瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 SVCHOST.EXE(请高手借给我5分钟~谢谢)

1234   3  /  4  页   跳转

SVCHOST.EXE(请高手借给我5分钟~谢谢)


[PID: 1220][C:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe]  <Microsoft Corporation><2000.080.0194.00>
[PID: 1524][C:\WINDOWS\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.5672>
[PID: 1604][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
[PID: 1776][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1340][C:\Program Files\Canon\CAL\CALMAIN.exe]  <Canon Inc.><8, 0, 0, 21>
[PID: 1156][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
    [C:\Program Files\KV2006\KVSock.dll]  <Jiangmin Co. Ltd.><9.2.5.720>
[PID: 2120][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 2268][C:\WINDOWS\SOUNDMAN.EXE]  <Realtek Semiconductor Corp.><5.1.0.27>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 2316][C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe]  <Sun Microsystems, Inc.><5.0.60.5>
[PID: 2352][C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe]  <Nokia Mobile Phones Ltd.><6, 60, 109, 3>
    [C:\Program Files\Common Files\PCSuite\DataLayer\Lang\DataLayer_chi-sc.nlr]  <Nokia><6, 60, 8, 0>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 2360][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3510>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
    [C:\Program Files\KV2006\KVMonXP.kxp]  <Jiangmin Co.Ltd><9, 0, 5, 1025>
    [C:\Program Files\KV2006\UpdateX.dll]  <JiangMin Co.Ltd.><9, 0, 5, 831>
    [C:\Program Files\KV2006\lang\Kvxp0804.lng]  <N/A><N/A>
    [C:\Program Files\KV2006\GUIExt.dll]  <Jiangmin Co.Ltd><9, 0, 5, 927>
    [C:\Program Files\KV2006\lang\GUIExt0804.lng]  <JiangMin Ltd.><7, 1, 0, 200>
    [C:\Program Files\KV2006\EngFace.dll]  <Jiangmin Co.Ltd><9.0.0.50809>
    [C:\Program Files\KV2006\EngPS.dll]  <Jiangmin Co.Ltd><9, 2, 0, 50817>
    [C:\Program Files\KV2006\KvOffice.dll]  <JiangMin New Tech.><9.0.0.1213>
    [C:\Program Files\KV2006\lang\KVOffice0804.lng]  <N/A><N/A>
    [C:\Program Files\KV2006\VirusUpload.dll]  <N/A><2, 0, 0, 0>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\Program Files\KV2006\PProtect.dll]  <Jiangmin Co. Ltd.><9.0.0.921>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 2404][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 2440][C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE]  <Nokia.><6, 60, 36, 1>
    [C:\WINDOWS\system32\NclTools.dll]  <Nokia.><6, 60, 12, 0>
    [C:\Program Files\Common Files\PCSuite\Transports\NCLIrDAMM.dll]  <Nokia Corp.><6, 60, 19, 0>
    [C:\Program Files\Common Files\PCSuite\Transports\NclMSBTMM.dll]  <Nokia.><6, 60, 29, 0>
    [C:\Program Files\Common Files\PCSuite\Transports\NCLRSMM.dll]  <Nokia><6,60, 28, 0>
    [C:\Program Files\Common Files\PCSuite\Transports\NCLUSBMM.dll]  <Nokia><6, 60, 28, 0>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
    [C:\Program Files\KV2006\TrojDie.kxp]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\Program Files\KV2006\UpdateX.dll]  <JiangMin Co.Ltd.><9, 0, 5, 831>
    [C:\Program Files\KV2006\lang\TrojDie0804.lng]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\Program Files\KV2006\GUIExt.dll]  <Jiangmin Co.Ltd><9, 0, 5, 927>
    [C:\Program Files\KV2006\lang\GUIExt0804.lng]  <JiangMin Ltd.><7, 1, 0, 200>
    [C:\Program Files\KV2006\PProtect.dll]  <Jiangmin Co. Ltd.><9.0.0.921>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\Program Files\KV2006\ComUIPS.dll]  <N/A><9. 5. 5. 20>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 2784][C:\Program Files\KV2006\KRegEx.exe]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\Program Files\KV2006\KRegEx.dll]  <Jiangmin Co. Ltd.><9.0.0.825>
    [C:\Program Files\KV2006\KRegTrust.dll]  <Jiangmin Co. Ltd.><9.0.0.825>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 2832][C:\Program Files\KV2006\UIHost.exe]  <Jiangmin Co. Ltd><9.2.0.50822>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\Program Files\KV2006\UpdateX.dll]  <JiangMin Co.Ltd.><9, 0, 5, 831>
    [C:\Program Files\KV2006\ComUI.dll]  <Jiangmin Ltd.><9. 0. 0.509>
    [C:\Program Files\KV2006\ComUIPS.dll]  <N/A><9. 5. 5. 20>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
    [C:\Program Files\KV2006\GUIExt.dll]  <Jiangmin Co.Ltd><9, 0, 5, 927>
    [C:\Program Files\KV2006\lang\GUIExt0804.lng]  <JiangMin Ltd.><7, 1, 0, 200>
[PID: 3016][C:\WINDOWS\system32\wuauclt.exe]  <Microsoft Corporation><5.8.0.2469 built by: lab01_n(wmbla)>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
[PID: 1632][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2149 (xpsp_sp2_rc2.040610-1520)>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\Program Files\KV2006\KvShell.dll]  <Jiangmin Co.Ltd><9, 0, 5, 830>
    [C:\Program Files\KV2006\UpdateX.dll]  <JiangMin Co.Ltd.><9, 0, 5, 831>
    [C:\Program Files\KV2006\lang\Kvxp0804.lng]  <N/A><N/A>
    [C:\Program Files\KV2006\APIImpl.dll]  <JiangMin Ltd.><9.0.0.500>
    [C:\Program Files\KV2006\GUIExt.dll]  <Jiangmin Co.Ltd><9, 0, 5, 927>
    [C:\Program Files\KV2006\lang\GUIExt0804.lng]  <JiangMin Ltd.><7, 1, 0, 200>
    [C:\Program Files\KOS\KOSIEBar.dll]  <金山软件股份有限公司><2006, 2, 16, 1>
    [C:\Program Files\KV2006\KVBHO.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\Program Files\KV2006\KVAddrDb.dll]  <Jiangmin Co.Ltd><9, 0, 0, 1018>
    [C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll]  <Sun Microsystems, Inc.><5.0.60.5>
    [E:\KuGoo3\KuGoo3DownXControl.ocx]  <N/A><N/A>
    [C:\WINDOWS\downlo~1\CnsHook.dll]  <北京三七二一科技有限公司><1, 0, 2, 7>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
    [C:\WINDOWS\downlo~1\CnsHint.dll]  <3721><1, 0, 0, 8>
    [C:\Program Files\KV2006\KVSock.dll]  <Jiangmin Co. Ltd.><9.2.5.720>
    [C:\WINDOWS\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\WINDOWS\downlo~1\cnsplus.dll]  <3721><1, 0, 0, 2>
    [C:\WINDOWS\system32\xunleibho_v14.dll]  <Thunder Networking Technologies,LTD><4, 6, 0, 62>
[PID: 2280][C:\WINDOWS\system32\Rundll32.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\WINDOWS\downlo~1\CnsMinIO.dll]  <北京三七二一科技有限公司><1, 0, 3, 6>
    [C:\WINDOWS\downlo~1\cnsio.dll]  <北京三七二一科技有限公司><1, 0, 2, 7>
[PID: 3416][C:\WINDOWS\system32\HPZipm12.exe]  <HP><8, 0, 0, 0>
[PID: 184][C:\WINDOWS\system32\taskmgr.exe]  <Microsoft Corporation><5.1.2600.2149 (xpsp_sp2_rc2.040610-1520)>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
[PID: 3548][D:\qq\QQ.exe]  <TENCENT><0, 0, 0, 0>
gototop
 


    [D:\qq\CoralAssist.DLL]  <Coral Team><4.5.0 build 20060515>
    [D:\qq\CoralQQ.DLL]  <Coral Team><4.5.1 Build 20060620>
    [D:\qq\ipsearcher.dll]  <N/A><1.0.0.4>
    [D:\qq\QQBaseClassInDll.dll]  <><1, 0, 0, 1>
    [D:\qq\QQHelperDll.dll]  <><1, 0, 0, 1>
    [D:\qq\BasicCtrlDll.dll]  <Tencent><5, 0, 200, 160>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [D:\qq\RICHED20.dll]  <N/A><9, 0, 0, 1>
    [D:\qq\QQAPI.dll]  <><1, 0, 0, 1>
    [D:\qq\TIMProxy.dll]  <tencent><0, 3, 2, 4>
    [D:\qq\LoginCtrl.dll]  <><1, 0, 0, 1>
    [D:\qq\npkcntc.dll]  <INCA Internet Co., Ltd.><2006, 3, 2, 1>
    [D:\qq\npkpdb.dll]  <INCA Internet Co., Ltd.><2003, 10, 1, 1>
    [D:\qq\QQRes.dll]  <tencent><1, 0, 0, 1>
    [D:\qq\QQMainFrame.dll]  <N/A><N/A>
    [D:\qq\CQQApplication.dll]  <N/A><N/A>
    [C:\Program Files\KV2006\KVSock.dll]  <Jiangmin Co. Ltd.><9.2.5.720>
    [D:\qq\NewSkin.dll]  <><1, 0, 0, 1>
    [D:\qq\HostingMgr.dll]  <><1, 0, 0, 1>
    [D:\qq\CameraDll.dll]  <><1, 0, 0, 1>
    [D:\qq\MailSummary.dll]  <><1, 0, 0, 1>
    [D:\qq\QQSpace.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [D:\qq\QQGroupMng.dll]  <><1, 0, 0, 1>
    [D:\qq\GroupLive.dll]  <N/A><N/A>
    [D:\qq\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [D:\qq\QQPlugin.dll]  <N/A><N/A>
    [D:\qq\QQConfigPlugin.dll]  <><1, 0, 0, 1>
    [D:\qq\LongConnection.dll]  <tencent><5, 0, 200, 160>
    [D:\qq\ShareFiles.dll]  <N/A><N/A>
    [D:\qq\QQZip.dll]  <tencent><0, 3, 2, 4>
    [D:\qq\QRingMng.dll]  <N/A><N/A>
    [D:\qq\PhoneAPI.dll]  <><1, 0, 0, 1>
    [D:\qq\DialerAllinOne.dll]  <tencent><1, 4, 0, 0>
    [D:\qq\QQAvatar.dll]  <N/A><N/A>
    [D:\qq\FlashAvatarDll.dll]  <><1, 4, 0, 1>
    [D:\qq\QQAllInOne.dll]  <N/A><N/A>
    [D:\qq\SCCore.dll]  <N/A><N/A>
    [D:\qq\QQPet.dll]  <><1, 0, 0, 1>
    [D:\qq\QQCustomFace.dll]  <N/A><N/A>
    [C:\Program Files\KV2006\KVGuard.dll]  <Jiangmin Co Ltd><9.0.0.813>
    [C:\Program Files\KV2006\UpdateX.dll]  <JiangMin Co.Ltd.><9, 0, 5, 831>
    [C:\Program Files\KV2006\lang\KVGuard0804.lng]  <JiangMin Ltd.><7, 1, 0, 200>
    [C:\Program Files\KV2006\KVAddrDb.dll]  <Jiangmin Co.Ltd><9, 0, 0, 1018>
    [C:\WINDOWS\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [D:\qq\QQSceneMng.dll]  <N/A><N/A>
    [D:\qq\QQSysMsgMng.dll]  <N/A><N/A>
    [D:\qq\BQQApplication.dll]  <N/A><N/A>
    [D:\qq\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [D:\qq\ImageOle.dll]  <TODO: <Company name>><1.0.0.1>
    [F:\WOOOL1\Nokia PC Suite 6\PhoneBrowser.dll]  <Nokia><6, 60, 15, 3>
    [C:\WINDOWS\system32\ConnAPI.DLL]  <Nokia.><6, 60, 27, 2>
    [F:\WOOOL1\Nokia PC Suite 6\PCSCM.dll]  <Nokia><6, 60, 45, 4>
    [F:\WOOOL1\Nokia PC Suite 6\Lang\PhoneBrowser_chi-sc.nlr]  <Nokia><6, 60, 5, 1>
    [F:\WOOOL1\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr]  <Nokia><6, 60, 1, 1>
    [D:\qq\QQMagicFace.dll]  <><1, 0, 0, 1>
    [D:\qq\QQFileTransfer.dll]  <Tencent><5, 0, 202, 180>
    [D:\qq\CommercesMng.dll]  <><1, 0, 0, 1>
    [D:\qq\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
    [D:\qq\GroupConnection.dll]  <Tencent><5, 0, 202, 170>
    [D:\qq\QQPhoneHelper.dll]  <腾讯科技(深圳)有限公司><2, 0, 4, 40>
[PID: 3836][D:\qq\TIMPlatform.exe]  <tencent><0, 3, 1, 8>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [D:\qq\TIMProxy.dll]  <tencent><0, 3, 2, 4>
[PID: 3864][D:\DownLoads\Thunder.exe]  <Thunder Networking Technologies,LTD><5.1.4.174>
    [D:\DownLoads\UpdateDownload.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 2>
    [D:\DownLoads\download_interface.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 66>
    [D:\DownLoads\log4cplus.dll]  <><1, 0, 2, 1>
    [D:\DownLoads\stlport_vc646.dll]  <STLport Consulting, Inc.><4.6.2003.1031>
    [D:\DownLoads\msgmanage.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 15>
    [D:\DownLoads\historyinfo_manage.dll]  <Thunder Networking Technologies,LTD><5, 2, 0, 148>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [D:\DownLoads\iEmbed.dll]  <Thunder Networking Technologies,LTD><1, 1, 0, 22>
    [D:\DownLoads\RegisterDll.dll]  <Thunder Networking Technologies,LTD><1, 2, 0, 7>
    [D:\DownLoads\FloatBar.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 2>
    [C:\Program Files\KV2006\KVSock.dll]  <Jiangmin Co. Ltd.><9.2.5.720>
    [D:\DownLoads\iTargetAd.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 59>
    [C:\WINDOWS\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 2932][C:\DOCUME~1\wang\LOCALS~1\Temp\sreng2.zip 的临时目录 1\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\Program Files\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.0813>
    [C:\WINDOWS\downlo~1\CnsMin.dll]  <北京三七二一科技有限公司><1, 5, 3, 3>
    [C:\Program Files\KV2006\KVSock.dll]  <Jiangmin Co. Ltd.><9.2.5.720>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

晕~这么多啊~~~~连我自己也吓一跳~~~~~~麻烦你啦~
gototop
 

晕!第一次见有这么多的!楼主害人!

今天中午给你答案!
gototop
 

真的太谢谢啦!!!!!!!!同时也代表这个电脑的主人谢你了哈~
恩~我中午来看
gototop
 

人呢人呢?帮染帮到底嘛~~~~~~~~~正好就当复习以前学的功课啦
嘻嘻~~``
gototop
 

引用:
【阿龙979的贴子】人呢人呢?帮染帮到底嘛~~~~~~~~~正好就当复习以前学的功课啦
嘻嘻~~``
...........................


啥?偶刚来~

偶只给你分析两楼剩余的你自己分析!偶眼睛受不了这中折磨!
gototop
 

17楼,依次  启动项目    注册表项目  看到下面的删除:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceDelayLoad]
    <SysTime><C:\PROGRA~1\WinKld\WinKld.dll>  []

[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\PLANET~1.SCR>  []
gototop
 

虽然不太懂,但我试一下......谢谢咯~
gototop
 

用IceSword1.18删可以吧?
gototop
 
1234   3  /  4  页   跳转
页面顶部
Powered by Discuz!NT