    <C:\DOCUME~1\aaa\LOCALS~1\Temp\iexpl0re.exe>
[wf5]    <C:\DOCUME~1\aaa\LOCALS~1\Temp\c0nime.exe>
[bxwmfmydx01c8d]    <C:\DOCUME~1\aaa\LOCALS~1\Temp\1explore.exe>

[ 本帖最后由 jlennon 于 2007-5-27 04:14 编辑 ]
jlennon
头像被屏蔽
发表于 2007-5-27 04:14:09 | 显示全部楼层
.TXT  Error. [C:\WINDOWS\notepad.exe %1]
.CHM  Error. ["hh.exe" %1]
.INI  Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
用sreng修复这三个错误文件关联
csscz.love
发表于 2007-5-27 04:35:31 | 显示全部楼层
<{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.rxk>  [N/A](参考以下网:http://hi.baidu.com/peaset/blog/ ... 91f455b219a8f5.html)

用工具 SREng 启动项目 -->服务-->Win32服务应用程序 的如下项删除
Distributed Application Client / Mercha2][Stopped/Auto Start]
  <C:\WINDOWS\SYSTEM32\RUNDLL2000.EXE C:\WINDOWS\SYSTEM32\WBEM\QKNVU.DLL,Export 1087><Microsoft Corporation>
[P4P Service / P4P Service][Running/Auto Start]
  <C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[Remote Procedure Call System(RPCSx) / Remo][Stopped/Auto Start]
  <C:\WINDOWS\system32\Rpcsx.exe><N/A>
[Windows DDOS(DOS) / WINDDOS][Stopped/Auto Start]
  <C:\WINDOWS\system32\windoss.exe><N/A>
[Windows RPCS / WINRPCS][Stopped/Auto Start]
  <C:\WINDOWS\system32\winrpcs.exe><N/A>
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-12 16:09 , Processed in 0.129362 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表