kwhcommonpop删除.exe是病毒吗,提示是金山毒霸附带的

置百丈玄冰而崩裂,掷须臾池水而漂摇。
kwhcommonpop.exe是什么进程?我们使用自带的弹窗定位器将其定位,原来是金山毒霸所带的一个进程,该进程所在路径为:“D:\Program Files (x86)\kingsoft antivirus\”小编把金山毒霸安装在D盘,很显然这是金山毒霸里面的一个进程,这个进程有什么作用呢?其实,从上面的图片里,我们可以看到,我们定位的是什么呀?是一个天猫双十一抢红包的弹窗:“一个红包未领取,最高1111元。”通过定位上图双11红包的弹窗,我们发现这个弹窗是kwhcommonpop.exe进程弹出来的,这说明什么?这说明kwhcommonpop.exe进程就是弹窗广告进程。我们再来看看kwhcommonpop.exe的属性,关于该进程的说明是:Kingsoft cmpp tool,反正就是金山软件的一个工具,cmpp大概的意思应该就是猎豹弹窗的意思,cm是猎豹的英文简称嘛;文件修改日期是日,双11之前刚发布的新版本;这样就不奇怪,为什么是该进程弹出双11红包的窗口了。那么这个kwhcommonpop.exe是病毒吗?不是的,顶多算得上是广告程序,双十一就要到,联想到前段时间金山毒霸里面冒出一个,这双十一已经是全民疯狂的日子,剁手党要疯狂的买买买,有推广渠道的也疯狂地推广,譬如金山毒霸官方这样肆无忌惮地推广双十一红包。最后的题外话,有句话叫:免费是最贵的,之后,公司还要运作吧,开发人员还要发工资吧,彻底免费了怎么赚钱呢?于是,大部分的免费杀毒软件都会有广告,只是广告明显程度不同而已,像kwhcommonpop.exe进程这么明目张胆地弹广告,也实在是过分了些。
记住我,下次回复时不用重新输入个人信息只需一步,快速开始
后使用快捷导航
中了木马病毒 好象是下载器一类的
该用户从未签到
马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。
才可以下载或查看,没有帐号?
中的木马 图上有&&还有那几个都是 用你说的那个软件智能扫描了的
这个是清理专家清理以后&&重起机器以后连上网的
,20:58:32
System Repair Engineer 2.5.16.900
Smallfrogs ()
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
& & 所有的启动项目(包括注册表、启动文件夹、服务等)
& & 浏览器加载项
& & 正在运行的进程(包括进程模块信息)
& & 文件关联
& & Winsock 提供者
& & Autorun.inf
& & HOSTS 文件
& & 进程特权扫描
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
& & &ctfmon.exe&&C:\WINDOWS\system32\ctfmon.exe&&&[(Verified)Microsoft Windows Publisher]
& & &KavPFW&&&C:\KAV2007\KPFW32.EXE&&&&[Kingsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
& & &load&&&&&[N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
& & &IMJPMIG8.1&&&C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE& /Spoil /RemAdvDef /Migration32&&&[(Verified)Microsoft Windows Publisher]
& & &PHIME2002ASync&&C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC&&&[(Verified)Microsoft Windows Publisher]
& & &PHIME2002A&&C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName&&&[(Verified)Microsoft Windows Publisher]
& & &MSPY2002&&C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC&&&[(Verified)Microsoft Windows Publisher]
& & &Alert&&C:\Program Files\Starsoftcomm\StarCenter\alert.exe&&&[]
& & &StarCenter&&C:\Program Files\Starsoftcomm\StarCenter\StarCenter.exe&&&[starsoftcomm]
& & &AutoUpd&&C:\Program Files\Starsoftcomm\StarCenter\UpdTray.exe&&&[]
& & &SiSPower&&Rundll32.exe SiSPower.dll,ModeAgent&&&[Silicon Integrated Systems Corporation]
& & &THTFMo&&THTFMo.exe&&&[]
& & &SKDaemon&&C:\Program Files\THTF\THTF Keyboard Driver\Eudemon.exe&&&[]
& & &IMSCMig&&C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload&&&[(Verified)Microsoft Corporation]
& & &KavStart&&&C:\KAV2007\KAVStart.exe& -startup&&&[Kingsoft Corporation]
& & &miniqqlive&&&D:\QQLive\MiniQQLive.exe&&&&[Tencent]
& & &CertificateRegistration&&SafeSignCertReg.exe&&&[A.E.T. Europe B.V.]
& & &WinSys&&C:\WINDOWS\IGW.exe&&&[]
& & &WinSysM&&C:\WINDOWS\IGM.exe&&&[]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
& & &MSDCG32& & &&LYLeador.exe&&&[N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
& & &shell&&Explorer.exe&&&[(Verified)Microsoft Windows Component Publisher]
& & &Userinit&&C:\WINDOWS\system32\Userinit.exe&&&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
& & &AppInit_DLLs&&rsztcpm.dll&&&[]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
& & &UIHost&&logonui.exe&&&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
& & &{5B681598-AD5F-BC8C-77DC-748FAC8D3FB5}&&C:\WINDOWS\system32\kafyezy.dll&&&[]
& & &{3ADA-FF43-ABD3-345F323A48D3}&&C:\WINDOWS\system32\avwgcmn.dll&&&[N/A]
& & &{57D-}&&C:\WINDOWS\system32\kaqhezy.dll&&&[N/A]
& & &{4E32FA58-3453-FA2D-BC49-F340348ACCE4}&&C:\WINDOWS\system32\rsmydpm.dll&&&[N/A]
& & &{-DACF-3452-CB7D-3}&&C:\WINDOWS\system32\rsztcpm.dll&&&[]
& & &{22FAACDE-34DA-CCD4-AB4D-DA}&&C:\WINDOWS\system32\rsjzbpm.dll&&&[N/A]
& & &{6-}&&C:\WINDOWS\system32\kawdbzy.dll&&&[]
& & &{2598FF45-DA60-F48A-BC43-10AC47853D52}&&C:\WINDOWS\system32\rarjbpi.dll&&&[]
& & &{F90-34A0-ACD05F42}&&C:\WINDOWS\system32\raqjbpi.dll&&&[N/A]
& & &{4-5FABCD1566}&&C:\WINDOWS\system32\ratbfpi.dll&&&[N/A]
& & &{8E-DE24-BD50-268F589A56A2}&&C:\WINDOWS\system32\avwlbmn.dll&&&[]
& & &{3-FADC-B443-4732ABCD3781}&&C:\WINDOWS\system32\sidjazy.dll&&&[N/A]
& & &{3C87A354-ABC3-DEDE-FF33-C3}&&C:\WINDOWS\system32\kvdxcma.dll&&&[]
& & &{5D-BC13-AC4F-145D47DA34F4}&&C:\WINDOWS\system32\avzxdmn.dll&&&[]
& & &{2A7-D98A-C8D5-A2}&&C:\WINDOWS\system32\kapjbzy.dll&&&[N/A]
& & &{4ADA-FF43-ABD3-345F323A48D4}&&C:\WINDOWS\system32\avwgdmn.dll&&&[]
& & &{2DF3-A451-F908-A}&&C:\WINDOWS\system32\kvdxsbma.dll&&&[]
& & &{67D-}&&C:\WINDOWS\system32\kaqhfzy.dll&&&[]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\&{d38-484f-9b9e-dec}]
& & &Internet Explorer&&%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE&&&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\&{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
& & &Outlook Express&&%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE&&&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09--FED}]
& & &Themes Setup&&%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll&&&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
& & &Microsoft Outlook Express 6&&&%ProgramFiles%\Outlook Express\setup50.exe& /APP:OE /CALLER:WINNT /user /install&&&[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
& & &NetMeeting 3.01&&rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT&&&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{e7d-11d1-bc44-00c04fd912be}]
& & &Windows Messenger 4.7&&rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser&&&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
& & &Microsoft Windows Media Player&&rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub&&&[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{71-11d2-AF11-00C04FA35D02}]
& & &通讯簿 6&&&%ProgramFiles%\Outlook Express\setup50.exe& /APP:WAB /CALLER:WINNT /user /install&&&[N/A]
==================================
启动文件夹
[腾讯QQ]
&&&C:\Documents and Settings\Admin\「开始」菜单\程序\启动\腾讯QQ.lnk --& D:\QQ2007\QQ.exe [TENCENT]&&H&
==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
&&&C:\WINDOWS\System32\svchost.exe -k netsvcs--&%SystemRoot%\System32\hidserv.dll&&N/A&
[Kingsoft Personal Firewall Service / KPfwSvc][Running/Auto Start]
&&&&C:\KAV2007\KPfwSvc.EXE&&&Kingsoft Corporation&
[Kingsoft Antivirus KWatch Service / KWatchSvc][Running/Auto Start]
&&&C:\KAV2007\KWatch.EXE&&Kingsoft Corporation&
[Telephotsgoogle / Winownes][Stopped/Auto Start]
&&&C:\WINDOWS\system32\sedrsvedt.exe&&N/A&
==================================
驱动程序
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
&&&system32\drivers\ALCXWDM.SYS&&Realtek Semiconductor Corp.&
[AliIde / AliIde][Stopped/Boot Start]
&&&\SystemRoot\System32\DRIVERS\aliide.sys&&N/A&
[CmdIde / CmdIde][Running/Boot Start]
&&&\SystemRoot\System32\DRIVERS\cmdide.sys&&CMD Technology, Inc.&
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
&&&system32\DRIVERS\fetnd5.sys&&VIA Technologies, Inc.&
[usb Card Device / ft2kEnum][Running/Manual Start]
&&&system32\DRIVERS\ic2kenum.sys&&OEM Corporation&
[USB Chip Holder Service / GDBaseSmc][Running/Manual Start]
&&&system32\DRIVERS\Chip_smc.sys&&OEM&
[USB Chip Service / GD_USB][Stopped/Manual Start]
&&&system32\DRIVERS\Chip_usb.sys&&&
[KNetWch / KNetWch][Running/System Start]
&&&\??\C:\KAV2007\KNetWch.SYS&&Kingsoft Corporation&
[KWatch3 / KWatch3][Running/System Start]
&&&\??\C:\WINDOWS\system32\drivers\KWatch3.SYS&&Kingsoft Corporation&
[MegaIDE / MegaIDE][Running/Boot Start]
&&&\SystemRoot\System32\DRIVERS\MegaIDE.sys&&LSI Logic Corporation.&
[npkcrypt / npkcrypt][Stopped/Manual Start]
&&&\??\C:\WINDOWS\system32\npkcrypt.sys&&N/A&
[npkycryp / npkycryp][Stopped/Manual Start]
&&&\??\C:\WINDOWS\system32\npkycryp.sys&&N/A&
[nv / nv][Stopped/Manual Start]
&&&system32\DRIVERS\nv4_mini.sys&&NVIDIA Corporation&
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
&&&system32\DRIVERS\ptilink.sys&&Parallel Technologies, Inc.&
[QKeyServiceDisplay / QKeyService][Running/Boot Start]
&&&\SystemRoot\system32\KeyCrypt.sys&&Tencent Technology (Shenzhen) Company Limited&
[SmartCard Reader Device&&/ Reader_Device][Running/Manual Start]
&&&system32\DRIVERS\usbic2k.sys&&OEM&
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
&&&system32\DRIVERS\RTL8139.SYS&&Realtek Semiconductor Corporation&
[SCBACK / SCBACK][Stopped/Boot Start]
&&&\SystemRoot\System32\drivers\SCBACK.SYS&&StarSoftComm&
[Secdrv / Secdrv][Stopped/Manual Start]
&&&system32\DRIVERS\secdrv.sys&&N/A&
[SiS315 / SiS315][Running/Manual Start]
&&&system32\DRIVERS\sisgrp.sys&&Silicon Integrated Systems Corporation&
[SiS AGP Filter / SISAGP][Running/Boot Start]
&&&\SystemRoot\system32\DRIVERS\SISAGPX.sys&&Silicon Integrated Systems Corporation&
[SiSkp / SiSkp][Running/System Start]
&&&system32\DRIVERS\srvkp.sys&&Silicon Integrated Systems Corporation&
[PS/2 Keyboard Filter Driver for Win2KXP / Skkbdf][Running/Manual Start]
&&&system32\DRIVERS\SKTHTFK.sys&&Silitek Corp.&
[SSCFLTXP / SSCFLTXP][Running/Boot Start]
&&&\SystemRoot\System32\drivers\SSCFLTXP.SYS&&Windows (R) 2000 DDK provider&
[Samsung Mobile USB Device 1.0 driver (WDM) / ss_bus][Stopped/Manual Start]
&&&system32\DRIVERS\ss_bus.sys&&MCCI&
[SAMSUNG Mobile USB Modem 1.0 Filter / ss_mdfl][Stopped/Manual Start]
&&&system32\DRIVERS\ss_mdfl.sys&&MCCI&
[SAMSUNG Mobile USB Modem 1.0 Drivers / ss_mdm][Stopped/Manual Start]
&&&system32\DRIVERS\ss_mdm.sys&&MCCI&
[TesSafe / TesSafe][Stopped/Manual Start]
&&&\??\C:\WINDOWS\system32\TesSafe.sys&&N/A&
[ViaIde / ViaIde][Running/Boot Start]
&&&\SystemRoot\system32\DRIVERS\viaide.sys&&Microsoft Corporation&
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
&&&system32\DRIVERS\WSTCODEC.SYS&&Microsoft Corporation&
[KAVBootC / KAVBootC][Running/Boot Start]
&&&\SystemRoot\system32\Drivers\KAVBootC.sys&&Kingsoft Corporation&
==================================
浏览器加载项
[ThunderAtOnce Class]
&&{01443AEC-0FD1-40fd-9C87-E93D} &D:\迅雷\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD&
[CBrowseStakeout Class]
&&{E-470E-8A57-} &C:\KAV2007\KAVAFish.DLL, Kingsoft Corporation&
[Thunder Browser Helper]
&&{889D2FEB-98-1DD2C5261283} &D:\迅雷\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD&
[启动迅雷5]
&&{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} &D:\迅雷\Thunder.exe, Thunder Networking Technologies,LTD&
[信息检索(&R)]
&&{CC-41C8-B9BE-3C9C571A8263} &C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL, Microsoft Corporation&
[Windows Genuine Advantage Validation Tool]
&&{A-453E-A040-C7C580BBF700} &C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation&
[EditCtrl Class]
&&{488AB3-8F27-FA1AECAA8844} &C:\WINDOWS\system32\aliedit\aliedit.dll, &
[AxSubmitControl Class]
&&{8D9E0B29-563C--5FF2AE77E1D2} &C:\WINDOWS\system32\SUBMIT~1.DLL, &
[Shockwave Flash Object]
&&{D27CDB6E-AE6D-11CF-96B8-} &C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.&
[ThunderAtOnce Class]
&&{01443AEC-0FD1-40FD-9C87-E93D} &D:\迅雷\ComDlls\TDAtOnce_Now.dll, Thunder Networking Technologies,LTD&
[InfosecCertInstall Class]
&&{0EB487C8-E9AC-43A6-8C4C-2F} &C:\WINDOWS\system32\certInStall.dll, &
[HTML Document]
&&{F9-11CF-8FD0-00AA00686F13} &%SystemRoot%\system32\mshtml.dll, N/A&
[Thunder Agent Class]
&&{-8FB2-4B3B-B29B-8B919B0EACCE} &D:\迅雷\ComDlls\ThunderAgent_Now.dll, Thunder Networking Technologies,LTD&
[CBrowseStakeout Class]
&&{E-470E-8A57-} &C:\KAV2007\KAVAFish.DLL, Kingsoft Corporation&
[PowerPlayer Control]
&&{5EC7C511-CD0F-42E6-830C-1BD} &D:\pp\PPStream\POWERP~1.DLL, PPStream Inc.&
[InfoSecNetSign Class]
&&{62B938C4--8CF0-A92B0A91CC77} &C:\WINDOWS\system32\NetSign.dll, Infosec Technologies Co., Ltd.&
[XMP Class]
&&{8-4C41-AACC-52D4D7845851} &C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xplayer.dll_1_work, &
[XDRM]
&&{693571CB-54A3-4E90-9D52-EEAE} &C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\xdrm.dll_1_work, &
[Windows Media Player]
&&{6BF52A52-394A-11D3-B153-00C04F79FAA6} &C:\WINDOWS\system32\wmp.dll, Microsoft Corporation&
[AxInputControl Class]
&&{73E4740C-08EB-D0A7C9EE3CD} &C:\WINDOWS\system32\INPUTC~1.DLL, &
[MediaComm Class]
&&{1B-42AF-BDFE-46D26AF5EFF2} &D:\迅雷\Components\InMedia\MediaAddin13.dll, Thunder Networking Technologies,LTD&
[Microsoft Web 浏览器]
&&{A-11D0-A96B-00C04FD705A2} &C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation&
[Thunder Browser Helper]
&&{889D2FEB-98-1DD2C5261283} &D:\迅雷\ComDlls\xunleiBHO_Now.dll, Thunder Networking Technologies,LTD&
[AxSubmitControl Class]
&&{8D9E0B29-563C--5FF2AE77E1D2} &C:\WINDOWS\system32\SUBMIT~1.DLL, &
[RMGetLicense Class]
&&{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} &C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation&
[SearchAssistantOC]
&&{B45FF030--85DE-00C04FA35C89} &%SystemRoot%\system32\shdocvw.dll, N/A&
[RDS.DataSpace]
&&{BD96C556-65A3-11D0-983A-00C04FC29E36} &C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation&
[CSetLET Class]
&&{C35D7AE1--BF07-29FA} &C:\WINDOWS\system32\GDSetLET.dll, &
[Shockwave Flash Object]
&&{D27CDB6E-AE6D-11CF-96B8-} &C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.&
[Thunder DapPlayer]
&&{EEDD6FF9-13DE-496B-9A1C-D78B} &D:\迅雷\Components\DownAndPlay\DapPlayer3.0.28.50.dll, ShenZhen Thunder Networking Technologies Ltd.&
[XPPlayer Class]
&&{F3E70CEA-956E-49CC-B444-73AFE593AD7F} &C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\pplayer.dll_1_work, Thunder&
[&使用超级旋风下载]
&&&D:\超级旋风\geturl.htm, N/A&
[&使用超级旋风下载全部链接]
&&&D:\超级旋风\getAllurl.htm, N/A&
[使用迅雷下载]
&&&D:\迅雷\Program\geturl.htm, N/A&
[使用迅雷下载全部链接]
&&&D:\迅雷\Program\getallurl.htm, N/A&
[添加到QQ表情]
&&&D:\QQ2007\AddEmotion.htm, N/A&
[反钓鱼...]
&&&C:\KAV2007\KAF\ShowSet.htm, N/A&
==================================
正在运行的进程
[PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 500 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 524 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
& & [C:\WINDOWS\system32\msacm32.drv]&&[Microsoft Corporation, 5.1.2600.0 (xpclient.8)]
[PID: 568 / SYSTEM][C:\WINDOWS\system32\services.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 580 / SYSTEM][C:\WINDOWS\system32\lsass.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 732 / SYSTEM][C:\WINDOWS\system32\svchost.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 792 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 856 / SYSTEM][C:\WINDOWS\System32\svchost.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 908 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 992 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 1140 / SYSTEM][C:\KAV2007\KWatch.EXE]&&[Kingsoft Corporation, , 78]
& & [C:\KAV2007\KAVIPC2.DLL]&&[Kingsoft Corporation, , 30]
& & [C:\KAV2007\KAEPlat.DLL]&&[Kingsoft Corp., , 64]
& & [C:\KAV2007\KAEMem.DAT]&&[Kingsoft, , 16]
& & [C:\KAV2007\KAEUnpack.DAT]&&[Kingsoft Corp., , 134]
& & [C:\KAV2007\KAVQuara.DLL]&&[Kingsoft Corporation, , 4]
& & [C:\KAV2007\KAVDevC.dll]&&[Kingsoft Corporation, , 12]
[PID: 1348 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_gdr.9)]
& & [C:\WINDOWS\system32\mdimon.dll]&&[Microsoft Corporation, 11.3.2175.0]
& & [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]&&[Microsoft Corporation, 11.3.2175.0]
[PID: 1352 / Admin][C:\WINDOWS\Explorer.EXE]&&[Microsoft Corporation, 6.00. (xpsp_sp2_gdr.4)]
& & [C:\WINDOWS\system32\msacm32.drv]&&[Microsoft Corporation, 5.1.2600.0 (xpclient.8)]
& & [C:\KAV2007\KASocket.dll]&&[Kingsoft Corporation, , 241]
& & [C:\KAV2007\KMailOEBand.dll]&&[Kingsoft Corporation, , 139]
& & [C:\WINDOWS\system32\MSVCR71.dll]&&[Microsoft Corporation, 7.10.3052.4]
& & [C:\WINDOWS\system32\MSVCP71.dll]&&[Microsoft Corporation, 7.10.3077.0]
& & [C:\WINDOWS\system32\rsztcpm.dll]&&[N/A, ]
& & [C:\WINDOWS\system32\kvdxsbma.dll]&&[N/A, ]
& & [C:\WINDOWS\system32\kaqhfzy.dll]&&[N/A, ]
& & [D:\QQ2007\DShared.dll]&&[Tencent, 1, 6, 0, 2]
& & [D:\迅雷\ComDlls\TDAtOnce_Now.dll]&&[Thunder Networking Technologies,LTD, 1.0.5.16]
& & [D:\迅雷\ComDlls\xunleiBHO_Now.dll]&&[Thunder Networking Technologies,LTD, 5, 0, 8, 42]
& & [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll]&&[Microsoft Corporation, 11.0.5510]
[PID: 1404 / LOCAL SERVICE][C:\WINDOWS\System32\SCardSvr.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 1656 / SYSTEM][C:\KAV2007\KPfwSvc.EXE]&&[Kingsoft Corporation, , 39]
[PID: 1676 / SYSTEM][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]&&[Microsoft Corporation, 7.00.9466]
& & [C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\2052\mdmui.dll]&&[Microsoft Corporation, 7.00.9466]
& & [C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MSDBG2.DLL]&&[Microsoft Corporation, 7.00.9466]
[PID: 1720 / SYSTEM][C:\WINDOWS\system32\svchost.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 1760 / SYSTEM][C:\program files\internet explorer\IEXPLORE.EXE]&&[Microsoft Corporation, 6.00. (xpsp_sp2_rtm.8)]
& & [C:\WINDOWS\system32\rsztcpm.dll]&&[N/A, ]
& & [C:\WINDOWS\system32\kvdxsbma.dll]&&[N/A, ]
& & [C:\WINDOWS\system32\kaqhfzy.dll]&&[N/A, ]
[PID: 1992 / Admin][C:\Program Files\Starsoftcomm\StarCenter\alert.exe]&&[, 1, 0, 0, 123]
& & [C:\Program Files\Starsoftcomm\StarCenter\MFC42.DLL]&&[Microsoft Corporation, 6.00.9586.0]
& & [C:\KAV2007\KASocket.dll]&&[Kingsoft Corporation, , 241]
& & [C:\KAV2007\KMailOEBand.dll]&&[Kingsoft Corporation, , 139]
& & [C:\WINDOWS\system32\MSVCR71.dll]&&[Microsoft Corporation, 7.10.3052.4]
& & [C:\WINDOWS\system32\MSVCP71.dll]&&[Microsoft Corporation, 7.10.3077.0]
& & [C:\WINDOWS\system32\rsztcpm.dll]&&[N/A, ]
& & [D:\QQ2007\DShared.dll]&&[Tencent, 1, 6, 0, 2]
[PID: 2016 / Admin][C:\Program Files\Starsoftcomm\StarCenter\StarCenter.exe]&&[starsoftcomm, 1, 0, 0, 113]
& & [C:\Program Files\Starsoftcomm\StarCenter\MFC42.DLL]&&[Microsoft Corporation, 6.00.9586.0]
& & [C:\Program Files\Starsoftcomm\StarCenter\SmartBackup.dll]&&[SSC, 1, 0, 1, 142]
& & [C:\Program Files\Starsoftcomm\StarCenter\drvKernel.dll]&&[, 1, 0, 0, 116]
& & [C:\Program Files\Starsoftcomm\StarCenter\SC_SystemProtect.DLL]&&[N/A, ]
& & [C:\Program Files\Starsoftcomm\StarCenter\Asset.DLL]&&[, 1, 0, 0, 110]
& & [C:\Program Files\Starsoftcomm\StarCenter\DiskMonitor.DLL]&&[, 1, 0, 0, 108]
& & [C:\Program Files\Starsoftcomm\StarCenter\DrvMonitor.DLL]&&[, 1, 0, 0, 111]
& & [C:\KAV2007\KMailOEBand.dll]&&[Kingsoft Corporation, , 139]
& & [C:\WINDOWS\system32\MSVCR71.dll]&&[Microsoft Corporation, 7.10.3052.4]
& & [C:\WINDOWS\system32\MSVCP71.dll]&&[Microsoft Corporation, 7.10.3077.0]
& & [C:\KAV2007\KASocket.dll]&&[Kingsoft Corporation, , 241]
& & [C:\Program Files\Starsoftcomm\StarCenter\HookMgr.dll]&&[, 1, 0, 0, 109]
& & [C:\Program Files\Starsoftcomm\StarCenter\SSCRegAc.dll]&&[, 1, 0, 0, 109]
& & [C:\Program Files\Starsoftcomm\StarCenter\SoftFunc.dll]&&[, 1, 0, 0, 108]
& & [C:\Program Files\Starsoftcomm\StarCenter\Encrypt.dll]&&[N/A, ]
& & [C:\Program Files\Starsoftcomm\StarCenter\sscac.dll]&&[N/A, ]
& & [D:\QQ2007\DShared.dll]&&[Tencent, 1, 6, 0, 2]
[PID: 2032 / Admin][C:\Program Files\Starsoftcomm\StarCenter\UpdTray.exe]&&[, 1, 0, 0, 2]
& & [C:\Program Files\Starsoftcomm\StarCenter\MFC42.DLL]&&[Microsoft Corporation, 6.00.9586.0]
[PID: 112 / Admin][C:\WINDOWS\THTFMo.exe]&&[N/A, ]
& & [C:\WINDOWS\HKNTDLL.dll]&&[N/A, ]
& & [C:\KAV2007\KASocket.dll]&&[Kingsoft Corporation, , 241]
& & [D:\QQ2007\DShared.dll]&&[Tencent, 1, 6, 0, 2]
[PID: 124 / Admin][C:\Program Files\THTF\THTF Keyboard Driver\Eudemon.exe]&&[, 1, 0, 0, 1]
& & [C:\Program Files\THTF\THTF Keyboard Driver\Ctrdev.dll]&&[Silitek, 1, 0, 0, 0]
& & [C:\Program Files\THTF\THTF Keyboard Driver\SKUtil.dll]&&[Silitek Corp., 1, 0, 0, 0]
& & [C:\WINDOWS\system32\msacm32.drv]&&[Microsoft Corporation, 5.1.2600.0 (xpclient.8)]
& & [C:\KAV2007\KASocket.dll]&&[Kingsoft Corporation, , 241]
& & [D:\QQ2007\DShared.dll]&&[Tencent, 1, 6, 0, 2]
[PID: 168 / Admin][C:\KAV2007\KAVStart.exe]&&[Kingsoft Corporation, , 289]
& & [C:\WINDOWS\system32\MFC71.DLL]&&[Microsoft Corporation, 7.10.3077.0]
& & [C:\WINDOWS\system32\MSVCR71.dll]&&[Microsoft Corporation, 7.10.3052.4]
& & [C:\WINDOWS\system32\MSVCP71.dll]&&[Microsoft Corporation, 7.10.3077.0]
& & [C:\WINDOWS\system32\MFC71CHS.DLL]&&[Microsoft Corporation, 7.10.3077.0]
& & [C:\KAV2007\KAVIPC2.DLL]&&[Kingsoft Corporation, , 30]
& & [C:\KAV2007\SvcTimer.DLL]&&[Kingsoft Corporation, .84]
& & [C:\KAV2007\PopSprt3.dll]&&[Kingsoft Corporation, , 48]
& & [C:\KAV2007\KAVPassp.dll]&&[Kingsoft Corporation, , 271]
& & [C:\KAV2007\KASocket.dll]&&[Kingsoft Corporation, , 241]
& & [C:\KAV2007\KMailOEBand.dll]&&[Kingsoft Corporation, , 139]
& & [C:\WINDOWS\system32\rsztcpm.dll]&&[N/A, ]
& & [D:\QQ2007\DShared.dll]&&[Tencent, 1, 6, 0, 2]
& & [C:\WINDOWS\system32\kaqhfzy.dll]&&[N/A, ]
& & [C:\WINDOWS\system32\kvdxsbma.dll]&&[N/A, ]
[PID: 224 / Admin][C:\WINDOWS\system32\SafeSignCertReg.exe]&&[A.E.T. Europe B.V., 2.0.0.2]
[PID: 228 / Admin][C:\WINDOWS\IGW.exe]&&[N/A, ]
[PID: 236 / Admin][C:\WINDOWS\IGM.exe]&&[N/A, ]
[PID: 320 / Admin][C:\WINDOWS\system32\ctfmon.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
& & [C:\KAV2007\KASocket.dll]&&[Kingsoft Corporation, , 241]
& & [D:\QQ2007\DShared.dll]&&[Tencent, 1, 6, 0, 2]
[PID: 332 / Admin][C:\KAV2007\KPFW32.EXE]&&[Kingsoft Corporation, , 726]
& & [C:\WINDOWS\system32\MFC71.DLL]&&[Microsoft Corporation, 7.10.3077.0]
& & [C:\WINDOWS\system32\MSVCR71.dll]&&[Microsoft Corporation, 7.10.3052.4]
& & [C:\WINDOWS\system32\MSVCP71.dll]&&[Microsoft Corporation, 7.10.3077.0]
& & [C:\WINDOWS\system32\MFC71CHS.DLL]&&[Microsoft Corporation, 7.10.3077.0]
& & [C:\KAV2007\KAVIPC2.DLL]&&[Kingsoft Corporation, , 30]
& & [C:\KAV2007\KAConfig.DLL]&&[Kingsoft Corporation, , 41]
& & [C:\KAV2007\FiltList.dll]&&[N/A, ]
& & [C:\KAV2007\KAVPassp.DLL]&&[Kingsoft Corporation, , 271]
& & [C:\KAV2007\KMailOEBand.dll]&&[Kingsoft Corporation, , 139]
& & [C:\KAV2007\KASocket.dll]&&[Kingsoft Corporation, , 241]
& & [C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\PDM.DLL]&&[Microsoft Corporation, 7.00.9466]
& & [C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\2052\mdmui.dll]&&[Microsoft Corporation, 7.00.9466]
& & [C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MSDBG2.DLL]&&[Microsoft Corporation, 7.00.9466]
& & [C:\Program Files\Common Files\Microsoft Shared\INK\PENCHS.DLL]&&[Microsoft Corporation, 1.0.1038.0]
& & [C:\KAV2007\KAScript.DLL]&&[Kingsoft Corporation, , 75]
& & [D:\QQ2007\DShared.dll]&&[Tencent, 1, 6, 0, 2]
[PID: 464 / Admin][C:\KAV2007\KMailMon.EXE]&&[Kingsoft Corporation, , 967]
& & [C:\KAV2007\KAntiSpm.dll]&&[Kingsoft Corporation, , 129]
& & [C:\WINDOWS\system32\MSVCR71.dll]&&[Microsoft Corporation, 7.10.3052.4]
& & [C:\WINDOWS\system32\MSVCP71.dll]&&[Microsoft Corporation, 7.10.3077.0]
& & [C:\KAV2007\KAVIPC2.DLL]&&[Kingsoft Corporation, , 30]
& & [C:\KAV2007\KAECall2.DLL]&&[Kingsoft Corporation, , 7]
& & [C:\KAV2007\KAEPlat.DLL]&&[Kingsoft Corp., , 64]
& & [C:\KAV2007\KAEMem.DAT]&&[Kingsoft, , 16]
& & [C:\KAV2007\KAEUnpack.DAT]&&[Kingsoft Corp., , 134]
& & [C:\KAV2007\KAConfig.DLL]&&[Kingsoft Corporation, , 41]
& & [C:\KAV2007\KASocket.dll]&&[Kingsoft Corporation, , 241]
& & [C:\KAV2007\KMailOEBand.dll]&&[Kingsoft Corporation, , 139]
& & [D:\QQ2007\DShared.dll]&&[Tencent, 1, 6, 0, 2]
[PID: 2264 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
[PID: 208 / SYSTEM][C:\WINDOWS\IGW.exe]&&[N/A, ]
[PID: 1164 / SYSTEM][C:\WINDOWS\system32\kvdxcis.exe]&&[N/A, ]
& & [C:\WINDOWS\system32\rsztcpm.dll]&&[N/A, ]
[PID: 1900 / SYSTEM][C:\WINDOWS\system32\kvdxsbis.exe]&&[N/A, ]
& & [C:\WINDOWS\system32\rsztcpm.dll]&&[N/A, ]
& & [C:\WINDOWS\system32\kvdxsbma.dll]&&[N/A, ]
[PID: 3872 / Admin][D:\QQ2007\QQ.exe]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\QQBaseClassInDll.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\QQHelperDll.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\BasicCtrlDll.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\MFC42.DLL]&&[Microsoft Corporation, 6.00.8665.0]
& & [C:\WINDOWS\system32\rsztcpm.dll]&&[N/A, ]
& & [C:\KAV2007\KMailOEBand.dll]&&[Kingsoft Corporation, , 139]
& & [C:\WINDOWS\system32\MSVCR71.dll]&&[Microsoft Corporation, 7.10.3052.4]
& & [C:\WINDOWS\system32\MSVCP71.dll]&&[Microsoft Corporation, 7.10.3077.0]
& & [C:\KAV2007\KASocket.dll]&&[Kingsoft Corporation, , 241]
& & [D:\QQ2007\RICHED32.DLL]&&[Microsoft Corporation, 5.00.2134.1]
& & [D:\QQ2007\RICHED20.dll]&&[Microsoft Corporation, 5.31.23.1218]
& & [D:\QQ2007\QQAPI.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\TIMProxy.dll]&&[tencent, 0, 3, 2, 4]
& & [D:\QQ2007\LoginCtrl.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\LoginCtrlRes.dll]&&[TENCENT, 7,0,365,1701]
& & [C:\WINDOWS\system32\kvdxsbma.dll]&&[N/A, ]
& & [C:\WINDOWS\system32\kaqhfzy.dll]&&[N/A, ]
& & [C:\Program Files\Starsoftcomm\StarCenter\HookMgr.dll]&&[, 1, 0, 0, 109]
& & [C:\WINDOWS\HKNTDLL.dll]&&[N/A, ]
& & [D:\QQ2007\QQRes.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\QQMainFrame.dll]&&[N/A, ]
& & [D:\QQ2007\gdiplus.dll]&&[Microsoft Corporation, 5.1. (xpsp_sp2_rtm.8)]
& & [D:\QQ2007\CQQApplication.dll]&&[N/A, ]
& & [D:\QQ2007\FlashAvatarDll.dll]&&[, 1, 4, 0, 1]
& & [D:\QQ2007\NewSkin.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\HostingMgr.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\CameraDll.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\MailSummary.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\QQKnowledgeSearch.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\QQAllInOne.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\SCCore.dll]&&[TENCENT, 1, 6, 0, 2]
& & [D:\QQ2007\QQSpace.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\vbscript.dll]&&[Microsoft Corporation, 5.6.0.7426]
& & [C:\WINDOWS\system32\msdmo.dll]&&[, ]
& & [D:\QQ2007\QQGroupMng.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\QQSysMsgMng.dll]&&[N/A, ]
& & [D:\QQ2007\UserDefinedHead.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\QQPlugin.dll]&&[N/A, ]
& & [D:\QQ2007\QQConfigPlugin.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\QQAvatar.dll]&&[N/A, ]
& & [D:\QQ2007\QQCustomFace.dll]&&[N/A, ]
& & [D:\QQ2007\QRingMng.dll]&&[N/A, ]
& & [D:\QQ2007\LongConnection.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\PhoneAPI.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\DialerAllinOne.dll]&&[tencent, 1, 4, 0, 0]
& & [C:\WINDOWS\system32\msacm32.drv]&&[Microsoft Corporation, 5.1.2600.0 (xpclient.8)]
& & [D:\QQ2007\QQPet.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\ImageOle.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\QQLiveQMng.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\QQSceneMng.dll]&&[N/A, ]
& & [C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx]&&[Adobe Systems, Inc., 9,0,47,0]
& & [C:\WINDOWS\system32\WINWB.IME]&&[Microsoft, 4.00.950]
& & [D:\QQ2007\BQQApplication.dll]&&[N/A, ]
& & [D:\QQ2007\CommercesMng.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\PersonalDesktop.dll]&&[深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
& & [D:\QQ2007\QQAddr.dll]&&[深圳市腾讯计算机系统有限公司, 5, 0, 101, 320]
& & [D:\QQ2007\QQMagicFace.dll]&&[TENCENT, 7,0,365,1701]
& & [D:\QQ2007\VqqAllInOne.dll]&&[Tencent, 1, 6, 0, 2]
& & [D:\QQ2007\InPlus.dll]&&[Tencent, 1, 6, 0, 2]
& & [D:\QQ2007\tencent-proto1.dll]&&[tencent, 1, 6, 0, 2]
& & [D:\QQ2007\tencent-comlib.dll]&&[tencent, 1, 6, 0, 2]
& & [D:\QQ2007\tencent-proto2.dll]&&[tencent, 1, 6, 0, 2]
& & [D:\QQ2007\DShared.dll]&&[Tencent, 1, 6, 0, 2]
& & [D:\QQ2007\AddrSearch.dll]&&[腾讯科技(深圳)有限公司, 2, 1, 9, 95]
& & [D:\QQ2007\QQFileTransfer.dll]&&[TENCENT, 7,0,365,1701]
[PID: 4020 / Admin][D:\QQ2007\TIMPlatform.exe]&&[TENCENT, 7,0,365,1701]
& & [C:\KAV2007\KMailOEBand.dll]&&[Kingsoft Corporation, , 139]
& & [C:\WINDOWS\system32\MSVCR71.dll]&&[Microsoft Corporation, 7.10.3052.4]
& & [C:\WINDOWS\system32\MSVCP71.dll]&&[Microsoft Corporation, 7.10.3077.0]
& & [C:\KAV2007\KASocket.dll]&&[Kingsoft Corporation, , 241]
& & [D:\QQ2007\TIMProxy.dll]&&[tencent, 0, 3, 2, 4]
& & [D:\QQ2007\DShared.dll]&&[Tencent, 1, 6, 0, 2]
[PID: 3744 / Admin][D:\新建文件夹 (3)\新建文件夹\SREngPS.EXE]&&[Smallfrogs Studio, 2.5.16.900]
& & [C:\WINDOWS\system32\rsztcpm.dll]&&[N/A, ]
& & [C:\KAV2007\KMailOEBand.dll]&&[Kingsoft Corporation, , 139]
& & [C:\WINDOWS\system32\MSVCR71.dll]&&[Microsoft Corporation, 7.10.3052.4]
& & [C:\WINDOWS\system32\MSVCP71.dll]&&[Microsoft Corporation, 7.10.3077.0]
& & [D:\QQ2007\DShared.dll]&&[Tencent, 1, 6, 0, 2]
& & [C:\KAV2007\KASocket.dll]&&[Kingsoft Corporation, , 241]
& & [C:\WINDOWS\system32\kaqhfzy.dll]&&[N/A, ]
& & [C:\WINDOWS\system32\kvdxsbma.dll]&&[N/A, ]
& & [D:\新建文件夹 (3)\新建文件夹\Upload\3rdUpd.DLL]&&[Smallfrogs Studio, 2, 1, 0, 15]
& & [C:\PROGRA~1\MICROS~2\OFFICE11\MCPS.DLL]&&[Microsoft Corporation, 11.0.6551]
==================================
文件关联
.TXT&&OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE&&OK. [&%1& %*]
.COM&&OK. [&%1& %*]
.PIF&&OK. [&%1& %*]
.REG&&OK. [regedit.exe &%1&]
.BAT&&OK. [&%1& %*]
.SCR&&OK. [&%1& /S]
.CHM&&Error. [&hh.exe& %1]
.HLP&&Error. [winhlp32.exe %1]
.INI&&OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF&&OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS&&OK. [%SystemRoot%\System32\WScript.exe &%1& %*]
.JS& &OK. [%SystemRoot%\System32\WScript.exe &%1& %*]
.LNK&&OK. [{0-}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
127.0.0.1& && & localhost
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 1992, C:\PROGRAM FILES\STARSOFTCOMM\STARCENTER\ALERT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1992, C:\PROGRAM FILES\STARSOFTCOMM\STARCENTER\ALERT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2016, C:\PROGRAM FILES\STARSOFTCOMM\STARCENTER\STARCENTER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2032, C:\PROGRAM FILES\STARSOFTCOMM\STARCENTER\UPDTRAY.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 112, C:\WINDOWS\THTFMO.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 124, C:\PROGRAM FILES\THTF\THTF KEYBOARD DRIVER\EUDEMON.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 168, C:\KAV2007\KAVSTART.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 168, C:\KAV2007\KAVSTART.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 224, C:\WINDOWS\SYSTEM32\SAFESIGNCERTREG.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 228, C:\WINDOWS\IGW.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 236, C:\WINDOWS\IGM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 332, C:\KAV2007\KPFW32.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 464, C:\KAV2007\KMAILMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 464, C:\KAV2007\KMAILMON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 208, C:\WINDOWS\IGW.EXE]
==================================
API HOOK
入口点错误:LoadLibraryExW (危险等级: 高,&&被下面模块所HOOK: C:\KAV2007\KASocket.dll)
==================================
隐藏进程
N/A
==================================
复制代码
(19.49 KB, 下载次数: 13)
21:13 上传
清理专家查出的
(17.25 KB, 下载次数: 9)
21:13 上传
清理专家查出的
(23.45 KB, 下载次数: 11)
21:13 上传
杀毒软件查出的
21:13 上传
点击文件名下载附件
33.48 KB, 下载次数: 27
用清理专家清理了以后的
21:13 上传
点击文件名下载附件
32.69 KB, 下载次数: 17
重起以后连网的
21:13 上传
点击文件名下载附件
29.07 KB, 下载次数: 16
重起以后没连网上了的
对了那个可疑RUN下的启动项有 个什么保护
有没有高手帮个忙啊 金山是杀不下去了& &电脑竟重起玩了
?????????怎么没人说句话啊
都下班了吗`
&&这是我提的 帮忙解决一下
[将方案保存文本放在桌面,没有操作完之前,不要打开任何网站、网页、QQ,不要进入任何分区。
预先下载好所有工具,看清楚步骤和要求。引自annygi ]
建议使用XDelBox删除以下文件:()
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。[选择备份,勾选“抑制文件再生”有提示不存在该文件就忽略,继续添加其它文件]C:\WINDOWS\system32\kafyezy.dll
C:\WINDOWS\system32\avwgcmn.dll
C:\WINDOWS\system32\kaqhezy.dll
C:\WINDOWS\system32\rsmydpm.dll
C:\WINDOWS\system32\rsztcpm.dll
C:\WINDOWS\system32\rsjzbpm.dll
C:\WINDOWS\system32\kawdbzy.dll
C:\WINDOWS\system32\rarjbpi.dll
C:\WINDOWS\system32\raqjbpi.dll
C:\WINDOWS\system32\ratbfpi.dll
C:\WINDOWS\system32\avwlbmn.dll
C:\WINDOWS\system32\sidjazy.dll
C:\WINDOWS\system32\kvdxcma.dll
C:\WINDOWS\system32\avzxdmn.dll
C:\WINDOWS\system32\kapjbzy.dll
C:\WINDOWS\system32\avwgdmn.dll
C:\WINDOWS\system32\kvdxsbma.dll
C:\WINDOWS\system32\kaqhfzy.dll复制代码 重要 你可以将xdelbox目录下的backup打包上传到可疑文件上传区。以供病毒工程师分析
重启以后删除注册表键值(打开 SREng ,依次点击“启动项目”-&“注册表”,列表中显示注册表中启动信息内容。点击选择需要删除的项目,然后点击“删除”按钮,弹出删除确认对话框,点击“是”删除,点击“否”取消。
)[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
& & &{5B681598-AD5F-BC8C-77DC-748FAC8D3FB5}&&&[]
& & &{3ADA-FF43-ABD3-345F323A48D3}&&&[N/A]
& & &{57D-}&&&[N/A]
& & &{4E32FA58-3453-FA2D-BC49-F340348ACCE4}&&&[N/A]
& & &{-DACF-3452-CB7D-3}&&&[]
& & &{22FAACDE-34DA-CCD4-AB4D-DA}&&&[N/A]
& & &{6-}&&&[]
& & &{2598FF45-DA60-F48A-BC43-10AC47853D52}&&&[]
& & &{F90-34A0-ACD05F42}&&&[N/A]
& & &{4-5FABCD1566}&&&[N/A]
& & &{8E-DE24-BD50-268F589A56A2}&&&[]
& & &{3-FADC-B443-4732ABCD3781}&&&[N/A]
& & &{3C87A354-ABC3-DEDE-FF33-C3}&&&[]
& & &{5D-BC13-AC4F-145D47DA34F4}&&&[]
& & &{2A7-D98A-C8D5-A2}&&&[N/A]
& & &{4ADA-FF43-ABD3-345F323A48D4}&&&[]
& & &{2DF3-A451-F908-A}&&&[]
& & &{67D-}&&&[]
&MSDCG32& & &&LYLeador.exe&&&[N/A]
&WinSys&&C:\WINDOWS\IGW.exe&&&[]
&WinSysM&&C:\WINDOWS\IGM.exe&&&[]复制代码使用sreng编辑 AppInit_DLLs的值为空&&
使用以下的软件清理工具清理下系统里面可能存在的病毒或者恶意软件残余
由于勾选了“抑制文件再生”被删除文件同一个地方会有相同的文件名字文件夹,(并且开机会自动打开这些文件夹,请忽略。)请一一进去将与原来病毒同名文件夹删除即可
最后请楼主修复下下列文件关联()
.CHM&&Error. [&hh.exe& %1]
.HLP&&Error. [winhlp32.exe %1]
由于水平所限可能存在漏判,,误判的情况欢迎楼主及时反馈问题的解决情况
[ 本帖最后由 李逍遥 于
23:02 编辑 ]
原帖由 malefactor 于
22:09 发表
都下班了吗`
没有上班和下班
请到我的网盘下载文件提取器()
将以下杀软无法删除的文件提取出来打包发至可疑文件上传区,请配合,谢谢
C:\WINDOWS\system32\sedrsvedt.exe
C:\WINDOWS\system32\kafyezy.dll
C:\WINDOWS\system32\avwgcmn.dll
C:\WINDOWS\system32\kaqhezy.dll
C:\WINDOWS\system32\rsmydpm.dll
C:\WINDOWS\system32\rsztcpm.dll
C:\WINDOWS\system32\rsjzbpm.dll
C:\WINDOWS\system32\kawdbzy.dll
C:\WINDOWS\system32\rarjbpi.dll
C:\WINDOWS\system32\raqjbpi.dll
C:\WINDOWS\system32\ratbfpi.dll
C:\WINDOWS\system32\avwlbmn.dll
C:\WINDOWS\system32\sidjazy.dll
C:\WINDOWS\system32\kvdxcma.dll
C:\WINDOWS\system32\avzxdmn.dll
C:\WINDOWS\system32\kapjbzy.dll
C:\WINDOWS\system32\avwgdmn.dll
C:\WINDOWS\system32\kvdxsbma.dll
C:\WINDOWS\system32\kaqhfzy.dll
C:\WINDOWS\IGW.exe
C:\WINDOWS\IGM.exe
C:\WINDOWS\system32\LYLeador.exe
用XDelBox删除以上文件( 下载):
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
打开SREng-&启动项目-&注册表-&删除以下启动项目
& & &{5B681598-AD5F-BC8C-77DC-748FAC8D3FB5}&&C:\WINDOWS\system32\kafyezy.dll&&&[]
& & &{3ADA-FF43-ABD3-345F323A48D3}&&C:\WINDOWS\system32\avwgcmn.dll&&&[N/A]
& & &{57D-}&&C:\WINDOWS\system32\kaqhezy.dll&&&[N/A]
& & &{4E32FA58-3453-FA2D-BC49-F340348ACCE4}&&C:\WINDOWS\system32\rsmydpm.dll&&&[N/A]
& & &{-DACF-3452-CB7D-3}&&C:\WINDOWS\system32\rsztcpm.dll&&&[]
& & &{22FAACDE-34DA-CCD4-AB4D-DA}&&C:\WINDOWS\system32\rsjzbpm.dll&&&[N/A]
& & &{6-}&&C:\WINDOWS\system32\kawdbzy.dll&&&[]
& & &{2598FF45-DA60-F48A-BC43-10AC47853D52}&&C:\WINDOWS\system32\rarjbpi.dll&&&[]
& & &{F90-34A0-ACD05F42}&&C:\WINDOWS\system32\raqjbpi.dll&&&[N/A]
& & &{4-5FABCD1566}&&C:\WINDOWS\system32\ratbfpi.dll&&&[N/A]
& & &{8E-DE24-BD50-268F589A56A2}&&C:\WINDOWS\system32\avwlbmn.dll&&&[]
& & &{3-FADC-B443-4732ABCD3781}&&C:\WINDOWS\system32\sidjazy.dll&&&[N/A]
& & &{3C87A354-ABC3-DEDE-FF33-C3}&&C:\WINDOWS\system32\kvdxcma.dll&&&[]
& & &{5D-BC13-AC4F-145D47DA34F4}&&C:\WINDOWS\system32\avzxdmn.dll&&&[]
& & &{2A7-D98A-C8D5-A2}&&C:\WINDOWS\system32\kapjbzy.dll&&&[N/A]
& & &{4ADA-FF43-ABD3-345F323A48D4}&&C:\WINDOWS\system32\avwgdmn.dll&&&[]
& & &{2DF3-A451-F908-A}&&C:\WINDOWS\system32\kvdxsbma.dll&&&[]
& & &{67D-}&&C:\WINDOWS\system32\kaqhfzy.dll&&&[]
& & &WinSys&&C:\WINDOWS\IGW.exe&&&[]
& & &WinSysM&&C:\WINDOWS\IGM.exe&&&[]
& & &MSDCG32& & &&LYLeador.exe&&&[N/A]
编辑& & &AppInit_DLLs&&rsztcpm.dll&
为& & &AppInit_DLLs&&&
打开SREng-&启动项目-&服务-&&Win32服务应用程序&选中&隐藏已认证的微软服务& 然后将下面名称的服务删除(选中有问题的服务后,点“删除服务”,点“设置”按钮即可。&&注意弹出的窗口中要点 “NO 否”才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置):
[Telephotsgoogle / Winownes][Stopped/Auto Start]
&&&C:\WINDOWS\system32\sedrsvedt.exe&&N/A&
新手&&能不能说的通俗点&&一步一步的& &你那样我看不懂&&你说的那些都在那找
说的够清楚了啊,一步步都说明白了。
更通俗的方法,是安装金山清理专家2.0和毒霸,下载AV终结者专杀工具,运行 专杀工具修复映像支持后,立即升级毒霸和清理专家,然后,重启系统到安全模式下杀毒。最后,用清理专家把病毒修改的注册表项修复。
相关工具,在AV终结者解决方案专贴和禽兽病毒专贴都可以下载
禽兽病毒解决方案
清理专家2的使用,参考签名中的《清理专家简易手册》
逛了这许久,何不进去瞧瞧?
关注我们:

我要回帖

更多关于 dfs.common.agent.exe 的文章

 

随机推荐