使用映像劫持,ARP欺骗,autorun.inf等技术的AV杀手mgemtjk.exe,sb.exe,qodwjay.exe,smsovct.exe等1

简介: 使用映像劫持,ARP欺骗,autorun.inf等技术的AV杀手mgemtjk.exe,sb.exe,qodwjay.exe,smsovct.exe等1

今天早上办公室的电脑打开任一网页,卡巴就报告:

 已检测到: 恶意程序 Exploit.JS.RealPlr.t URL: hxxp://***.5*20s**b*.cn/ad/images/*real**.htm

 典型的ARP病毒作怪。

 正在检查ARP地址信息,一位同事来说他的电脑不正常,鼠标指针变是带着漏斗形状,系统反应很慢,让偶帮助检修。

 在同事的电脑中打开msconfig.exe,检查开机启动项,发现如下 pe_xscan 的log中的O4项,其中一项名为:ArpInsert,原来是它在作怪。

 先把这台电脑的网线拔出来,运行 pe_xscan 扫描 log 并分析,发现如下可疑项(进程模块部分有省略,另外O1部分是安全软件添加的,所以也省略了):

===



pe_xscan 07-12-26 by Purple Endurer
2008-1-7 9:20:36
Windows XP Service Pack 2(5.1.2600)
管理员用户组

[System Process] * 0
   C:/WINDOWS/system32/kvdxsmma.dll | 2004-8-4 15:28:16
   C:/WINDOWS/Fonts/hookhelp.dll | 2008-1-4 15:22:30
   C:/WINDOWS/system32/wsmsezx.dll | 2004-8-4 21:28:40
   C:/WINDOWS/Fonts/gjcsdyc.dll | 2004-8-4 8:42:32
   C:/WINDOWS/Fonts/swrcgzc.dll | 2004-8-4 17:7:4
   C:/WINDOWS/Fonts/avwljmn.dll | 2004-8-4 17:6:50
   C:/WINDOWS/system32/avwghmn.dll | 2004-8-4 15:28:40
   C:/WINDOWS/system32/rarjepi.dll | 2004-8-4 15:28:28
   C:/WINDOWS/system32/kawdizy.dll | 2004-8-4 15:28:24
   C:/WINDOWS/system32/avzxmmn.dll | 2004-8-4 15:28:8
   C:/WINDOWS/system32/ratbspi.dll | 2004-8-4 15:28:4
   C:/WINDOWS/system32/kaqhlzy.dll | 2004-8-4 15:27:58
   C:/WINDOWS/system32/rsmyjpm.dll | 2004-8-4 15:27:46
   C:/WINDOWS/system32/okmhdzy.dll | 2004-8-4 15:27:42
C:/WINDOWS/system32/winlogon.exe * 692 | 2004-8-4 0:52:38 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Windows NT Logon Application | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | winlogon | WINLOGON.EXE
   C:/WINDOWS/system32/wsmsezx.dll | 2004-8-4 21:28:40
C:/WINDOWS/system32/services.exe * 740 | 2004-8-4 0:52:38 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Services and Controller app | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | services.exe | services.exe
   C:/WINDOWS/system32/wsmsezx.dll | 2004-8-4 21:28:40
C:/WINDOWS/system32/lsass.exe * 752 | 2004-8-4 0:52:32 | Microsoft? Windows? Operating System | 5.1.2600.2180 | LSA Shell (Export Version) | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | lsass.exe | lsass.exe
   C:/WINDOWS/system32/wsmsezx.dll | 2004-8-4 21:28:40
C:/WINDOWS/system32/svchost.exe * 908 | 2004-8-4 0:52:38 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
   C:/WINDOWS/system32/wsmsezx.dll | 2004-8-4 21:28:40
C:/WINDOWS/Explorer.EXE * 1548 | 2004-8-4 0:52:32 | Microsoft(R) Windows(R) Operating System | 6.00.2900.2180 | Windows Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | explorer | EXPLORER.EXE
   C:/WINDOWS/system32/wsmsezx.dll | 2004-8-4 21:28:40
   C:/WINDOWS/Fonts/hookhelp.dll | 2008-1-4 15:22:30
   C:/WINDOWS/system32/okmhdzy.dll | 2004-8-4 15:27:42
   C:/WINDOWS/system32/rsmyjpm.dll | 2004-8-4 15:27:46
   C:/WINDOWS/system32/kaqhlzy.dll | 2004-8-4 15:27:58
   C:/WINDOWS/system32/ratbspi.dll | 2004-8-4 15:28:4
   C:/WINDOWS/system32/avzxmmn.dll | 2004-8-4 15:28:8
   C:/WINDOWS/system32/kvdxsmma.dll | 2004-8-4 15:28:16
   C:/WINDOWS/system32/kawdizy.dll | 2004-8-4 15:28:24
   C:/WINDOWS/system32/rarjepi.dll | 2004-8-4 15:28:28
   C:/WINDOWS/system32/avwghmn.dll | 2004-8-4 15:28:40
   C:/WINDOWS/Fonts/avwljmn.dll | 2004-8-4 17:6:50
   C:/WINDOWS/Fonts/swrcgzc.dll | 2004-8-4 17:7:4
   C:/WINDOWS/919331MM.DLL | 2008-1-7 9:7:48
   C:/WINDOWS/Fonts/gjcsdyc.dll | 2004-8-4 8:42:32
   C:/PROGRA~1/baidu/bar/baidubar.dll | 2007-11-7 14:40:56 | BaiduBar Module | 2, 0, 2, 158 | BaiduBar Module | Copyright 2005 | 2, 0, 2, 158 | Baidu.com, Inc. | | BaiduBar | BaiduBar.DLL
C:/Program Files/Common Files/Real/Update_OB/realsched.exe * 1884 | 2007-12-16 21:29:32 | RealPlayer (32-bit) | 0.1.0.4279 | RealNetworks Scheduler | Copyright ? RealNetworks, Inc. 1995-2007 | 0.1.0.4279 | RealNetworks, Inc. | RealAudio(tm) is a trademark of RealNetworks, Inc. | schedapp | realsched.exe

   C:/WINDOWS/system32/kvdxsmma.dll | 2004-8-4 15:28:16
   C:/WINDOWS/Fonts/hookhelp.dll | 2008-1-4 15:22:30
C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe * 1908 | 2007-12-27 9:18:16
   C:/WINDOWS/Fonts/hookhelp.dll | 2008-1-4 15:22:30
   C:/WINDOWS/system32/kvdxsmma.dll | 2004-8-4 15:28:16
C:/Program Files/Common Files/System/qodwjay.exe * 1916 | 2007-12-27 9:18:16
   C:/WINDOWS/system32/wsmsezx.dll | 2004-8-4 21:28:40
   C:/WINDOWS/system32/kvdxsmma.dll | 2004-8-4 15:28:16
   C:/WINDOWS/Fonts/hookhelp.dll | 2008-1-4 15:22:30
   C:/WINDOWS/system32/okmhdzy.dll | 2004-8-4 15:27:42
   C:/WINDOWS/system32/rsmyjpm.dll | 2004-8-4 15:27:46
   C:/WINDOWS/system32/kaqhlzy.dll | 2004-8-4 15:27:58
   C:/WINDOWS/system32/ratbspi.dll | 2004-8-4 15:28:4
   C:/WINDOWS/system32/avzxmmn.dll | 2004-8-4 15:28:8
   C:/WINDOWS/system32/kawdizy.dll | 2004-8-4 15:28:24
   C:/WINDOWS/system32/rarjepi.dll | 2004-8-4 15:28:28
   C:/WINDOWS/system32/avwghmn.dll | 2004-8-4 15:28:40
   C:/WINDOWS/Fonts/avwljmn.dll | 2004-8-4 17:6:50
   C:/WINDOWS/Fonts/swrcgzc.dll | 2004-8-4 17:7:4
   C:/WINDOWS/Fonts/gjcsdyc.dll | 2004-8-4 8:42:32
C:/WINDOWS/system32/ctfmon.exe * 1924 | 2004-8-4 0:52:30 | Microsoft? Windows? Operating System | 5.1.2600.2180 | CTF Loader | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | CTFMON | CTFMON.EXE
   C:/WINDOWS/system32/wsmsezx.dll | 2004-8-4 21:28:40
   C:/WINDOWS/system32/kvdxsmma.dll | 2004-8-4 15:28:16
   C:/WINDOWS/Fonts/hookhelp.dll | 2008-1-4 15:22:30
C:/WINDOWS/system32/conime.exe * 204 | 2004-8-4 0:52:30 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Console IME | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | Console | CONIME.EXE
   C:/WINDOWS/system32/wsmsezx.dll | 2004-8-4 21:28:40
   C:/WINDOWS/Fonts/hookhelp.dll | 2008-1-4 15:22:30
   C:/WINDOWS/system32/kvdxsmma.dll | 2004-8-4 15:28:16
C:/WINDOWS/system32/svchost.exe * 224 | 2004-8-4 0:52:38 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
   C:/WINDOWS/system32/sb.dll | 2008-1-7 8:36:34
C:/WINDOWS/system32/svchost.exe * 412 | 2004-8-4 0:52:38 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
   C:/WINDOWS/system32/npp/ndisnpp.dll | 2004-8-4 0:52:20 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Network Monitor NDIS Network Packet Provider | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | NDISNPP.DLL | NDISNPP.DLL
C:/WINDOWS/system32/svchost.exe * 1020 | 2004-8-4 0:52:38 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
   C:/WINDOWS/system32/wsmsezx.dll | 2004-8-4 21:28:40
C:/WINDOWS/system32/svchost.exe * 2068 | 2004-8-4 0:52:38 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe
   C:/WINDOWS/system32/kvdxsmma.dll | 2004-8-4 15:28:16
   C:/WINDOWS/Fonts/hookhelp.dll | 2008-1-4 15:22:30
C:/Program Files/Common Files/System/qodwjay.exe * 10244 | 2007-12-27 9:18:16
   C:/WINDOWS/system32/kvdxsmma.dll | 2004-8-4 15:28:16
   C:/WINDOWS/Fonts/hookhelp.dll | 2008-1-4 15:22:30
C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe * 9148 | 2007-12-27 9:18:16
   C:/WINDOWS/Fonts/hookhelp.dll | 2008-1-4 15:22:30
   C:/WINDOWS/system32/kvdxsmma.dll | 2004-8-4 15:28:16
C:/Program Files/Common Files/System/qodwjay.exe * 10916 | 2007-12-27 9:18:16
   C:/WINDOWS/Fonts/hookhelp.dll | 2008-1-4 15:22:30
   C:/WINDOWS/system32/kvdxsmma.dll | 2004-8-4 15:28:16
C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe * 16572 | 2007-12-27 9:18:16
   C:/WINDOWS/system32/wsmsezx.dll | 2004-8-4 21:28:40
   C:/WINDOWS/system32/kvdxsmma.dll | 2004-8-4 15:28:16
   C:/WINDOWS/Fonts/hookhelp.dll | 2008-1-4 15:22:30
sb.exe * 32108

O2 - BHO BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:/PROGRA~1/baidu/bar/baidubar.dll
O2 - BHO  - {9963387B-212E-4643-B207-82DAEA0E713D} - C:/Program Files/Internet Explorer/PLUGINS/Wn_Sys8x.Sys

O3 - IE工具栏:  - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:/PROGRA~1/baidu/bar/baidubar.dll

O4 - HKLM/../Run: [WinSysM] C:/WINDOWS/919331M.exe
O4 - HKLM/../Run: [ArpInsert] C:/WINDOWS/system32/sb.exe
O4 - HKLM/../Run: [smsovct] C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O4 - HKLM/../Run: [jhqocsd] C:/Program Files/Common Files/System/qodwjay.exe

C:/autorun.inf
/-----
[AutoRun]
open=smsovct.exe
shell/open=打开(&O)
shell/open/Command=smsovct.exe
shell/open/Default=1
shell/explore=资源管理器(&X)
shell/explore/Command=smsovct.exe
-----/
D:/autorun.inf
/-----
[AutoRun]
open=smsovct.exe
shell/open=打开(&O)
shell/open/Command=smsovct.exe
shell/open/Default=1
shell/explore=资源管理器(&X)
shell/explore/Command=smsovct.exe
-----/
E:/autorun.inf
/-----
[AutoRun]
open=smsovct.exe
shell/open=打开(&O)
shell/open/Command=smsovct.exe
shell/open/Default=1
shell/explore=资源管理器(&X)
shell/explore/Command=smsovct.exe
-----/
F:/autorun.inf
/-----
[AutoRun]
open=smsovct.exe
shell/open=打开(&O)
shell/open/Command=smsovct.exe
shell/open/Default=1
shell/explore=资源管理器(&X)
shell/explore/Command=smsovct.exe
-----/

O6 - HKCU/Software/Policies/Microsoft/Internet Explorer/Control Panel 存在 IE或Internet选项可能受到限制

O23 - 服务: BdGuard (BdGuard) - system32/drivers/BDGuard.SYS

O23 - 服务: NPF (Netgroup Packet Filter) - system32/drivers/npf.sys | WinPcap Netgroup Packet Filter Driver | 3, 1, 0, 27 | npf | Copyright ? 2005 CACE Technologies. Copyright ? 2003-2005 NetGroup, Politecnico di Torino. | 3, 1, 0, 27 | CACE Technologies |  | NPF + TME  | npf.sys(手动)

O23 - 服务: PciHardDisk (PciHardDisk) - C:/WINDOWS/system32/drivers/pcidisk.sys(手动)

O24 - ShlExecHook: [7] - {792FADFA-BCDE-ACDF-CDEF-21054865CBA7} = C:/WINDOWS/system32/wsmsezx.dll
O24 - ShlExecHook: [E] - {E159854F-6971-3456-6941-10235412974E} = C:/WINDOWS/Fonts/hookhelp.dll
O24 - ShlExecHook: [4] - {4A57CAD1-412F-9547-713F-9641FA3FC7A4} = C:/WINDOWS/system32/okmhdzy.dll
O24 - ShlExecHook: [A] - {AE32FA58-3453-FA2D-BC49-F340348ACCEA} = C:/WINDOWS/system32/rsmyjpm.dll
O24 - ShlExecHook: [C] - {C7D81718-1314-5200-2597-58790101807C} = C:/WINDOWS/system32/kaqhlzy.dll
O24 - ShlExecHook: [4] - {47650011-3344-6688-4899-345FABCD1574} = C:/WINDOWS/system32/ratbspi.dll
O24 - ShlExecHook: [D] - {D859245F-345D-BC13-AC4F-145D47DA34FD} = C:/WINDOWS/system32/avzxmmn.dll
O24 - ShlExecHook: [D] - {DD561258-45F3-A451-F908-A258458226DD} = C:/WINDOWS/system32/kvdxsmma.dll
O24 - ShlExecHook: [9] - {9960356A-458E-DE24-BD50-268F589A56A9} = C:/WINDOWS/system32/avwlimn.dll
O24 - ShlExecHook: [9] - {98907901-1416-3389-9981-372178569989} = C:/WINDOWS/system32/kawdizy.dll
O24 - ShlExecHook: [5] - {5598FF45-DA60-F48A-BC43-10AC47853D55} = C:/WINDOWS/system32/rarjepi.dll
O24 - ShlExecHook: [7] - {778A7521-FA87-34AB-34C2-4893F3AD34C7} = C:/WINDOWS/system32/swrcfzc.dll
O24 - ShlExecHook: [8] - {8A1247C1-53DA-FF43-ABD3-345F323A48D8} = C:/WINDOWS/system32/avwghmn.dll
O24 - ShlExecHook: [A] - {A960356A-458E-DE24-BD50-268F589A56AA} = C:/WINDOWS/Fonts/avwljmn.dll
O24 - ShlExecHook: [8] - {878A7521-FA87-34AB-34C2-4893F3AD34C8} = C:/WINDOWS/Fonts/swrcgzc.dll
O24 - ShlExecHook: [4] - {4FA10261-B890-F432-A453-69F1023513F4} = C:/WINDOWS/Fonts/gjcsdyc.dll

O26 - IFEO: 360rpt.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: 360Safe.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: 360tray.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: adam.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: AgentSvr.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: AppSvc32.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: ArSwp.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: AST.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: autoruns.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: AvastU3.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: avconsol.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: avgrssvc.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: AvMonitor.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: avp.com -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: avp.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: CCenter.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: ccSvcHst.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: EGHOST.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: FileDsty.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: FTCleanerShell.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: FYFireWall.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: ghost.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: HijackThis.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: IceSword.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: iparmo.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: Iparmor.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: irsetup.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: isPwdSvc.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: kabaload.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KaScrScn.SCR -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KASMain.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KASTask.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KAV32.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KAVDX.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KAVPF.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KAVPFW.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KAVSetup.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KAVStart.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KISLnchr.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KMailMon.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KMFilter.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KPFW32.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KPFW32X.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KPfwSvc.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KRegEx.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KRepair.com -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KsLoader.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KVCenter.kxp -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KvDetect.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KvfwMcl.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KVMonXP.kxp -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KVMonXP_1.kxp -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: kvol.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: kvolself.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KvReport.kxp -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KVScan.kxp -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KVSrvXP.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KVStub.kxp -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: kvupload.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: kvwsc.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KvXP.kxp -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KvXP_1.kxp -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KWatch.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KWatch9x.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: KWatchX.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: loaddll.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: MagicSet.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: mcconsol.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: mmqczj.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: mmsk.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: Navapsvc.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: Navapw32.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: nod32.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: nod32krn.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: nod32kui.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: NPFMntor.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: PFW.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: PFWLiveUpdate.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: QHSET.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: QQDoctor.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: QQKav.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: QQSC.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: Ras.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: Rav.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: RavMon.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: RavMonD.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: RavStub.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: RavTask.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: RegClean.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: rfwcfg.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: RfwMain.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: rfwsrv.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: RsAgent.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: Rsaupd.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: rstrui.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: runiep.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: safelive.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: scan32.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: shcfg32.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: SmartUp.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: SREng.EXE -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: symlcsvc.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: SysSafe.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: TrojanDetector.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: Trojanwall.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: TrojDie.kxp -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: UIHost.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: UmxAgent.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: UmxAttachment.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: UmxCfg.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: UmxFwHlp.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: UmxPol.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: upiea.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: UpLive.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: USBCleaner.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: vsstat.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: webscanx.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: WoptiClean.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
O26 - IFEO: zjb.exe -> C:/Program Files/Common Files/Microsoft Shared/mgemtjk.exe
===/
相关文章
|
10天前
|
弹性计算 人工智能 架构师
阿里云携手Altair共拓云上工业仿真新机遇
2024年9月12日,「2024 Altair 技术大会杭州站」成功召开,阿里云弹性计算产品运营与生态负责人何川,与Altair中国技术总监赵阳在会上联合发布了最新的“云上CAE一体机”。
阿里云携手Altair共拓云上工业仿真新机遇
|
7天前
|
机器学习/深度学习 算法 大数据
【BetterBench博士】2024 “华为杯”第二十一届中国研究生数学建模竞赛 选题分析
2024“华为杯”数学建模竞赛,对ABCDEF每个题进行详细的分析,涵盖风电场功率优化、WLAN网络吞吐量、磁性元件损耗建模、地理环境问题、高速公路应急车道启用和X射线脉冲星建模等多领域问题,解析了问题类型、专业和技能的需要。
2512 16
【BetterBench博士】2024 “华为杯”第二十一届中国研究生数学建模竞赛 选题分析
|
6天前
|
机器学习/深度学习 算法 数据可视化
【BetterBench博士】2024年中国研究生数学建模竞赛 C题:数据驱动下磁性元件的磁芯损耗建模 问题分析、数学模型、python 代码
2024年中国研究生数学建模竞赛C题聚焦磁性元件磁芯损耗建模。题目背景介绍了电能变换技术的发展与应用,强调磁性元件在功率变换器中的重要性。磁芯损耗受多种因素影响,现有模型难以精确预测。题目要求通过数据分析建立高精度磁芯损耗模型。具体任务包括励磁波形分类、修正斯坦麦茨方程、分析影响因素、构建预测模型及优化设计条件。涉及数据预处理、特征提取、机器学习及优化算法等技术。适合电气、材料、计算机等多个专业学生参与。
1520 14
【BetterBench博士】2024年中国研究生数学建模竞赛 C题:数据驱动下磁性元件的磁芯损耗建模 问题分析、数学模型、python 代码
|
2天前
|
存储 关系型数据库 分布式数据库
GraphRAG:基于PolarDB+通义千问+LangChain的知识图谱+大模型最佳实践
本文介绍了如何使用PolarDB、通义千问和LangChain搭建GraphRAG系统,结合知识图谱和向量检索提升问答质量。通过实例展示了单独使用向量检索和图检索的局限性,并通过图+向量联合搜索增强了问答准确性。PolarDB支持AGE图引擎和pgvector插件,实现图数据和向量数据的统一存储与检索,提升了RAG系统的性能和效果。
|
8天前
|
编解码 JSON 自然语言处理
通义千问重磅开源Qwen2.5,性能超越Llama
击败Meta,阿里Qwen2.5再登全球开源大模型王座
539 14
|
1月前
|
运维 Cloud Native Devops
一线实战:运维人少,我们从 0 到 1 实践 DevOps 和云原生
上海经证科技有限公司为有效推进软件项目管理和开发工作,选择了阿里云云效作为 DevOps 解决方案。通过云效,实现了从 0 开始,到现在近百个微服务、数百条流水线与应用交付的全面覆盖,有效支撑了敏捷开发流程。
19282 30
|
8天前
|
人工智能 自动驾驶 机器人
吴泳铭:AI最大的想象力不在手机屏幕,而是改变物理世界
过去22个月,AI发展速度超过任何历史时期,但我们依然还处于AGI变革的早期。生成式AI最大的想象力,绝不是在手机屏幕上做一两个新的超级app,而是接管数字世界,改变物理世界。
461 48
吴泳铭:AI最大的想象力不在手机屏幕,而是改变物理世界
|
1月前
|
人工智能 自然语言处理 搜索推荐
阿里云Elasticsearch AI搜索实践
本文介绍了阿里云 Elasticsearch 在AI 搜索方面的技术实践与探索。
18837 20
|
1月前
|
Rust Apache 对象存储
Apache Paimon V0.9最新进展
Apache Paimon V0.9 版本即将发布,此版本带来了多项新特性并解决了关键挑战。Paimon自2022年从Flink社区诞生以来迅速成长,已成为Apache顶级项目,并广泛应用于阿里集团内外的多家企业。
17526 13
Apache Paimon V0.9最新进展
|
1天前
|
云安全 存储 运维
叮咚!您有一份六大必做安全操作清单,请查收
云安全态势管理(CSPM)开启免费试用
358 4
叮咚!您有一份六大必做安全操作清单,请查收