遭遇 Trojan-PSW.Win32.QQPass,Trojan.PSW.Win32.GameOL等1

遭遇 Trojan-PSW.Win32.QQPass,Trojan.PSW.Win32.GameOL等1

endurer 原创
2008-05-19 第1

上午帮一位同事的电脑装软件,进入命令提示符状态进行操作时,感觉特别卡,打开 msconfig.exe 检查开机启动项,发现了 pe_xscan 的 log中的部分 O4 项,才知道电脑中标了,不过在GUI界面下操作倒不觉得卡,可见机子硬件配置好,中了标也不倒~

下载 pe_xscan 扫描 log 并分析,发现如下可疑项(进程模块有省略):

/===
pe_xscan 08-04-26 by Purple Endurer
2008-5-19 9:20:34
Windows XP Service Pack 2(5.1.2600)
MSIE:6.0.2900.2180
管理员用户组
正常模式

[System Process] 0
<nobr>  <font color="#ff0000">C:/WINDOWS/system32/SysDaJHv.dll </font><font color="#008000">|</font> 2008-5-18 14:8:1 <font color="#008000">|</font> Microsoft(R) Windows(R) Operating System <font color="#008000">|</font> 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) <font color="#008000">|</font> Windows XP MSPLAY API DLL <font color="#008000">|</font> (C) Microsoft Corporation. All rights resad. <font color="#008000">|</font> 5.1.2600.3099 <font color="#008000">|</font> Microsoft Corporation <font color="#008000">|</font> Microsoft <font color="#008000">|</font> msplay32 <font color="#008000">|</font> msplay32</nobr>
   2008-5-18 14:3:19
   2008-5-18 14:7:8
   2008-5-18 14:7:49
   2008-5-18 14:5:59
   2008-5-18 14:7:26
   2008-5-18 14:4:6
   2008-5-18 14:4:16
   2008-5-18 14:8:13
   2008-5-18 14:8:38
   2008-5-18 14:51:9
   2008-5-18 23:59:20
   2008-5-18 14:8:50
   2004-8-8 14:29:16
   2004-8-8 14:28:40
   2004-8-8 14:27:6
   2004-8-8 14:28:38
   2008-5-18 14:7:38
   2008-5-18 14:8:26
   2008-5-18 14:9:1
   2008-5-18 14:6:45
   2008-5-18 14:6:56
   2008-5-18 14:6:34
   2008-5-18 14:6:23
   2008-5-18 14:5:48
   2008-5-18 14:5:38
   2008-5-18 14:6:11
   2008-5-18 14:5:27
   2008-5-18 14:5:13
   2008-5-18 14:5:3
   2008-5-18 14:4:44
   2008-5-18 14:3:47
   2008-5-18 14:3:28
   2008-5-18 14:4:35
   2008-5-18 14:4:25
   2008-5-18 14:4:54
C:/WINDOWS/system32/winlogon.exe 640 2005-12-14 16:0:0 Microsoft(R) Windows(R) Operating System 5.1.2600.2180 Windows NT Logon Application (C) Microsoft Corporation. All rights reserved. 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Corporation ? winlogon WINLOGON.EXE
   2008-5-18 14:8:1 Microsoft(R) Windows(R) Operating System 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) Windows XP MSPLAY API DLL (C) Microsoft Corporation. All rights resad. 5.1.2600.3099 Microsoft Corporation Microsoft msplay32 msplay32
   2008-5-18 14:3:19
   2008-5-18 14:7:8
   2008-5-18 14:7:49
   2008-5-18 14:5:59
   2008-5-18 14:7:26
   2008-5-18 14:4:6
   2008-5-18 14:4:16
   2008-5-18 14:8:13
   2008-5-18 14:8:38
   2008-5-18 14:51:9
C:/WINDOWS/system32/services.exe 732 2005-12-14 16:0:0 Microsoft(R) Windows(R) Operating System 5.1.2600.2180 Services and Controller app (C) Microsoft Corporation. All rights reserved. 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Corporation ? services.exe services.exe
   2008-5-18 14:8:1 Microsoft(R) Windows(R) Operating System 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) Windows XP MSPLAY API DLL (C) Microsoft Corporation. All rights resad. 5.1.2600.3099 Microsoft Corporation Microsoft msplay32 msplay32
   2008-5-18 14:3:19
   2008-5-18 14:7:8
   2008-5-18 14:7:49
   2008-5-18 14:5:59
   2008-5-18 14:7:26
   2008-5-18 14:4:6
   2008-5-18 14:4:16
   2008-5-18 14:8:13
   2008-5-18 14:8:38
   2008-5-18 14:51:9
C:/WINDOWS/system32/lsass.exe 744 2005-12-14 16:0:0 Microsoft? Windows? Operating System 5.1.2600.2180 LSA Shell (Export Version) ? Microsoft Corporation. All rights reserved. 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Corporation ? lsass.exe lsass.exe
   2008-5-18 14:8:1 Microsoft(R) Windows(R) Operating System 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) Windows XP MSPLAY API DLL (C) Microsoft Corporation. All rights resad. 5.1.2600.3099 Microsoft Corporation Microsoft msplay32 msplay32
   2008-5-18 14:3:19
   2008-5-18 14:7:8
   2008-5-18 14:7:49
   2008-5-18 14:5:59
   2008-5-18 14:7:26
   2008-5-18 14:4:6
   2008-5-18 14:4:16
   2008-5-18 14:8:13
   2008-5-18 14:8:38
   2008-5-18 14:51:9
C:/WINDOWS/system32/svchost.exe 996 2005-12-14 16:0:0 Microsoft? Windows? Operating System 5.1.2600.2180 Generic Host Process for Win32 Services ? Microsoft Corporation. All rights reserved. 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Corporation ? svchost.exe svchost.exe
   2008-5-18 14:8:1 Microsoft(R) Windows(R) Operating System 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) Windows XP MSPLAY API DLL (C) Microsoft Corporation. All rights resad. 5.1.2600.3099 Microsoft Corporation Microsoft msplay32 msplay32
   2008-5-18 14:3:19
   2008-5-18 14:7:8
   2008-5-18 14:7:49
   2008-5-18 14:5:59
   2008-5-18 14:7:26
   2008-5-18 14:4:6
   2008-5-18 14:4:16
   2008-5-18 14:8:13
   2008-5-18 14:8:38
   2008-5-18 14:51:9
C:/WINDOWS/Explorer.EXE 1824 2005-12-14 16:0:0 Microsoft(R) Windows(R) Operating System 6.00.2900.2180 Windows Explorer (C) Microsoft Corporation. All rights reserved. 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Corporation ? explorer EXPLORER.EXE
   2008-5-18 14:8:1 Microsoft(R) Windows(R) Operating System 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) Windows XP MSPLAY API DLL (C) Microsoft Corporation. All rights resad. 5.1.2600.3099 Microsoft Corporation Microsoft msplay32 msplay32
   2008-5-18 14:3:19
   2008-5-18 14:7:8
   2008-5-18 14:7:49
   2008-5-18 14:5:59
   2008-5-18 14:7:26
   2008-5-18 14:4:6
   2008-5-18 14:4:16
   2008-5-18 14:8:13
   2008-5-18 14:8:38
   2008-5-18 14:51:9
   2008-5-18 14:8:50
   2004-8-8 14:27:6
   2004-8-8 14:28:38
   2004-8-8 14:28:40
   2004-8-8 14:29:16
   2008-5-18 23:59:20
   2008-5-18 14:3:28
   2008-5-18 14:3:47
   2008-5-18 14:4:25
   2008-5-18 14:4:35
   2008-5-18 14:4:54
   2008-5-18 14:4:44
   2008-5-18 14:5:3
   2008-5-18 14:5:13
   2008-5-18 14:5:27
   2008-5-18 14:5:38
   2008-5-18 14:6:11
   2008-5-18 14:5:48
   2008-5-18 14:6:23
   2008-5-18 14:6:34
   2008-5-18 14:6:45
   2008-5-18 14:8:26
   2008-5-18 14:6:56
   2008-5-18 14:7:38
   2008-5-18 14:9:1
   2002-1-10 7:4:37 usrinit Module 1, 0, 0, 1 usrinit Module Copyright 2006 1, 0, 0, 1 ? usrinit usrinit.DLL
C:/WINDOWS/SoundMan.exe 508 2006-10-18 13:47:14 工程1 1.00 ? ? 1.00 1 ? di2 di2.exe
   2008-5-18 14:8:1 Microsoft(R) Windows(R) Operating System 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) Windows XP MSPLAY API DLL (C) Microsoft Corporation. All rights resad. 5.1.2600.3099 Microsoft Corporation Microsoft msplay32 msplay32
   2008-5-18 14:3:19
   2008-5-18 14:7:8
   2008-5-18 14:7:49
   2008-5-18 14:5:59
   2008-5-18 14:7:26
   2008-5-18 14:4:6
   2008-5-18 14:4:16
   2008-5-18 14:8:13
   2008-5-18 14:8:38
   2008-5-18 14:51:9
2256 2007-12-11 9:43:36 Microsoft 应用程序 1, 0, 0, 1 Microsoft 基础类应用程序 版权所有 (C) 2005 1, 0, 0, 1
   2008-5-18 14:8:1 Microsoft(R) Windows(R) Operating System 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) Windows XP MSPLAY API DLL (C) Microsoft Corporation. All rights resad. 5.1.2600.3099 Microsoft Corporation Microsoft msplay32 msplay32
   2008-5-18 14:3:19
   2008-5-18 14:7:8
   2008-5-18 14:7:49
   2008-5-18 14:5:59
   2008-5-18 14:7:26
   2008-5-18 14:4:6
   2008-5-18 14:4:16
   2008-5-18 14:8:13
   2008-5-18 14:8:38
   2008-5-18 14:51:9
   2008-5-18 14:8:50
   2004-8-8 14:27:6
   2004-8-8 14:29:16
   2004-8-8 14:28:40
   2004-8-8 14:28:38
   2008-5-18 14:7:38
   2008-5-18 14:8:26
   2008-5-18 14:9:1
   2008-5-18 14:6:45
   2008-5-18 14:6:56
   2008-5-18 14:6:34
   2008-5-18 14:6:23
   2008-5-18 14:5:48
   2008-5-18 14:5:38
   2008-5-18 14:6:11
   2008-5-18 14:5:27
   2008-5-18 14:5:13
   2008-5-18 14:5:3
   2008-5-18 14:4:44
   2008-5-18 14:3:47
   2008-5-18 14:3:28
   2008-5-18 14:4:35
   2008-5-18 14:4:25
   2008-5-18 14:4:54
   2008-5-18 23:59:20
C:/WINDOWS/system32/conime.exe 2112 2005-12-14 16:0:0 Microsoft? Windows? Operating System 5.1.2600.2180 Console IME ? Microsoft Corporation. All rights reserved. 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Corporation ? Console CONIME.EXE
   2008-5-18 14:8:1 Microsoft(R) Windows(R) Operating System 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) Windows XP MSPLAY API DLL (C) Microsoft Corporation. All rights resad. 5.1.2600.3099 Microsoft Corporation Microsoft msplay32 msplay32
   2008-5-18 14:3:19
   2008-5-18 14:7:8
   2008-5-18 14:7:49
   2008-5-18 14:5:59
   2008-5-18 14:7:26
   2008-5-18 14:4:6
   2008-5-18 14:4:16
   2008-5-18 14:8:13
   2008-5-18 14:8:38
   2008-5-18 14:51:9
   2008-5-18 23:59:20
   2008-5-18 14:8:50
   2004-8-8 14:27:6
   2004-8-8 14:28:40
   2004-8-8 14:29:16
O2 - BHO - {35694105-5108-9405-3695-954187462153} -
O2 - BHO - {398C9B84-4EF7-47B5-9862-DE29543B3C42} -
O2 - BHO - {3C648541-1025-9650-9057-6541258720C3} -
O2 - BHO - {3C8D1401-A58D-A81C-CD24-A5915C4517C3} -
O2 - BHO IEInit Class - {5B02EBA1-EFDD-477D-A37F-05383165C9C0} -
O2 - BHO - {6490415F-65F8-B5C5-D8BA-9405FB120546} -
O2 - BHO ChinaBuy Class - {85FAEA13-9C62-4917-8571-B35C563A1943} -
O2 - BHO FavHook Class - {CD8BFE70-5809-4C73-9EEE-E5672C2B79D7} -
O4 - HKLM/../Run: [RealTray]
O4 - HKLM/../Run: [fmsiocps]
O4 - HKLM/../Run: [anistio]
O4 - HKLM/../Run: [dionpis]
O4 - HKLM/../Run: [hefcndy]
O4 - HKLM/../Run: [tciocp64]
O4 - HKLM/../Run: [fmsbbqi]
O4 - HKLM/../Run: [bincdwsa]
O4 - HKLM/../Run: [dbhlp32]
O4 - HKLM/../Run: [fmsjhif]
O4 - HKLM/../Run: [kangitxp]
O4 - HKLM/../Run: [ptshell]
O4 - HKLM/../Run: [ticisms]
O4 - HKLM/../Run: [huifitc]
O4 - HKLM/../Run: [yuiabct]
O4 - HKLM/../Run: [mfchlp64]
O4 - HKLM/../Run: [dndsioc]
O4 - HKLM/../Run: [WINSvr64]
O4 - HKLM/../Run: [fmbiost]
O4 - HKLM/../Run: [cinfonmc]
O4 - HKLM/../Run: [isndntio]

O4 - HKLM/../Policies/Explorer/Run: [usrinit]
O4 - HKLM/../Policies/Explorer/Run: [WinAutoUp]
O4 - HKLM/../Policies/Explorer/Run: [adsnt]
O4 - HKLM/../Policies/Explorer/Run: [bdwinrun]
O20 - AppInit_DLLs =,,,,,,,,,,,,,
O23 - 服务: cqit (cqit) -(自动)
O23 - 服务: drop (drop) -(自动)
O23 - 服务: fmsq (fmsq) -(自动)
O23 - 服务: helpsvc (Help and Support) - 2006-12-14 6:29:29 工程1 1.00 ? ? 1.00 1 ? note note.exe(自动)
O23 - 服务: jtio (jtio) -(自动)
O23 - 服务: mnsf (mnsf) -(自动)
O23 - 服务: msfpfis64 (msfpfis64) - 2008-5-18 14:4:6(自动)
O23 - 服务: msp2p32 (msp2p32) - 2008-5-18 14:3:11(自动)

O23 - 服务: ping (ping) -(自动)
O23 - 服务: ptfs (ptfs) -(自动)
O23 - 服务: XPROTECTOR (XPROTECTOR) - 2006-2-2 17:54:55(自动)
O23 - 服务: zftp (zftp) -(自动)
O26 - IFEO: 360Loader.exe -> svchost.exe
O26 - IFEO: 360rpt.exe -> ntsd -d
O26 - IFEO: 360safe.exe -> ntsd -d
O26 - IFEO: 360safebox.exe -> ntsd -d
O26 - IFEO: 360tray.exe -> ntsd -d
O26 - IFEO: adam.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: AgentSvr.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: AppSvc32.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: ati2evxx.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: autoruns.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: avconsol.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: avgrssvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: AvMonitor.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: avp.com -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: avp.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: CCenter.exe -> ntsd -d
O26 - IFEO: ccSvcHst.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: ctfmon.exe -> SoundMan.exe
O26 - IFEO: egui.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: esafe.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: FileDsty.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: FTCleanerShell.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: HijackThis.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: IceSword -> svchost.exe
O26 - IFEO: IceSword.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: idag.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: Iparmor.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: isPwdSvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kabaload.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kaccore.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KaScrScn.SCR -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KASMain.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KASTask.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAV32.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAVDX.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAVPF.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAVPFW.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAVSetup.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAVStart.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kavsvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAVsvcUI.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KISLnchr.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kissvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kmailmon.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KMFilter.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KPFW32.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kpfwsvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KPPMain.exe -> ntsd -d
O26 - IFEO: KRegEx.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KRepair.com -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KsLoader.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVCenter.kxp -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KvDetect.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVFW.EXE -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KvfwMcl.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVMonXP_1.kxp -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kvol.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kvolself.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KvReport.kxp -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVScan.kxp -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVsrvXP.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVStub.kxp -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kvupload.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVwsc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KWatch.exe -> ntsd -d
O26 - IFEO: KWatch9x.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KWatchX.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: MagicSet.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: mcconsol.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: mmqczj.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: mmsk.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: navapsvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: Navapw32.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: nod32krn.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: NPFMntor.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: OllyDBG.EXE -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: OllyICE.EXE -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: PFW.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: PFWLiveUpdate.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: procexp.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: QHSET.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: QQDoctor.exe -> ntsd -d
O26 - IFEO: QQKav.exe -> ntsd -d
O26 - IFEO: qqsc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: ras -> svchost.exe
O26 - IFEO: Ras.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: rav.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: RavMon.exe -> ntsd -d
O26 - IFEO: RavMonD.exe -> ntsd -d
O26 - IFEO: ravstub.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: ravtask.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: ravtimer.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: ravtool.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: RegClean.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: regtool.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: rfwmain.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: rfwproxy.exeFYFireWall.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: rfwsrv.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: rfwstub.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: rising.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: Rsaupd.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: runiep -> svchost.exe
O26 - IFEO: runiep.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: safebank.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: safeboxTray.exe -> ntsd -d
O26 - IFEO: safelive.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: scan32.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: shcfg32.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: SmartUp.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: SREng.EXE -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: symlcsvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: SysSafe.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: tqat.exe -> ntsd -d
O26 - IFEO: TrojanDetector.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: Trojanwall.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: TrojDie.kxp -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UIHost.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UmxAgent.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UmxAttachment.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UmxCfg.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UmxFwHlp.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UmxPol.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UpLive.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: vsstat.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: webscanx.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: WinDbg.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: WoptiClean.exe -> C:/WINDOWS/system32/svchost.exe
HKLM/SHOWALL 值非1
===/
(未完待续)
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值