遭遇 Trojan-PSW.Win32.QQPass,Trojan.PSW.Win32.GameOL等1

简介: 遭遇 Trojan-PSW.Win32.QQPass,Trojan.PSW.Win32.GameOL等1

上午帮一位同事的电脑装软件,进入命令提示符状态进行操作时,感觉特别卡,打开 msconfig.exe 检查开机启动项,发现了 pe_xscan 的 log中的部分 O4 项,才知道电脑中标了,不过在GUI界面下操作倒不觉得卡,可见机子硬件配置好,中了标也不倒~

下载 pe_xscan 扫描 log 并分析,发现如下可疑项(进程模块有省略):

/===
pe_xscan 08-04-26 by Purple Endurer 
2008-5-19 9:20:34 
Windows XP Service Pack 2(5.1.2600) 
MSIE:6.0.2900.2180 
管理员用户组 
正常模式 
 
[System Process] * 0 

 
     
  C:/WINDOWS/system32/SysDaJHv.dll 
  | 2008-5-18 14:8:1 
  | Microsoft(R) Windows(R) Operating System 
  | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) 
  | Windows XP MSPLAY API DLL 
  | (C) Microsoft Corporation. All rights resad. 
  | 5.1.2600.3099 
  | Microsoft Corporation 
  | Microsoft 
  | msplay32 
  | msplay32
 
   C:/WINDOWS/system32/fmsiocps.dll | 2008-5-18 14:3:19 
   C:/WINDOWS/system32/msosptfs00.dll | 2008-5-18 14:7:8 
   C:/WINDOWS/system32/msosfmsq00.dll | 2008-5-18 14:7:49 
   C:/WINDOWS/system32/msosmnsf00.dll | 2008-5-18 14:5:59 
   C:/WINDOWS/system32/msosping00.dll | 2008-5-18 14:7:26 
   C:/WINDOWS/system32/msosdohs00.dll | 2008-5-18 14:4:6 
   C:/WINDOWS/system32/msoscqit00.dll | 2008-5-18 14:4:16 
   C:/WINDOWS/system32/msosdrop00.dll | 2008-5-18 14:8:13 
   C:/WINDOWS/system32/msosjtio00.dll | 2008-5-18 14:8:38 
   C:/WINDOWS/system32/kbnqzg.dll | 2008-5-18 14:51:9 
   C:/WINDOWS/system32/uhwbqp.dll | 2008-5-18 23:59:20 
   C:/Program Files/Internet Explorer/PLUGINS/Nt_Sys32.Sys | 2008-5-18 14:8:50 
   C:/WINDOWS/system32/mndhcdwd.dll | 2004-8-8 14:29:16 
   C:/WINDOWS/system32/yzztfmsn.dll | 2004-8-8 14:28:40 
   C:/WINDOWS/system32/mnmhcsrv.dll | 2004-8-8 14:27:6 
   C:/WINDOWS/system32/mpwdcapi.dll | 2004-8-8 14:28:38 
   C:/WINDOWS/system32/fmbiost.dll | 2008-5-18 14:7:38 
   C:/WINDOWS/system32/cinfonmc.dll | 2008-5-18 14:8:26 
   C:/WINDOWS/system32/isndntio.dll | 2008-5-18 14:9:1 
   C:/WINDOWS/system32/dndsioc.dll | 2008-5-18 14:6:45 
   C:/WINDOWS/system32/WINSvr64.dll | 2008-5-18 14:6:56 
   C:/WINDOWS/system32/mfchlp64.dll | 2008-5-18 14:6:34 
   C:/WINDOWS/system32/yuiabct.dll | 2008-5-18 14:6:23 
   C:/WINDOWS/system32/ticisms.dll | 2008-5-18 14:5:48 
   C:/WINDOWS/system32/ptshell.dll | 2008-5-18 14:5:38 
   C:/WINDOWS/system32/huifitc.dll | 2008-5-18 14:6:11 
   C:/WINDOWS/system32/fnqtjjjh.dll | 2008-5-18 14:5:27 
   C:/WINDOWS/system32/fmsjhif.dll | 2008-5-18 14:5:13 
   C:/WINDOWS/system32/dbhlp32.dlL | 2008-5-18 14:5:3 
   C:/WINDOWS/system32/fmsbbqi.dll | 2008-5-18 14:4:44 
   C:/WINDOWS/system32/dionpis.dll | 2008-5-18 14:3:47 
   C:/WINDOWS/system32/anistio.dll | 2008-5-18 14:3:28 
   C:/WINDOWS/system32/tciocp64.dll | 2008-5-18 14:4:35 
   C:/WINDOWS/system32/hefcndy.dll | 2008-5-18 14:4:25 
   C:/WINDOWS/system32/bincdwsa.dll | 2008-5-18 14:4:54 
C:/WINDOWS/system32/winlogon.exe* 640 | 2005-12-14 16:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Windows NT Logon Application | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | winlogon | WINLOGON.EXE 
   C:/WINDOWS/system32/SysDaJHv.dll | 2008-5-18 14:8:1 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32 
   C:/WINDOWS/system32/fmsiocps.dll | 2008-5-18 14:3:19 
   C:/WINDOWS/system32/msosptfs00.dll | 2008-5-18 14:7:8 
   C:/WINDOWS/system32/msosfmsq00.dll | 2008-5-18 14:7:49 
   C:/WINDOWS/system32/msosmnsf00.dll | 2008-5-18 14:5:59 
   C:/WINDOWS/system32/msosping00.dll | 2008-5-18 14:7:26 
   C:/WINDOWS/system32/msosdohs00.dll | 2008-5-18 14:4:6 
   C:/WINDOWS/system32/msoscqit00.dll | 2008-5-18 14:4:16 
   C:/WINDOWS/system32/msosdrop00.dll | 2008-5-18 14:8:13 
   C:/WINDOWS/system32/msosjtio00.dll | 2008-5-18 14:8:38 
   C:/WINDOWS/system32/kbnqzg.dll | 2008-5-18 14:51:9 
C:/WINDOWS/system32/services.exe* 732 | 2005-12-14 16:0:0 | Microsoft(R) Windows(R) Operating System | 5.1.2600.2180 | Services and Controller app | (C) Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | services.exe | services.exe 
   C:/WINDOWS/system32/SysDaJHv.dll | 2008-5-18 14:8:1 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32 
   C:/WINDOWS/system32/fmsiocps.dll | 2008-5-18 14:3:19 
   C:/WINDOWS/system32/msosptfs00.dll | 2008-5-18 14:7:8 
   C:/WINDOWS/system32/msosfmsq00.dll | 2008-5-18 14:7:49 
   C:/WINDOWS/system32/msosmnsf00.dll | 2008-5-18 14:5:59 
   C:/WINDOWS/system32/msosping00.dll | 2008-5-18 14:7:26 
   C:/WINDOWS/system32/msosdohs00.dll | 2008-5-18 14:4:6 
   C:/WINDOWS/system32/msoscqit00.dll | 2008-5-18 14:4:16 
   C:/WINDOWS/system32/msosdrop00.dll | 2008-5-18 14:8:13 
   C:/WINDOWS/system32/msosjtio00.dll | 2008-5-18 14:8:38 
   C:/WINDOWS/system32/kbnqzg.dll | 2008-5-18 14:51:9 
C:/WINDOWS/system32/lsass.exe* 744 | 2005-12-14 16:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | LSA Shell (Export Version) | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | lsass.exe | lsass.exe 
   C:/WINDOWS/system32/SysDaJHv.dll | 2008-5-18 14:8:1 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32 
   C:/WINDOWS/system32/fmsiocps.dll | 2008-5-18 14:3:19 
   C:/WINDOWS/system32/msosptfs00.dll | 2008-5-18 14:7:8 
   C:/WINDOWS/system32/msosfmsq00.dll | 2008-5-18 14:7:49 
   C:/WINDOWS/system32/msosmnsf00.dll | 2008-5-18 14:5:59 
   C:/WINDOWS/system32/msosping00.dll | 2008-5-18 14:7:26 
   C:/WINDOWS/system32/msosdohs00.dll | 2008-5-18 14:4:6 
   C:/WINDOWS/system32/msoscqit00.dll | 2008-5-18 14:4:16 
   C:/WINDOWS/system32/msosdrop00.dll | 2008-5-18 14:8:13 
   C:/WINDOWS/system32/msosjtio00.dll | 2008-5-18 14:8:38 
   C:/WINDOWS/system32/kbnqzg.dll | 2008-5-18 14:51:9 
C:/WINDOWS/system32/svchost.exe* 996 | 2005-12-14 16:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Generic Host Process for Win32 Services | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | svchost.exe | svchost.exe 
   C:/WINDOWS/system32/SysDaJHv.dll | 2008-5-18 14:8:1 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32 
   C:/WINDOWS/system32/fmsiocps.dll | 2008-5-18 14:3:19 
   C:/WINDOWS/system32/msosptfs00.dll | 2008-5-18 14:7:8 
   C:/WINDOWS/system32/msosfmsq00.dll | 2008-5-18 14:7:49 
   C:/WINDOWS/system32/msosmnsf00.dll | 2008-5-18 14:5:59 
   C:/WINDOWS/system32/msosping00.dll | 2008-5-18 14:7:26 
   C:/WINDOWS/system32/msosdohs00.dll | 2008-5-18 14:4:6 
   C:/WINDOWS/system32/msoscqit00.dll | 2008-5-18 14:4:16 
   C:/WINDOWS/system32/msosdrop00.dll | 2008-5-18 14:8:13 
   C:/WINDOWS/system32/msosjtio00.dll | 2008-5-18 14:8:38 
   C:/WINDOWS/system32/kbnqzg.dll | 2008-5-18 14:51:9 
C:/WINDOWS/Explorer.EXE* 1824 | 2005-12-14 16:0:0 | Microsoft(R) Windows(R) Operating System | 6.00.2900.2180 | Windows Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | explorer | EXPLORER.EXE 
   C:/WINDOWS/system32/SysDaJHv.dll | 2008-5-18 14:8:1 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32 
   C:/WINDOWS/system32/fmsiocps.dll | 2008-5-18 14:3:19 
   C:/WINDOWS/system32/msosptfs00.dll | 2008-5-18 14:7:8 
   C:/WINDOWS/system32/msosfmsq00.dll | 2008-5-18 14:7:49 
   C:/WINDOWS/system32/msosmnsf00.dll | 2008-5-18 14:5:59 
   C:/WINDOWS/system32/msosping00.dll | 2008-5-18 14:7:26 
   C:/WINDOWS/system32/msosdohs00.dll | 2008-5-18 14:4:6 
   C:/WINDOWS/system32/msoscqit00.dll | 2008-5-18 14:4:16 
   C:/WINDOWS/system32/msosdrop00.dll | 2008-5-18 14:8:13 
   C:/WINDOWS/system32/msosjtio00.dll | 2008-5-18 14:8:38 
   C:/WINDOWS/system32/kbnqzg.dll | 2008-5-18 14:51:9 
   C:/Program Files/Internet Explorer/PLUGINS/Nt_Sys32.Sys | 2008-5-18 14:8:50 
   C:/WINDOWS/system32/mnmhcsrv.dll | 2004-8-8 14:27:6 
   C:/WINDOWS/system32/mpwdcapi.dll | 2004-8-8 14:28:38 
   C:/WINDOWS/system32/yzztfmsn.dll | 2004-8-8 14:28:40 
   C:/WINDOWS/system32/mndhcdwd.dll | 2004-8-8 14:29:16 
   C:/WINDOWS/system32/uhwbqp.dll | 2008-5-18 23:59:20 
   C:/WINDOWS/system32/anistio.dll | 2008-5-18 14:3:28 
   C:/WINDOWS/system32/dionpis.dll | 2008-5-18 14:3:47 
   C:/WINDOWS/system32/hefcndy.dll | 2008-5-18 14:4:25 
   C:/WINDOWS/system32/tciocp64.dll | 2008-5-18 14:4:35 
   C:/WINDOWS/system32/bincdwsa.dll | 2008-5-18 14:4:54 
   C:/WINDOWS/system32/fmsbbqi.dll | 2008-5-18 14:4:44 
   C:/WINDOWS/system32/dbhlp32.dlL | 2008-5-18 14:5:3 
   C:/WINDOWS/system32/fmsjhif.dll | 2008-5-18 14:5:13 
   C:/WINDOWS/system32/fnqtjjjh.dll | 2008-5-18 14:5:27 
   C:/WINDOWS/system32/ptshell.dll | 2008-5-18 14:5:38 
   C:/WINDOWS/system32/huifitc.dll | 2008-5-18 14:6:11 
   C:/WINDOWS/system32/ticisms.dll | 2008-5-18 14:5:48 
   C:/WINDOWS/system32/yuiabct.dll | 2008-5-18 14:6:23 
   C:/WINDOWS/system32/mfchlp64.dll | 2008-5-18 14:6:34 
   C:/WINDOWS/system32/dndsioc.dll | 2008-5-18 14:6:45 
   C:/WINDOWS/system32/cinfonmc.dll | 2008-5-18 14:8:26 
   C:/WINDOWS/system32/WINSvr64.dll | 2008-5-18 14:6:56 
   C:/WINDOWS/system32/fmbiost.dll | 2008-5-18 14:7:38 
   C:/WINDOWS/system32/isndntio.dll | 2008-5-18 14:9:1 
   C:/WINDOWS/system32/drivers/usrinit.dll | 2002-1-10 7:4:37 | usrinit Module | 1, 0, 0, 1 | usrinit Module | Copyright 2006 | 1, 0, 0, 1 | | ? | usrinit | usrinit.DLL 
C:/WINDOWS/SoundMan.exe* 508 | 2006-10-18 13:47:14 | 工程1 | 1.00| ?| ? | 1.00 | 1| ? | di2 | di2.exe 
   C:/WINDOWS/system32/SysDaJHv.dll | 2008-5-18 14:8:1 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32 
   C:/WINDOWS/system32/fmsiocps.dll | 2008-5-18 14:3:19 
   C:/WINDOWS/system32/msosptfs00.dll | 2008-5-18 14:7:8 
   C:/WINDOWS/system32/msosfmsq00.dll | 2008-5-18 14:7:49 
   C:/WINDOWS/system32/msosmnsf00.dll | 2008-5-18 14:5:59 
   C:/WINDOWS/system32/msosping00.dll | 2008-5-18 14:7:26 
   C:/WINDOWS/system32/msosdohs00.dll | 2008-5-18 14:4:6 
   C:/WINDOWS/system32/msoscqit00.dll | 2008-5-18 14:4:16 
   C:/WINDOWS/system32/msosdrop00.dll | 2008-5-18 14:8:13 
   C:/WINDOWS/system32/msosjtio00.dll | 2008-5-18 14:8:38 
   C:/WINDOWS/system32/kbnqzg.dll | 2008-5-18 14:51:9 
 C:/WINDOWS/bdsclk.exe * 2256 | 2007-12-11 9:43:36 | Microsoft 应用程序 | 1, 0, 0, 1 | Microsoft 基础类应用程序 | 版权所有 (C) 2005 | 1, 0, 0, 1 | | | | 
   C:/WINDOWS/system32/SysDaJHv.dll | 2008-5-18 14:8:1 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32 
   C:/WINDOWS/system32/fmsiocps.dll | 2008-5-18 14:3:19 
   C:/WINDOWS/system32/msosptfs00.dll | 2008-5-18 14:7:8 
   C:/WINDOWS/system32/msosfmsq00.dll | 2008-5-18 14:7:49 
   C:/WINDOWS/system32/msosmnsf00.dll | 2008-5-18 14:5:59 
   C:/WINDOWS/system32/msosping00.dll | 2008-5-18 14:7:26 
   C:/WINDOWS/system32/msosdohs00.dll | 2008-5-18 14:4:6 
   C:/WINDOWS/system32/msoscqit00.dll | 2008-5-18 14:4:16 
   C:/WINDOWS/system32/msosdrop00.dll | 2008-5-18 14:8:13 
   C:/WINDOWS/system32/msosjtio00.dll | 2008-5-18 14:8:38 
   C:/WINDOWS/system32/kbnqzg.dll | 2008-5-18 14:51:9 
   C:/Program Files/Internet Explorer/PLUGINS/Nt_Sys32.Sys | 2008-5-18 14:8:50 
   C:/WINDOWS/system32/mnmhcsrv.dll | 2004-8-8 14:27:6 
   C:/WINDOWS/system32/mndhcdwd.dll | 2004-8-8 14:29:16 
   C:/WINDOWS/system32/yzztfmsn.dll | 2004-8-8 14:28:40 
   C:/WINDOWS/system32/mpwdcapi.dll | 2004-8-8 14:28:38 
   C:/WINDOWS/system32/fmbiost.dll | 2008-5-18 14:7:38 
   C:/WINDOWS/system32/cinfonmc.dll | 2008-5-18 14:8:26 
   C:/WINDOWS/system32/isndntio.dll | 2008-5-18 14:9:1 
   C:/WINDOWS/system32/dndsioc.dll | 2008-5-18 14:6:45 
   C:/WINDOWS/system32/WINSvr64.dll | 2008-5-18 14:6:56 
   C:/WINDOWS/system32/mfchlp64.dll | 2008-5-18 14:6:34 
   C:/WINDOWS/system32/yuiabct.dll | 2008-5-18 14:6:23 
   C:/WINDOWS/system32/ticisms.dll | 2008-5-18 14:5:48 
   C:/WINDOWS/system32/ptshell.dll | 2008-5-18 14:5:38 
   C:/WINDOWS/system32/huifitc.dll | 2008-5-18 14:6:11 
   C:/WINDOWS/system32/fnqtjjjh.dll | 2008-5-18 14:5:27 
   C:/WINDOWS/system32/fmsjhif.dll | 2008-5-18 14:5:13 
   C:/WINDOWS/system32/dbhlp32.dlL | 2008-5-18 14:5:3 
   C:/WINDOWS/system32/fmsbbqi.dll | 2008-5-18 14:4:44 
   C:/WINDOWS/system32/dionpis.dll | 2008-5-18 14:3:47 
   C:/WINDOWS/system32/anistio.dll | 2008-5-18 14:3:28 
   C:/WINDOWS/system32/tciocp64.dll | 2008-5-18 14:4:35 
   C:/WINDOWS/system32/hefcndy.dll | 2008-5-18 14:4:25 
   C:/WINDOWS/system32/bincdwsa.dll | 2008-5-18 14:4:54 
   C:/WINDOWS/system32/uhwbqp.dll | 2008-5-18 23:59:20 
C:/WINDOWS/system32/conime.exe* 2112 | 2005-12-14 16:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Console IME | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | Console | CONIME.EXE 
   C:/WINDOWS/system32/SysDaJHv.dll | 2008-5-18 14:8:1 | Microsoft(R) Windows(R) Operating System | 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) | Windows XP MSPLAY API DLL | (C) Microsoft Corporation. All rights resad. | 5.1.2600.3099 | Microsoft Corporation | Microsoft | msplay32 | msplay32 
   C:/WINDOWS/system32/fmsiocps.dll | 2008-5-18 14:3:19 
   C:/WINDOWS/system32/msosptfs00.dll | 2008-5-18 14:7:8 
   C:/WINDOWS/system32/msosfmsq00.dll | 2008-5-18 14:7:49 
   C:/WINDOWS/system32/msosmnsf00.dll | 2008-5-18 14:5:59 
   C:/WINDOWS/system32/msosping00.dll | 2008-5-18 14:7:26 
   C:/WINDOWS/system32/msosdohs00.dll | 2008-5-18 14:4:6 
   C:/WINDOWS/system32/msoscqit00.dll | 2008-5-18 14:4:16 
   C:/WINDOWS/system32/msosdrop00.dll | 2008-5-18 14:8:13 
   C:/WINDOWS/system32/msosjtio00.dll | 2008-5-18 14:8:38 
   C:/WINDOWS/system32/kbnqzg.dll | 2008-5-18 14:51:9 
   C:/WINDOWS/system32/uhwbqp.dll | 2008-5-18 23:59:20 
   C:/Program Files/Internet Explorer/PLUGINS/Nt_Sys32.Sys | 2008-5-18 14:8:50 
   C:/WINDOWS/system32/mnmhcsrv.dll | 2004-8-8 14:27:6 
   C:/WINDOWS/system32/yzztfmsn.dll | 2004-8-8 14:28:40 
   C:/WINDOWS/system32/mndhcdwd.dll | 2004-8-8 14:29:16 
O2 - BHO - {35694105-5108-9405-3695-954187462153} - C:/WINDOWS/system32/mpwdcapi.dll
O2 - BHO - {398C9B84-4EF7-47B5-9862-DE29543B3C42} - C:/Program Files/Internet Explorer/PLUGINS/Nt_Sys32.Sys
O2 - BHO - {3C648541-1025-9650-9057-6541258720C3} - C:/WINDOWS/system32/mndhcdwd.dll
O2 - BHO - {3C8D1401-A58D-A81C-CD24-A5915C4517C3} - C:/WINDOWS/system32/mnmhcsrv.dll
O2 - BHO IEInit Class - {5B02EBA1-EFDD-477D-A37F-05383165C9C0} - C:/WINDOWS/system32/drivers/usrinit.dll
O2 - BHO - {6490415F-65F8-B5C5-D8BA-9405FB120546} - C:/WINDOWS/system32/yzztfmsn.dll
O2 - BHO ChinaBuy Class - {85FAEA13-9C62-4917-8571-B35C563A1943} - C:/WINDOWS/system32/buyunion.dll
O2 - BHO FavHook Class - {CD8BFE70-5809-4C73-9EEE-E5672C2B79D7} - C:/Program Files/Deepdo/DeepdoBar/Favorite/FavBlock.dll
O4 - HKLM/../Run: [RealTray] C:/Program Files/Real/RealPlayer/Realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM/../Run: [fmsiocps] C:/WINDOWS/fmsiocps.exe
O4 - HKLM/../Run: [anistio] C:/WINDOWS/anistio.exE
O4 - HKLM/../Run: [dionpis] C:/WINDOWS/dionpis.exe
O4 - HKLM/../Run: [hefcndy] C:/WINDOWS/hefcndy.exe
O4 - HKLM/../Run: [tciocp64] C:/WINDOWS/tciocp64.exe
O4 - HKLM/../Run: [fmsbbqi] C:/WINDOWS/fmsbbqi.exe
O4 - HKLM/../Run: [bincdwsa] C:/WINDOWS/bincdwsa.exe
O4 - HKLM/../Run: [dbhlp32] C:/WINDOWS/dbhlp32.exe
O4 - HKLM/../Run: [fmsjhif] C:/WINDOWS/fmsjhif.exe
O4 - HKLM/../Run: [kangitxp] C:/WINDOWS/agtpshsy.exe
O4 - HKLM/../Run: [ptshell] C:/WINDOWS/ptshell.exe
O4 - HKLM/../Run: [ticisms] C:/WINDOWS/ticisms.exe
O4 - HKLM/../Run: [huifitc] C:/WINDOWS/huifitc.exe
O4 - HKLM/../Run: [yuiabct] C:/WINDOWS/yuiabct.exe
O4 - HKLM/../Run: [mfchlp64] C:/WINDOWS/mfchlp64.exe
O4 - HKLM/../Run: [dndsioc] C:/WINDOWS/dndsioc.exe
O4 - HKLM/../Run: [WINSvr64] C:/WINDOWS/WINSvr64.exe
O4 - HKLM/../Run: [fmbiost] C:/WINDOWS/fmbiost.exe
O4 - HKLM/../Run: [cinfonmc] C:/WINDOWS/cinfonmc.exe
O4 - HKLM/../Run: [isndntio] C:/WINDOWS/isndntio.exe

O4 - HKLM/../Policies/Explorer/Run: [usrinit] C:/WINDOWS/system32/usrinit.exe
O4 - HKLM/../Policies/Explorer/Run: [WinAutoUp] C:/WINDOWS/AutoUp.exe
O4 - HKLM/../Policies/Explorer/Run: [adsnt] C:/WINDOWS/AdsNT.exe
O4 - HKLM/../Policies/Explorer/Run: [bdwinrun] C:/WINDOWS/bdsclk.exe
O20 - AppInit_DLLs =  SysDaJHv.dll,nicozftp00.dll,fmsiocps.dll,msosptfs00.dll,msosfmsq00.dll,msosmnsf00.dll,msosmhfp00.dll,msosping00.dll,msosdohs00.dll,msoscqit00.dll,msosdrop00.dll,msosjtio00.dll,kbnqzg.dll,uhwbqp.dll 
O23 - 服务: cqit (cqit) - C:/DOCUME~1/ADMINI~1/LOCALS~1/Temp/tmp17.tmp (自动) 
O23 - 服务: drop (drop) - C:/DOCUME~1/ADMINI~1/LOCALS~1/Temp/tmp21.tmp (自动) 
O23 - 服务: fmsq (fmsq) - C:/DOCUME~1/ADMINI~1/LOCALS~1/Temp/tmp1F.tmp (自动) 
O23 - 服务: helpsvc (Help and Support) - C:/WINDOWS/system32/interne.exe | 2006-12-14 6:29:29 | 工程1 | 1.00| ?| ? | 1.00 | 1| ? | note | note.exe(自动) 
O23 - 服务: jtio (jtio) - C:/DOCUME~1/ADMINI~1/LOCALS~1/Temp/tmp23.tmp (自动) 
O23 - 服务: mnsf (mnsf) - C:/DOCUME~1/ADMINI~1/LOCALS~1/Temp/tmp19.tmp (自动) 
O23 - 服务: msfpfis64 (msfpfis64) - C:/WINDOWS/system32/drivers/msosmsfpfis64.sys | 2008-5-18 14:4:6(自动) 
O23 - 服务: msp2p32 (msp2p32) - C:/WINDOWS/system32/drivers/msosmsp2p32.sys | 2008-5-18 14:3:11(自动) 

O23 - 服务: ping (ping) - C:/DOCUME~1/ADMINI~1/LOCALS~1/Temp/tmp1D.tmp (自动) 
O23 - 服务: ptfs (ptfs) - C:/DOCUME~1/ADMINI~1/LOCALS~1/Temp/tmp1B.tmp (自动) 
O23 - 服务: XPROTECTOR (XPROTECTOR) - C:/WINDOWS/system32/drivers/Xprotector.sys | 2006-2-2 17:54:55(自动) 
O23 - 服务: zftp (zftp) - C:/DOCUME~1/ADMINI~1/LOCALS~1/Temp/tmp13.tmp(自动)
O26 - IFEO: 360Loader.exe -> svchost.exe
O26 - IFEO: 360rpt.exe -> ntsd -d
O26 - IFEO: 360safe.exe -> ntsd -d
O26 - IFEO: 360safebox.exe -> ntsd -d
O26 - IFEO: 360tray.exe -> ntsd -d
O26 - IFEO: adam.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: AgentSvr.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: AppSvc32.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: ati2evxx.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: autoruns.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: avconsol.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: avgrssvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: AvMonitor.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: avp.com -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: avp.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: CCenter.exe -> ntsd -d
O26 - IFEO: ccSvcHst.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: ctfmon.exe -> SoundMan.exe
O26 - IFEO: egui.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: esafe.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: FileDsty.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: FTCleanerShell.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: HijackThis.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: IceSword -> svchost.exe
O26 - IFEO: IceSword.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: idag.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: Iparmor.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: isPwdSvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kabaload.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kaccore.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KaScrScn.SCR -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KASMain.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KASTask.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAV32.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAVDX.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAVPF.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAVPFW.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAVSetup.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAVStart.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kavsvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KAVsvcUI.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KISLnchr.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kissvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kmailmon.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KMFilter.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KPFW32.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kpfwsvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KPPMain.exe -> ntsd -d
O26 - IFEO: KRegEx.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KRepair.com -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KsLoader.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVCenter.kxp -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KvDetect.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVFW.EXE -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KvfwMcl.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVMonXP_1.kxp -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kvol.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kvolself.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KvReport.kxp -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVScan.kxp -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVsrvXP.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVStub.kxp -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: kvupload.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KVwsc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KWatch.exe -> ntsd -d
O26 - IFEO: KWatch9x.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: KWatchX.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: MagicSet.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: mcconsol.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: mmqczj.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: mmsk.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: navapsvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: Navapw32.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: nod32krn.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: NPFMntor.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: OllyDBG.EXE -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: OllyICE.EXE -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: PFW.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: PFWLiveUpdate.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: procexp.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: QHSET.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: QQDoctor.exe -> ntsd -d
O26 - IFEO: QQKav.exe -> ntsd -d
O26 - IFEO: qqsc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: ras -> svchost.exe
O26 - IFEO: Ras.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: rav.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: RavMon.exe -> ntsd -d
O26 - IFEO: RavMonD.exe -> ntsd -d
O26 - IFEO: ravstub.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: ravtask.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: ravtimer.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: ravtool.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: RegClean.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: regtool.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: rfwmain.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: rfwproxy.exeFYFireWall.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: rfwsrv.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: rfwstub.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: rising.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: Rsaupd.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: runiep -> svchost.exe
O26 - IFEO: runiep.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: safebank.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: safeboxTray.exe -> ntsd -d
O26 - IFEO: safelive.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: scan32.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: shcfg32.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: SmartUp.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: SREng.EXE -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: symlcsvc.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: SysSafe.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: tqat.exe -> ntsd -d
O26 - IFEO: TrojanDetector.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: Trojanwall.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: TrojDie.kxp -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UIHost.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UmxAgent.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UmxAttachment.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UmxCfg.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UmxFwHlp.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UmxPol.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: UpLive.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: vsstat.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: webscanx.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: WinDbg.exe -> C:/WINDOWS/system32/svchost.exe
O26 - IFEO: WoptiClean.exe -> C:/WINDOWS/system32/svchost.exe
相关文章
|
10天前
|
弹性计算 人工智能 架构师
阿里云携手Altair共拓云上工业仿真新机遇
2024年9月12日,「2024 Altair 技术大会杭州站」成功召开,阿里云弹性计算产品运营与生态负责人何川,与Altair中国技术总监赵阳在会上联合发布了最新的“云上CAE一体机”。
阿里云携手Altair共拓云上工业仿真新机遇
|
7天前
|
机器学习/深度学习 算法 大数据
【BetterBench博士】2024 “华为杯”第二十一届中国研究生数学建模竞赛 选题分析
2024“华为杯”数学建模竞赛,对ABCDEF每个题进行详细的分析,涵盖风电场功率优化、WLAN网络吞吐量、磁性元件损耗建模、地理环境问题、高速公路应急车道启用和X射线脉冲星建模等多领域问题,解析了问题类型、专业和技能的需要。
2513 16
【BetterBench博士】2024 “华为杯”第二十一届中国研究生数学建模竞赛 选题分析
|
6天前
|
机器学习/深度学习 算法 数据可视化
【BetterBench博士】2024年中国研究生数学建模竞赛 C题:数据驱动下磁性元件的磁芯损耗建模 问题分析、数学模型、python 代码
2024年中国研究生数学建模竞赛C题聚焦磁性元件磁芯损耗建模。题目背景介绍了电能变换技术的发展与应用,强调磁性元件在功率变换器中的重要性。磁芯损耗受多种因素影响,现有模型难以精确预测。题目要求通过数据分析建立高精度磁芯损耗模型。具体任务包括励磁波形分类、修正斯坦麦茨方程、分析影响因素、构建预测模型及优化设计条件。涉及数据预处理、特征提取、机器学习及优化算法等技术。适合电气、材料、计算机等多个专业学生参与。
1520 14
【BetterBench博士】2024年中国研究生数学建模竞赛 C题:数据驱动下磁性元件的磁芯损耗建模 问题分析、数学模型、python 代码
|
2天前
|
存储 关系型数据库 分布式数据库
GraphRAG:基于PolarDB+通义千问+LangChain的知识图谱+大模型最佳实践
本文介绍了如何使用PolarDB、通义千问和LangChain搭建GraphRAG系统,结合知识图谱和向量检索提升问答质量。通过实例展示了单独使用向量检索和图检索的局限性,并通过图+向量联合搜索增强了问答准确性。PolarDB支持AGE图引擎和pgvector插件,实现图数据和向量数据的统一存储与检索,提升了RAG系统的性能和效果。
|
9天前
|
编解码 JSON 自然语言处理
通义千问重磅开源Qwen2.5,性能超越Llama
击败Meta,阿里Qwen2.5再登全球开源大模型王座
545 14
|
1月前
|
运维 Cloud Native Devops
一线实战:运维人少,我们从 0 到 1 实践 DevOps 和云原生
上海经证科技有限公司为有效推进软件项目管理和开发工作,选择了阿里云云效作为 DevOps 解决方案。通过云效,实现了从 0 开始,到现在近百个微服务、数百条流水线与应用交付的全面覆盖,有效支撑了敏捷开发流程。
19282 30
|
9天前
|
人工智能 自动驾驶 机器人
吴泳铭:AI最大的想象力不在手机屏幕,而是改变物理世界
过去22个月,AI发展速度超过任何历史时期,但我们依然还处于AGI变革的早期。生成式AI最大的想象力,绝不是在手机屏幕上做一两个新的超级app,而是接管数字世界,改变物理世界。
464 48
吴泳铭:AI最大的想象力不在手机屏幕,而是改变物理世界
|
1月前
|
人工智能 自然语言处理 搜索推荐
阿里云Elasticsearch AI搜索实践
本文介绍了阿里云 Elasticsearch 在AI 搜索方面的技术实践与探索。
18837 20
|
1月前
|
Rust Apache 对象存储
Apache Paimon V0.9最新进展
Apache Paimon V0.9 版本即将发布,此版本带来了多项新特性并解决了关键挑战。Paimon自2022年从Flink社区诞生以来迅速成长,已成为Apache顶级项目,并广泛应用于阿里集团内外的多家企业。
17526 13
Apache Paimon V0.9最新进展
|
1天前
|
云安全 存储 运维
叮咚!您有一份六大必做安全操作清单,请查收
云安全态势管理(CSPM)开启免费试用
359 4
叮咚!您有一份六大必做安全操作清单,请查收