| 引用: |
【超级游戏迷的贴子】启动项目 注册表 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] <{B63BFF8C-2E25-4CCC-9A01-68807F567AA7}><C:\WINDOWS\system32\BandRes.dll> [N/A] ================================== 服务 [cpu app / cpuapp][Running/Auto Start] <C:\WINDOWS\system32\apcups.exe><N/A> [DCOM Client / DCOMClient][Stopped/Auto Start] <C:\WINDOWS\system32\DCOMSvr.EXE><N/A> [Windows Install Helper / lDOMANE][Stopped/Auto Start] <C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL,Export 1087><N/A> [Logical Disk Manager Administrator Service / Logical Disk Manager Administrator Service][Stopped/Auto Start] <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ntxml.dll><N/A> [ms win avp / MSWAVP][Stopped/Disabled] <C:\WINDOWS\system32\mswavp.exe><N/A> ================================== 驱动程序 [ADProt / ADProt][Stopped/Disabled] <\SystemRoot\system32\drivers\ADProt.sys><N/A> [ast / ast][Stopped/Disabled] <\??\C:\WINDOWS\system32\drivers\ast.sys><N/A> [CALLKEY_IO / CALLKEY_IO][Stopped/Disabled] <\??\C:\Program Files\OneKey\CALLKEY.sys><N/A> [Cdsys / Cdsys][Stopped/Disabled] <\??\C:\WINDOWS\system32\cdcd.sys><N/A> [CKG005 / CKG005][Stopped/Disabled] <\??\C:\WINDOWS\TEMP\fq2v.syshs1bfku.sys><N/A> [cugheb5 / cugheb55][Running/Boot Start] <\SystemRoot\System32\DRIVERS\cugheb55.sys><N/A> [dqmawh5 / dqmawh51][Running/Boot Start] <\SystemRoot\System32\DRIVERS\dqmawh51.sys><N/A> [eaecamm / eaecamm][Running/Boot Start] <\SystemRoot\system32\drivers\eaecamm.sys><N/A> [iyiona4 / iyiona41][Stopped/Disabled] <System32\DRIVERS\iyiona41.sys><N/A> [jvcapn9 / jvcapn96][Stopped/Disabled] <System32\DRIVERS\jvcapn96.sys><N/A> [karakhk / karakhk][Running/Boot Start] <\SystemRoot\\SystemRoot\System32\drivers\karakhk.sys><N/A> [lanfs / lanfs][Stopped/Disabled] <\??\C:\WINDOWS\system32\drivers\lanfs.sys><N/A> [lbadjj1 / lbadjj13][Stopped/Disabled] <System32\DRIVERS\lbadjj13.sys><N/A> [ljzttdll / ljzttdll][Stopped/Disabled] <System32\DRIVERS\ljzttdll.sys><Yahoo! China Corporation> [ltbomcu / ltbomcu][Running/Boot Start] <\SystemRoot\system32\drivers\ltbomcu.sys><N/A> [mdxgthkn / mdxgthkn][Stopped/Disabled] <\??\C:\DOCUME~1\王紫\LOCALS~1\Temp\mdxgthkn.sys><N/A> [ntkzrcn / ntkzrcn][Running/Boot Start] <\SystemRoot\system32\drivers\ntkzrcn.sys><N/A> [qoapvjk / qoapvjk][Running/Boot Start] <\SystemRoot\system32\drivers\qoapvjk.sys><N/A> [qzibgts / qzibgts][Running/Boot Start] <\SystemRoot\system32\drivers\qzibgts.sys><N/A> [rsefges / rsefges][Running/Boot Start] <\SystemRoot\system32\drivers\rsefges.sys><N/A> [TUR557 / TUR557][Stopped/Disabled] <\??\C:\WINDOWS\TEMP\20s1.sys><N/A> ================================== 正在运行的进程 [C:\WINDOWS\system32\xtniutk.dll] [N/A, ] [C:\WINDOWS\system32\qoapvjk.dll] [N/A, ]
以上是我认为应该怀疑的地方。其中红、兰色为病毒项;黑色为可疑项目(需要验证)!
……………… |
拿什么删??xtniutk等文件~这一类的拿冰刃一删就死机.......