瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 < 以解决>drw.kills, 不停弹出系统错误,系统崩溃

123456   2  /  6  页   跳转

[求助] < 以解决>drw.kills, 不停弹出系统错误,系统崩溃

回复 3F coricks 的帖子

重装无效感染型病毒

ftp://ftp.drweb.com/pub/drweb/cureit/launch.exe
放入WINDOWS文件夹
全盘杀毒
修复被感染文件(注意识别杀毒结果)
gototop
 

回复 10F 天月来了 的帖子

可以运行  需要升级不  显示说3000多天没升级
gototop
 

回复 12F coricks 的帖子

不是吧
看看 你系统时间
怕是系统时间被改

报下大蜘蛛版本号

注意识别杀毒结果
gototop
 

drw.kills, 不停弹出系统错误,系统崩溃

我扫描了一次 保存的报告

附件附件:

文件名:SYSLOG.TXT
下载次数:201
文件类型:text/plain
文件大小:
上传时间:2008-8-21 11:38:35
描述:txt

gototop
 

回复 13F aaccbbdd 的帖子

大蜘蛛下的比较慢  现在正在扫
gototop
 

drw.kills, 不停弹出系统错误,系统崩溃

打蜘蛛扫描的结果  上传不了
gototop
 

回复: drw.kills, 不停弹出系统错误,系统崩溃

下载附件清理吧

不升级清理

清理完以后立即进安全模式下继续清理

清理完

进系统里,去操作:

————————————————————————————————————
在扫日志的SRENG工具》启动项目》注册表》里面找下面项目删除:
启动项目
注册表
    <{E0F3526A-4165-4589-80CD-50B6FBAC3BDA}><C:\WINDOWS\system32\adsntzt.dll>  []
    <{6B9FEAD7-4319-4312-AB05-D8C9CD255BFE}><C:\WINDOWS\system32\avicapwm.dll>  []
    <{71A78CD4-E470-4a18-8457-E0E0283DD507}><C:\WINDOWS\system32\lweurqhx.dll>  []
    <{9E8287B0-0F3A-48ae-99C5-A6E0AAC36BC5}><C:\WINDOWS\system32\certmgrkd.dll>  []
    <{21BE5FDF-D4CB-4850-AD99-21E68B50BF3F}><C:\WINDOWS\system32\tuxumyls.dll>  []
    <{00300030-0030-0030-0030-00300030BB15}><C:\WINDOWS\system32\imgutilhx2.dll>  []
    <{D3112B69-A745-4805-874E-ABD480EA1299}><C:\WINDOWS\system32\bootvidgj.dll>  []
    <{00050005-0005-0005-0005-00050005BB15}><C:\WINDOWS\system32\cliconfgzx.dll>  []
    <bootvidgj.dll><C:\WINDOWS\system32\bootvidgj.dll>  []
    <kbdswjr.dll><C:\WINDOWS\system32\kbdswjr.dll>  [File is missing]
    <lweurqhx.dll><C:\WINDOWS\system32\lweurqhx.dll>  []
    <tuxumyls.dll><C:\WINDOWS\system32\tuxumyls.dll>  []
    <cliconfgzx.dll><C:\WINDOWS\system32\cliconfgzx.dll>  []
    <adsntzt.dll><C:\WINDOWS\system32\adsntzt.dll>  []
    <certmgrkd.dll><C:\WINDOWS\system32\certmgrkd.dll>  []
    <avicapwm.dll><C:\WINDOWS\system32\avicapwm.dll>  []
    <imgutilhx2.dll><C:\WINDOWS\system32\imgutilhx2.dll>  []
————————————————————————————————————————————————
去开始菜单里找启动文件夹,删除下面的:
==================================
启动文件夹
[S89NSNPX]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\S89NSNPX.lnk --> C:\WINDOWS\Q0JMJR~1.EXE [drw.kills]><H>
[SD1D5P]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\SD1D5P.lnk --> C:\WINDOWS\MGKUAV~1.EXE [drw.kills]><H>
[Z3QBV5RRWOP0]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Z3QBV5RRWOP0.lnk --> C:\WINDOWS\JTSMZ2~1.EXE [drw.kills]><H>
[JWPHP400HP]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\JWPHP400HP.lnk --> C:\WINDOWS\IMWNH9L.exe [drw.kills]><H>
[NE4RQ4KLMXJU]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\NE4RQ4KLMXJU.lnk --> C:\WINDOWS\MSPJU.exe [drw.kills]><H>
[JKV63AISI]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\JKV63AISI.lnk --> C:\WINDOWS\TVEOQK~1.EXE [drw.kills]><H>
[12VEUIODKS]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\12VEUIODKS.lnk --> C:\WINDOWS\UTC8T.exe [drw.kills]><H>
[7T0KOWKL]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\7T0KOWKL.lnk --> C:\WINDOWS\IX9OOD.exe [drw.kills]><H>
[O4QGYKODVX]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\O4QGYKODVX.lnk --> C:\WINDOWS\PMD7S5~1.EXE [drw.kills]><H>
[5GHH1]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\5GHH1.lnk --> C:\WINDOWS\051FS.exe [drw.kills]><H>
[PYTYCWD8]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\PYTYCWD8.lnk --> C:\WINDOWS\IQ00M.exe [drw.kills]><H>
[Q7B7X]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Q7B7X.lnk -->  [File is missing]><N>
[PTNCQ6CSNI]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\PTNCQ6CSNI.lnk -->  [File is missing]><N>
—————————————————————————————————————
在扫日志的SRENG工具》启动项目》服务》Win32服务应用程序》里面找下面项删除
==================================
服务
[HZ9L5DE / 051FS][Stopped/Disabled]
  <C:\WINDOWS\051FS.exe -2V0EEJZKP><drw.kills>
[2B38FCXKUR / 078DR3][Stopped/Disabled]
  <C:\WINDOWS\078DR3.exe -ZXA59P><drw.kills>
[HWRQW / 07GIB174E][Stopped/Disabled]
  <C:\WINDOWS\07GIB174E.exe -3W2ZBDE9><drw.kills>
[F5KC7E4N9P / 0F1EJC3SMLV][Stopped/Disabled]
  <C:\WINDOWS\0F1EJC3SMLV.exe -OH8CJ2ROI><drw.kills>
[EW9HDQZQUUCE / 0JTGCPMS2][Stopped/Disabled]
  <C:\WINDOWS\system32\0JTGCPMS2.exe -3R49S><drw.kills>
[75Q9ZM / 0Q138JSDW][Stopped/Disabled]
  <C:\WINDOWS\0Q138JSDW.exe -WZ9GLVUG2CQA><drw.kills>
[WBMKTHT / 0Q54WZPOXGL][Stopped/Disabled]
  <C:\WINDOWS\system32\0Q54WZPOXGL.exe -6H3SL8O6LNE><drw.kills>
[4KURURX3I3 / 16G29QPCTMM][Stopped/Disabled]
  <C:\WINDOWS\16G29QPCTMM.exe -CGQKSDYK><drw.kills>
[BM5D3P9OKSX / 1AHHRPWU7S][Stopped/Disabled]
  <C:\WINDOWS\system32\1AHHRPWU7S.exe -Y971TT><drw.kills>
[5MUCUBY / 1AHSN5NOVZ][Stopped/Disabled]
  <C:\WINDOWS\1AHSN5NOVZ.exe -5FGNKBLNZCA><drw.kills>
[PM5XOSARQ6I / 1DC38][Stopped/Disabled]
  <C:\WINDOWS\system32\1DC38.exe -E0PDPPRWVXZ><drw.kills>
[SD7F8AN3CXF / 1GQ59][Stopped/Disabled]
  <C:\WINDOWS\system32\1GQ59.exe -6B8QSY><drw.kills>
[DWAXI / 1SC25V6LCGBW][Stopped/Disabled]
  <C:\WINDOWS\1SC25V6LCGBW.exe -XQFNO5O5C5RO><drw.kills>
[A8RO7L1 / 1YLN1R][Stopped/Disabled]
  <C:\WINDOWS\system32\1YLN1R.exe -3ZKUYVI><drw.kills>
[YGWMOSW / 203QUTANIO7][Stopped/Disabled]
  <C:\WINDOWS\system32\203QUTANIO7.exe -5HE3Y75TP><drw.kills>
[ND4PSDC / 20TXK][Stopped/Disabled]
  <C:\WINDOWS\system32\20TXK.exe -QW4AS><drw.kills>
[REQDT58T / 235XJGAR8Z][Stopped/Disabled]
  <C:\WINDOWS\235XJGAR8Z.exe -573J3PIN5A9><drw.kills>
[Z0OMEDG82 / 23UW2ARP][Stopped/Disabled]
  <C:\WINDOWS\system32\23UW2ARP.exe -YMHHUH><drw.kills>
[Z3D0RM / 25CK34R5][Stopped/Disabled]
  <C:\WINDOWS\25CK34R5.exe -QOR5E6><drw.kills>
[MAHA1LYM / 2BBQIOYO2CN3][Stopped/Disabled]
  <C:\WINDOWS\system32\2BBQIOYO2CN3.exe -Y1C6JE><drw.kills>
[007ZHMOHNRAF / 2I25D][Stopped/Disabled]
  <C:\WINDOWS\2I25D.exe -OIS5T><drw.kills>
[CK6P1REQP / 2OZN6Y][Stopped/Disabled]
  <C:\WINDOWS\2OZN6Y.exe -YI1CY5Q4IK><drw.kills>
[JZ0R6O8OB / 2PDW01LA][Stopped/Disabled]
  <C:\WINDOWS\2PDW01LA.exe -NFOP6VAKM><drw.kills>
[J3BZS3 / 2SSVI][Stopped/Disabled]
  <C:\WINDOWS\system32\2SSVI.exe -TP97C9><drw.kills>
[KMC7Z / 2TPP31BMB][Stopped/Disabled]
  <C:\WINDOWS\system32\2TPP31BMB.exe -IBN2K1WENQHW><drw.kills>
[BTZMFH0A9 / 2UFYNOZ0GDGG][Stopped/Disabled]
  <C:\WINDOWS\system32\2UFYNOZ0GDGG.exe -U4JTI><drw.kills>
[3R6GR3S4KAD1 / 2VBIVLN2334Q][Stopped/Disabled]
  <C:\WINDOWS\system32\2VBIVLN2334Q.exe -8Y97VA><drw.kills>
[LENHSX41 / 2ZYXYE64][Stopped/Disabled]
  <C:\WINDOWS\2ZYXYE64.exe -B0267V6RS40><drw.kills>
[TMPZCA / 39U7BCBN8][Stopped/Disabled]
  <C:\WINDOWS\39U7BCBN8.exe -11U84D782ONR><drw.kills>
[NG8MERW3KWPW / 3BVCPZC5U][Stopped/Disabled]
  <C:\WINDOWS\3BVCPZC5U.exe -88G27Q7><drw.kills>
[TN4ZR0Z / 3CGJPEK70J][Stopped/Disabled]
  <C:\WINDOWS\3CGJPEK70J.exe -7J4X7><drw.kills>
[NTBFN / 3HYBQ][Stopped/Disabled]
  <C:\WINDOWS\3HYBQ.exe -9H3Y1TPWPJ><drw.kills>
[XERTT2VJK3F5 / 3JQ6HPDCMC3C][Stopped/Disabled]
  <C:\WINDOWS\3JQ6HPDCMC3C.exe -XI8EP5Q7><drw.kills>
[FX7E8L6P0PX / 3OJY35JQA0P1][Stopped/Disabled]
  <C:\WINDOWS\3OJY35JQA0P1.exe -G1IK0RQCYZ3><drw.kills>
[PEK6K2PPLER / 3X6IZE78][Stopped/Disabled]
  <C:\WINDOWS\system32\3X6IZE78.exe -XCGSPOXD><drw.kills>
[00UEKS / 3YFS4WDBXYH][Stopped/Disabled]
  <C:\WINDOWS\system32\3YFS4WDBXYH.exe -24UCA><drw.kills>
[UR07R7DUQYT / 45II8Y1G][Stopped/Disabled]
  <C:\WINDOWS\45II8Y1G.exe -4VZWOBLRO><drw.kills>
[14OJAH2E / 47FSSIWWZX][Stopped/Disabled]
  <C:\WINDOWS\system32\47FSSIWWZX.exe -H99IAUE><drw.kills>
[EJ08AMWJVTF / 4C8VVE][Stopped/Disabled]
  <C:\WINDOWS\4C8VVE.exe -HLI8I01BAHUF><drw.kills>
[CWVR8I / 4F70OUCFC][Stopped/Disabled]
  <C:\WINDOWS\system32\4F70OUCFC.exe -HJUHQUP><drw.kills>
[ANI2KYVUVN / 4GY0FBATM54][Stopped/Disabled]
  <C:\WINDOWS\4GY0FBATM54.exe -0PTNCVIVEK97><drw.kills>
[S5UL7 / 4MNQ11H45][Stopped/Disabled]
  <C:\WINDOWS\4MNQ11H45.exe -D3EGV4103S><drw.kills>
[HHRPW / 4QU7O1YZUNF][Stopped/Disabled]
  <C:\WINDOWS\system32\4QU7O1YZUNF.exe -0TM5XWLEH1><drw.kills>
[KQQ9L3L90 / 4TVKXLXRXHB][Stopped/Disabled]
  <C:\WINDOWS\4TVKXLXRXHB.exe -VGITVX0CC0C><drw.kills>
[721N1RO / 4XHTPV8B6LV][Stopped/Disabled]
  <C:\WINDOWS\system32\4XHTPV8B6LV.exe -XAXIRMRYGTK><drw.kills>
[XDRMAX3SC8H / 5IMWICT][Stopped/Disabled]
  <C:\WINDOWS\system32\5IMWICT.exe -GWLMJ3IZN><drw.kills>
[JJYDKXYVGTHT / 5RL0TSAMVM][Stopped/Disabled]
  <C:\WINDOWS\5RL0TSAMVM.exe -4ZM3NCDE5AT2><drw.kills>
[48ZDNS6 / 5S4D9I8F][Stopped/Disabled]
  <C:\WINDOWS\5S4D9I8F.exe -XAQ64AU8YK><drw.kills>
[CH4GA7FL8 / 5VXNGXH][Stopped/Disabled]
  <C:\WINDOWS\system32\5VXNGXH.exe -DBWZLU5OQIE><drw.kills>
[CVQY6GKUU7 / 60DB72][Stopped/Disabled]
  <C:\WINDOWS\system32\60DB72.exe -ICJ8AW4><drw.kills>
[9T9WBG / 641FGEMP][Stopped/Disabled]
  <C:\WINDOWS\641FGEMP.exe -65G76I9P><drw.kills>
[58OW598 / 6A7EFELF71][Stopped/Disabled]
  <C:\WINDOWS\6A7EFELF71.exe -K0Z9M2><drw.kills>
[DGW78SPL / 6AD23FSNF][Stopped/Disabled]
  <C:\WINDOWS\system32\6AD23FSNF.exe -QQWPOODC2><drw.kills>
[WI87L7JLXM / 6J784HKVQ][Stopped/Disabled]
  <C:\WINDOWS\system32\6J784HKVQ.exe -TFAGZT7RZN9><drw.kills>
[BC3604JI / 6Q2O4NC27N][Stopped/Disabled]
  <C:\WINDOWS\system32\6Q2O4NC27N.exe -DZS1RVA><drw.kills>
[2HSX7 / 6QMAD][Stopped/Disabled]
  <C:\WINDOWS\system32\6QMAD.exe -WJIII><drw.kills>
[5ED9Y / 76B5JAMBDLL][Stopped/Disabled]
  <C:\WINDOWS\system32\76B5JAMBDLL.exe -M1XAGRD62><drw.kills>
[R7ZZR1MS7SY / 7AVJ69BV93T][Stopped/Disabled]
  <C:\WINDOWS\7AVJ69BV93T.exe -X88BSKL1><drw.kills>
[Y4MF1IV / 7FED2GRY][Stopped/Disabled]
  <C:\WINDOWS\7FED2GRY.exe -CF3XMCC6V9RQ><drw.kills>
[8H8N2SZ437 / 7IR1FEWD][Stopped/Disabled]
  <C:\WINDOWS\7IR1FEWD.exe -IDMG8NE8><drw.kills>
[H1NUZT / 7K5LH][Stopped/Disabled]
  <C:\WINDOWS\system32\7K5LH.exe -ZD7VFVDQL><drw.kills>
[PDF47PUEZN / 7V4LU6][Stopped/Disabled]
  <C:\WINDOWS\system32\7V4LU6.exe -14BBQ><drw.kills>
[IWWT3UHM / 7WKZH1LU][Stopped/Disabled]
  <C:\WINDOWS\7WKZH1LU.exe -WUEG01HRK><drw.kills>
[O7LHINGEWG3A / 82C0O][Stopped/Disabled]
  <C:\WINDOWS\system32\82C0O.exe -VCT2MPHVHV><drw.kills>
[27D2JD3 / 85685][Stopped/Disabled]
  <C:\WINDOWS\85685.exe -NYOX3PVTROH4><drw.kills>
[UDIEUTI6D / 87IK7R4X][Stopped/Disabled]
  <C:\WINDOWS\system32\87IK7R4X.exe -M4EV5X58><drw.kills>
[PYPZHBSPT0 / 899QSS7QBA80][Stopped/Disabled]
  <C:\WINDOWS\899QSS7QBA80.exe -60JNSL37><drw.kills>
[8561C4IXKE5 / 8DM6V904XR][Stopped/Disabled]
  <C:\WINDOWS\system32\8DM6V904XR.exe -TG178L><drw.kills>
[ABM2DE6O / 8GXCO][Stopped/Disabled]
  <C:\WINDOWS\system32\8GXCO.exe -1VJVLOO1E97U><drw.kills>
[4RBW107LF92E / 8NJ48][Stopped/Disabled]
  <C:\WINDOWS\system32\8NJ48.exe -OIYB65><drw.kills>
[LB3TY6T / 8YJKY6A][Stopped/Disabled]
  <C:\WINDOWS\8YJKY6A.exe -RYMBUCFP2><drw.kills>
[OOSON / 938HAP][Stopped/Disabled]
  <C:\WINDOWS\938HAP.exe -1ABG3WO><drw.kills>
[ELVK8VGQZ9E6 / 95QPUJ0][Stopped/Disabled]
  <C:\WINDOWS\system32\95QPUJ0.exe -2W5AYV><drw.kills>
[GNTV0V8S / 9GQ6XFDSRU][Stopped/Disabled]
  <C:\WINDOWS\9GQ6XFDSRU.exe -41RZ08EYN><drw.kills>
[MYW7MZ7 / 9IMC8][Stopped/Disabled]
  <C:\WINDOWS\9IMC8.exe -5M79LDY4><drw.kills>
[DAIMA4N6L8HZ / 9KZE0OS431B7][Stopped/Disabled]
  <C:\WINDOWS\system32\9KZE0OS431B7.exe -OFOVL50VHLS><drw.kills>
[GQPM5COCJQ / A3WOVO91BZ][Stopped/Disabled]
  <C:\WINDOWS\system32\A3WOVO91BZ.exe -XDSHFPLOD6EW><drw.kills>
[II159 / A7WS88QAJU0T][Stopped/Disabled]
  <C:\WINDOWS\A7WS88QAJU0T.exe -ZLLIU80><drw.kills>
[DQIR3V / A9C973][Stopped/Disabled]
  <C:\WINDOWS\A9C973.exe -SAN25BODRY0><drw.kills>
[YUAFT / AAUWSCGD][Stopped/Disabled]
  <C:\WINDOWS\system32\AAUWSCGD.exe -4KZYWU46VX7H><drw.kills>
[WEHWD8A175 / AGW57Z1P][Stopped/Disabled]
  <C:\WINDOWS\AGW57Z1P.exe -YG283><drw.kills>
[MMSABB0PMXQ / AH2C8][Stopped/Disabled]
  <C:\WINDOWS\system32\AH2C8.exe -WVT2L2OA8E><drw.kills>
[SNCYEM / AH9B3AN98DOM][Stopped/Disabled]
  <C:\WINDOWS\system32\AH9B3AN98DOM.exe -AM7S9SF><drw.kills>
[AIZA2UZPD6 / ALO32][Stopped/Disabled]
  <C:\WINDOWS\system32\ALO32.exe -2Z8KV2C2><drw.kills>
[U2O5MI6 / AN3DF2LVY][Stopped/Disabled]
  <C:\WINDOWS\system32\AN3DF2LVY.exe -2BKMZAD6F6W6><drw.kills>
[O3MK403I / ATWWNI][Stopped/Disabled]
  <C:\WINDOWS\system32\ATWWNI.exe -C5TXGFTPZDCI><drw.kills>
[YOMODOB6 / AU4IOD1L1X3J][Stopped/Disabled]
  <C:\WINDOWS\system32\AU4IOD1L1X3J.exe -K2LAS8><drw.kills>
[0N28HO8W / AVCCX2TT4][Stopped/Disabled]
  <C:\WINDOWS\system32\AVCCX2TT4.exe -6SJJMM8NF2L><drw.kills>
[AW3L6CS16R / B3MMEW][Stopped/Disabled]
  <C:\WINDOWS\B3MMEW.exe -27F2F14KBED><drw.kills>
[RFPNU64YD / B4N063YCS0][Stopped/Disabled]
  <C:\WINDOWS\system32\B4N063YCS0.exe -HHHHFF><drw.kills>
[F6GVV7 / B60R2][Stopped/Disabled]
  <C:\WINDOWS\B60R2.exe -VFIM3SV20R><drw.kills>
[JNY3LTR34JU / BIINOTUS][Stopped/Disabled]
  <C:\WINDOWS\BIINOTUS.exe -KGSWW44NKI><drw.kills>
[J0HDW / BPBJPP][Stopped/Disabled]
  <C:\WINDOWS\BPBJPP.exe -JHCX9PQFAM><drw.kills>
[K1LX7G369D / BQ4XCA][Stopped/Disabled]
  <C:\WINDOWS\BQ4XCA.exe -J6HMCHT><drw.kills>
[BM3N1EXV / BRR18PC7OW][Stopped/Disabled]
  <C:\WINDOWS\BRR18PC7OW.exe -DCZHEFPW><drw.kills>
[WAEGZK2IVI / BSZ20XMONWR][Stopped/Disabled]
  <C:\WINDOWS\BSZ20XMONWR.exe -1RVHBUJGK2U><drw.kills>
[MHSLISAGL / C18ATT7][Stopped/Disabled]
  <C:\WINDOWS\system32\C18ATT7.exe -LSPPCW9M58><drw.kills>
[XAWI4TQQ0PR6 / C8HIT673][Stopped/Disabled]
  <C:\WINDOWS\C8HIT673.exe -AAO55GL12><drw.kills>
[UM314JD / CA9NJBP][Stopped/Disabled]
  <C:\WINDOWS\CA9NJBP.exe -3RWDU><drw.kills>
[V8VLNUM9X5GM / CGXBTR][Stopped/Disabled]
  <C:\WINDOWS\system32\CGXBTR.exe -MLIA1KP><drw.kills>
[6E8VJ4TJBI1M / CPUUMT81QJS][Stopped/Disabled]
  <C:\WINDOWS\CPUUMT81QJS.exe -ID8HYA8><drw.kills>
[3SZM8UK5IG7 / DA9EOS][Stopped/Disabled]
  <C:\WINDOWS\DA9EOS.exe -HT5QSEY5C><drw.kills>
[V1MG87SUS / DBXDG9VAU8][Stopped/Disabled]
  <C:\WINDOWS\system32\DBXDG9VAU8.exe -1ZJ5JNT3OFJW><drw.kills>
[DCOM Service Process Manager / DCOMManager][Stopped/Auto Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->c:\windows\inf\pcidevices8.inf><N/A>
[C2AB3C8DKWOR / DETBGXKLCS][Stopped/Disabled]
  <C:\WINDOWS\DETBGXKLCS.exe -G5F0C8><drw.kills>
[E7N8ER / DGYMIKPKT][Stopped/Disabled]
  <C:\WINDOWS\system32\DGYMIKPKT.exe -OL8YG6KEX6B5><drw.kills>
[WGWR4 / DKWHFCQKDXK][Stopped/Disabled]
  <C:\WINDOWS\DKWHFCQKDXK.exe -U0G7CBQFB4IK><drw.kills>
[LEJQAWRHTVDH / DOAKZHP32][Stopped/Disabled]
  <C:\WINDOWS\system32\DOAKZHP32.exe -13Y93K1><drw.kills>
[9MVVLB41IIYK / DRLBTK][Stopped/Disabled]
  <C:\WINDOWS\system32\DRLBTK.exe -RPP0572SKSLM><drw.kills>
[dtmu / dtmu][Stopped/Auto Start]
  <C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\yohp\iyrz.dll,Service -s><Microsoft Corporation>
[3FFAW3H / DVN8KIYP1C][Stopped/Disabled]
  <C:\WINDOWS\system32\DVN8KIYP1C.exe -0A04S><drw.kills>
[FANFG / DX2EFY0JQBLD][Stopped/Disabled]
  <C:\WINDOWS\DX2EFY0JQBLD.exe -N8RZJ6><drw.kills>
[ZTBKDQR / DYFS50AN63][Stopped/Disabled]
  <C:\WINDOWS\DYFS50AN63.exe -W2JJRF9T><drw.kills>
[4AF3ZZ1IP69 / E22MS9TY9BOA][Stopped/Disabled]
  <C:\WINDOWS\system32\E22MS9TY9BOA.exe -0SRU6H><drw.kills>
[J35GWJO / E2JZ0AJ][Stopped/Disabled]
  <C:\WINDOWS\E2JZ0AJ.exe -8PW73><drw.kills>
[D910ZE / E6XE4BA9][Stopped/Disabled]
  <C:\WINDOWS\system32\E6XE4BA9.exe -WDVCB><drw.kills>
[0MQPDRTJDR / E9YN6HZ][Stopped/Disabled]
  <C:\WINDOWS\system32\E9YN6HZ.exe -5J4MH><drw.kills>
[FCFGDM / EBRF04][Stopped/Disabled]
  <C:\WINDOWS\EBRF04.exe -84QNZ><drw.kills>
[KKABBX / EL18GKHWE][Stopped/Disabled]
  <C:\WINDOWS\system32\EL18GKHWE.exe -X4B2SF><drw.kills>
[YUI2DYG / EPTOQ2][Stopped/Disabled]
  <C:\WINDOWS\EPTOQ2.exe -ZBYWNY8ZZ7><drw.kills>
[1TBQYRA / EUNMA][Stopped/Disabled]
  <C:\WINDOWS\EUNMA.exe -DGLXUJTP><drw.kills>
[7203C77YZPKI / EWARQ][Stopped/Disabled]
  <C:\WINDOWS\EWARQ.exe -HHJFPFC><drw.kills>
[TME2ZLQ / F03HX3WWS3G][Stopped/Disabled]
  <C:\WINDOWS\F03HX3WWS3G.exe -CG9RSS2L8><drw.kills>
[6D3LY / F80TB][Stopped/Disabled]
  <C:\WINDOWS\F80TB.exe -Z4FLOEGV50Z><drw.kills>
[EDXT698UM0TY / F8GGTFCQAO][Stopped/Disabled]
  <C:\WINDOWS\system32\F8GGTFCQAO.exe -6LCSL8AJ><drw.kills>
[LWTGAAM / F9R952QHSR][Stopped/Disabled]
  <C:\WINDOWS\F9R952QHSR.exe -9UJD0><drw.kills>
[H0728PF / FEEUL][Stopped/Disabled]
  <C:\WINDOWS\system32\FEEUL.exe -Q1BXIFTQHQ><drw.kills>
[7TBLS6O2 / FFU0W][Stopped/Disabled]
  <C:\WINDOWS\FFU0W.exe -6UH8HSW5I><drw.kills>
[G3ZE5ZW / FI66R4H05LX][Stopped/Disabled]
  <C:\WINDOWS\system32\FI66R4H05LX.exe -9RJOXO8X><drw.kills>
[W1XVX9LH1S1 / FKRD6][Stopped/Disabled]
  <C:\WINDOWS\FKRD6.exe -9XG7AHB2D><drw.kills>
[TBUVWLHF4 / FR2IF][Stopped/Disabled]
  <C:\WINDOWS\FR2IF.exe -M62MINC9><drw.kills>
[G4OW36 / FWDMYAE3AI][Stopped/Disabled]
  <C:\WINDOWS\FWDMYAE3AI.exe -2YCVCMLTDGU><drw.kills>
[WGS3TTEO / FWEHJ][Stopped/Disabled]
  <C:\WINDOWS\system32\FWEHJ.exe -N61K47G1T9T><drw.kills>
[9Z5EC2K8OU78 / FYJKCCWF5JD][Stopped/Disabled]
  <C:\WINDOWS\FYJKCCWF5JD.exe -460F7Z><drw.kills>
[8X7YI / G6JAN64][Stopped/Disabled]
  <C:\WINDOWS\system32\G6JAN64.exe -GBAOWMO0FI7><drw.kills>
[FBCG9ZETV / G9R10779M0RV][Stopped/Disabled]
  <C:\WINDOWS\G9R10779M0RV.exe -DDDDHW><drw.kills>
[5YEOZL114X9 / GGG5ID5KP4][Stopped/Disabled]
  <C:\WINDOWS\system32\GGG5ID5KP4.exe -YGGD7U3NZNE><drw.kills>
[58F1D1I8O4 / GJNL9][Stopped/Disabled]
  <C:\WINDOWS\GJNL9.exe -SXM6SZMSL><drw.kills>
[FPR6CB48QOCJ / GK73YJJ][Stopped/Disabled]
  <C:\WINDOWS\GK73YJJ.exe -H6QINVH><drw.kills>
[PMFIP / GKHKP5E][Stopped/Disabled]
  <C:\WINDOWS\system32\GKHKP5E.exe -WL73PT6MJ><drw.kills>
[ZP4BY2FLEU / GLLOWI3CIGA8][Stopped/Disabled]
  <C:\WINDOWS\GLLOWI3CIGA8.exe -R9PCBV><drw.kills>
[WQY7HQ / GNG4L4A][Stopped/Disabled]
  <C:\WINDOWS\system32\GNG4L4A.exe -UNG5QKGSO5T5><drw.kills>
[AVY7M543 / GOGUJB8][Stopped/Disabled]
  <C:\WINDOWS\system32\GOGUJB8.exe -HFO8X94YUR8D><drw.kills>
[Z323KQU / GPYJD8FWIF][Stopped/Disabled]
  <C:\WINDOWS\system32\GPYJD8FWIF.exe -MSXCKZ><drw.kills>
[HBGKY / GR4FOG][Stopped/Disabled]
  <C:\WINDOWS\system32\GR4FOG.exe -DQR57GX0WV6><drw.kills>
[NNFUI / GRRUZJ5BO6][Stopped/Disabled]
  <C:\WINDOWS\system32\GRRUZJ5BO6.exe -1L2FNF3PEX><drw.kills>
[XHFTGFAKU / GT3OURAS2][Stopped/Disabled]
  <C:\WINDOWS\system32\GT3OURAS2.exe -3H952EQ><drw.kills>
[VP6M2RWT6 / GU6OXSXSYG6P][Stopped/Disabled]
  <C:\WINDOWS\system32\GU6OXSXSYG6P.exe -D2QPAST7L><drw.kills>
[NPBYV5C / GWMPXJ][Stopped/Disabled]
  <C:\WINDOWS\GWMPXJ.exe -GI1V38><drw.kills>
[07ZFIUX6AR / GX7I835HRW][Stopped/Disabled]
  <C:\WINDOWS\GX7I835HRW.exe -H9AMVYUY><drw.kills>
[TNQQOZS / H152IWLPO5][Stopped/Disabled]
  <C:\WINDOWS\H152IWLPO5.exe -6WQ7XAXVE><drw.kills>
[HOL9VT8MQ / H1H94AHY][Stopped/Disabled]
  <C:\WINDOWS\system32\H1H94AHY.exe -H9I3HV8B6QVX><drw.kills>
[PQUNVB / H6UGVKIX3AQ6][Stopped/Disabled]
  <C:\WINDOWS\H6UGVKIX3AQ6.exe -8CY5R8U><drw.kills>
[PGLVY4B / H92QMAO9][Stopped/Disabled]
  <C:\WINDOWS\system32\H92QMAO9.exe -19WI3Q><drw.kills>
[NUADEGOVU / HAVXGNTAF][Stopped/Disabled]
  <C:\WINDOWS\system32\HAVXGNTAF.exe -9D58H><drw.kills>
[P7J4TZD / HCXASNJ][Stopped/Disabled]
  <C:\WINDOWS\HCXASNJ.exe -MYE2X43KQA><drw.kills>
[1MOE75CX / HJK2VQOR78][Stopped/Disabled]
  <C:\WINDOWS\HJK2VQOR78.exe -J6U9L><drw.kills>
[HLQ77I49V / HKV51][Stopped/Disabled]
  <C:\WINDOWS\system32\HKV51.exe -6QS7B5G><drw.kills>
[2K43DPI / HLGB1W2C][Stopped/Disabled]
  <C:\WINDOWS\system32\HLGB1W2C.exe -RV01LVR><drw.kills>
[9UVO7T26 / HS51BJC][Stopped/Disabled]
  <C:\WINDOWS\system32\HS51BJC.exe -GSQX0UVWI8><drw.kills>
[084PCB6WR8 / I76SWTODGE][Stopped/Disabled]
  <C:\WINDOWS\I76SWTODGE.exe -YMAO9AH396><drw.kills>
[O516YBG02 / I938HA][Stopped/Disabled]
  <C:\WINDOWS\I938HA.exe -4WRO0LWG40><drw.kills>
[L7P266HE2QE / IBB2B][Stopped/Disabled]
  <C:\WINDOWS\system32\IBB2B.exe -QS1L54IXEIP><drw.kills>
[X2DF8 / IF0C1A9A8R8W][Stopped/Disabled]
  <C:\WINDOWS\IF0C1A9A8R8W.exe -OEVW1><drw.kills>
[9OE36ARC2CKP / IF88R8JYDNEQ][Stopped/Disabled]
  <C:\WINDOWS\system32\IF88R8JYDNEQ.exe -2RLW4DC><drw.kills>
[KUFLL0 / IJFEXKQMGHXL][Stopped/Disabled]
  <C:\WINDOWS\IJFEXKQMGHXL.exe -Q9KM5><drw.kills>
[XNKHZKM6TLD7 / IL8VR47XRV][Stopped/Disabled]
  <C:\WINDOWS\system32\IL8VR47XRV.exe -BTQ8V48FYE><drw.kills>
[XK85F / IOJRZVRTI10O][Stopped/Disabled]
  <C:\WINDOWS\system32\IOJRZVRTI10O.exe -9RUN2TO1IMXT><drw.kills>
[TLXL8R7083XE / IQSDW][Stopped/Disabled]
  <C:\WINDOWS\system32\IQSDW.exe -RJWKSI2><drw.kills>
[PQ4SU / IT6QM3][Stopped/Disabled]
  <C:\WINDOWS\IT6QM3.exe -F5D2HQQWM82><drw.kills>
[O0PM8EX / J23ECO52B][Stopped/Disabled]
  <C:\WINDOWS\J23ECO52B.exe -562OQY><drw.kills>
[3DIN2Q0DJ / J5BIN38T7][Stopped/Disabled]
  <C:\WINDOWS\J5BIN38T7.exe -F4ABE><drw.kills>
[5CJE9MX3 / J5BNFRS9ME][Stopped/Disabled]
  <C:\WINDOWS\J5BNFRS9ME.exe -X3T02FDK6><drw.kills>
[DYWJJAV6 / J66BJ4RLUSB7][Stopped/Disabled]
  <C:\WINDOWS\system32\J66BJ4RLUSB7.exe -11C9MG6OX><drw.kills>
[24WEB9I9TY / JDB4MW][Stopped/Disabled]
  <C:\WINDOWS\system32\JDB4MW.exe -172PWH4LMW><drw.kills>
[87A56308S7H / JG81EFN6GKC][Stopped/Disabled]
  <C:\WINDOWS\system32\JG81EFN6GKC.exe -VPZ89YZVC8K><drw.kills>
[RW1ENJYIT / JGKFL8B][Stopped/Disabled]
  <C:\WINDOWS\JGKFL8B.exe -T82VYX5A1><drw.kills>
[AR64ZNQ / JXZ39D8][Stopped/Disabled]
  <C:\WINDOWS\system32\JXZ39D8.exe -LZCQE570AT14><drw.kills>
[Z78LD2YSANIJ / K6KYNK96582S][Stopped/Disabled]
  <C:\WINDOWS\K6KYNK96582S.exe -477ULN1DE3T0><drw.kills>
[U4A1OTXV3 / K6UM0][Stopped/Disabled]
  <C:\WINDOWS\system32\K6UM0.exe -67H46DK><drw.kills>
[NYR6R / KD9UQU3I249X][Stopped/Disabled]
  <C:\WINDOWS\system32\KD9UQU3I249X.exe -MYS4URH5T><drw.kills>
[9G5WHIU2CJ5 / KEQHGNAU][Stopped/Disabled]
  <C:\WINDOWS\KEQHGNAU.exe -8LUCMF1XL7GU><drw.kills>
[IURARC4B / KGSM2OZZV4][Stopped/Disabled]
  <C:\WINDOWS\system32\KGSM2OZZV4.exe -ENGPQ6><drw.kills>
[IE0QJ0 / KTNEVR][Stopped/Disabled]
  <C:\WINDOWS\KTNEVR.exe -FJSOPM><drw.kills>
[0MBGTR384G / KXH5J11O1][Stopped/Disabled]
  <C:\WINDOWS\system32\KXH5J11O1.exe -71L0SMR9><drw.kills>
[A2UXS / KXXLWELMFZQW][Stopped/Disabled]
  <C:\WINDOWS\system32\KXXLWELMFZQW.exe -81DIO8KW><drw.kills>
[GMLHX5CFXB / KZQPAN9AH][Stopped/Disabled]
  <C:\WINDOWS\system32\KZQPAN9AH.exe -RXS1BQUM7882><drw.kills>
[NT Data Provider / lDOMANE][Stopped/Disabled]
  <C:\WINDOWS\SYSTEM32\RUNDLL2KXP.EXE C:\WINDOWS\SYSTEM32\WBEM\ATJZQ.DLL,Export 1087><(File is missing)>
[46CPEEX0BRQ / LMSM1S][Stopped/Disabled]
  <C:\WINDOWS\LMSM1S.exe -C7CB4DLXA><drw.kills>
[HAIDFWVO / LN3495HA][Stopped/Disabled]
  <C:\WINDOWS\LN3495HA.exe -E0HU5WLA6Y><drw.kills>
[83QK7W4 / LQMLPP1][Stopped/Disabled]
  <C:\WINDOWS\LQMLPP1.exe -HLJMPOTHJ9H><drw.kills>
[6AQ3VRC1UB0 / LSLUI][Stopped/Disabled]
  <C:\WINDOWS\system32\LSLUI.exe -GWDYC><drw.kills>
[G9E2A9TT / LVC7XHOGQ95][Stopped/Disabled]
  <C:\WINDOWS\LVC7XHOGQ95.exe -EWLKZFKSJ><drw.kills>
[CP5YGUF / LY3MYJ9U][Stopped/Disabled]
  <C:\WINDOWS\LY3MYJ9U.exe -2YTTAZMT57G><drw.kills>
[Q9QZX1PPD / M10VB2SJ3Q][Stopped/Disabled]
  <C:\WINDOWS\system32\M10VB2SJ3Q.exe -7DVIBQUFFOO><drw.kills>
[MAM4Q1 / M2FFF6EBA][Stopped/Disabled]
  <C:\WINDOWS\M2FFF6EBA.exe -8CICIZWMX6><drw.kills>
[95WK88ZHJW81 / M2QD38P459F][Stopped/Disabled]
  <C:\WINDOWS\M2QD38P459F.exe -N81OC><drw.kills>
[7HL6J02 / M4RLN8JQS][Stopped/Disabled]
  <C:\WINDOWS\M4RLN8JQS.exe -4E81TCY01UCO><drw.kills>
[UAZVW1DEGVY / MHOEM9V9][Stopped/Disabled]
  <C:\WINDOWS\system32\MHOEM9V9.exe -XY8P4><drw.kills>
[P0FO5 / MM7CUSR][Stopped/Disabled]
  <C:\WINDOWS\system32\MM7CUSR.exe -8VOH0WOT3K><drw.kills>
[MOT8M7 / MPH6UU84][Stopped/Disabled]
  <C:\WINDOWS\MPH6UU84.exe -334WDS4IN><drw.kills>
[26U0B1PCUP / MU7U0EB][Stopped/Disabled]
  <C:\WINDOWS\MU7U0EB.exe -IGSG6LRL6TXW><drw.kills>
[MTFOD8Z / NENA6XY0][Stopped/Disabled]
  <C:\WINDOWS\NENA6XY0.exe -6JJYG><drw.kills>
[EQOMM6R / NF46LL9IC9WF][Stopped/Disabled]
  <C:\WINDOWS\NF46LL9IC9WF.exe -T7HMOWU><drw.kills>
[LOOQ7 / NFWIW79][Stopped/Disabled]
  <C:\WINDOWS\NFWIW79.exe -AZBRQWSWYQB><drw.kills>
[PLS39VV8H3S / NMUNM][Stopped/Disabled]
  <C:\WINDOWS\NMUNM.exe -EQB00ZSOUZG><drw.kills>
[ZAI1HLK / NQVAXIAJL10][Stopped/Disabled]
  <C:\WINDOWS\system32\NQVAXIAJL10.exe -QFOKJ4><drw.kills>
[ZQTWISJ05DE / NTNWCGSUWYDX][Stopped/Disabled]
  <C:\WINDOWS\system32\NTNWCGSUWYDX.exe -1LHFFUV4V><drw.kills>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[WD0WH5TN / NXKGARVPVA7Z][Stopped/Disabled]
  <C:\WINDOWS\system32\NXKGARVPVA7Z.exe -KGBOF477WZO><drw.kills>
[NAYV4J / NXYA9JN9WO2][Stopped/Disabled]
  <C:\WINDOWS\system32\NXYA9JN9WO2.exe -M3B2ANV><drw.kills>
[A0LHBCY1 / NYEVRNBBCJ][Stopped/Disabled]
  <C:\WINDOWS\system32\NYEVRNBBCJ.exe -US8JA><drw.kills>
[38ZY0G9 / O8H1U1][Stopped/Disabled]
  <C:\WINDOWS\system32\O8H1U1.exe -YMOECI4NQ><drw.kills>
[AWWIO / O9SP9OEOGN][Stopped/Disabled]
  <C:\WINDOWS\system32\O9SP9OEOGN.exe -V8A42E4VA6><drw.kills>
[PR757UP0GZ / OAIMPKRKNX5][Stopped/Disabled]
  <C:\WINDOWS\system32\OAIMPKRKNX5.exe -YOIIMWQ1GZR><drw.kills>
[WV9LP7L / OE4NH][Stopped/Disabled]
  <C:\WINDOWS\OE4NH.exe -HS5AHNNCZV><drw.kills>
[XRMF027 / OHBQV][Stopped/Disabled]
  <C:\WINDOWS\OHBQV.exe -GLITFLP3R1><drw.kills>
[JEI3X3VYXM / OKIW995][Stopped/Disabled]
  <C:\WINDOWS\system32\OKIW995.exe -0E0VSU4DQ><drw.kills>
[GQX913W6JR6 / OLDZ9B][Stopped/Disabled]
  <C:\WINDOWS\OLDZ9B.exe -GGPPX1><drw.kills>
[QFPZLYS / ON104V][Stopped/Disabled]
  <C:\WINDOWS\system32\ON104V.exe -Z9HIGQZDTGK><drw.kills>
[Q45JQ88QY / ON2FU9E6][Stopped/Disabled]
  <C:\WINDOWS\system32\ON2FU9E6.exe -X37DJSOUF><drw.kills>
[C6FAKUEDG / OPI6AEOGG5A8][Stopped/Disabled]
  <C:\WINDOWS\system32\OPI6AEOGG5A8.exe -7UTY6T2LXM><drw.kills>
[58802RV / OT62YD][Stopped/Disabled]
  <C:\WINDOWS\system32\OT62YD.exe -IJVF68><drw.kills>
[595DUC / OU33MUQV][Stopped/Disabled]
  <C:\WINDOWS\system32\OU33MUQV.exe -034OY7PBX7B><drw.kills>
[FZ0G3541 / OWD5T36BKYV8][Stopped/Disabled]
  <C:\WINDOWS\system32\OWD5T36BKYV8.exe -Y16VVEUM><drw.kills>
[ZEG7CNEE41 / OXEW6ZA4][Stopped/Disabled]
  <C:\WINDOWS\OXEW6ZA4.exe -9WDKZIZGH><drw.kills>
[J1ZHBHKK / P23VRQYR45][Stopped/Disabled]
  <C:\WINDOWS\P23VRQYR45.exe -D91XR><drw.kills>
[9PKUQNR4 / P44HUI0CMU3P][Stopped/Disabled]
  <C:\WINDOWS\P44HUI0CMU3P.exe -VFTVS3SCZ4><drw.kills>
[V22KHS7T / P5UXH85PLZ][Stopped/Disabled]
  <C:\WINDOWS\P5UXH85PLZ.exe -Q2W03S9><drw.kills>
[5IYE9ST2M / PD93U][Stopped/Disabled]
  <C:\WINDOWS\PD93U.exe -PO5PI><drw.kills>
[MXJAX / PDG7X][Stopped/Disabled]
  <C:\WINDOWS\system32\PDG7X.exe -O2HR7XHTDQRH><drw.kills>
[GF451U / PLLUWFTDS9][Stopped/Disabled]
  <C:\WINDOWS\PLLUWFTDS9.exe -GH4ST6><drw.kills>
[4C9CB3JQO / PRJNAZTX6R][Stopped/Disabled]
  <C:\WINDOWS\system32\PRJNAZTX6R.exe -N89RKA1><drw.kills>
[946VY6W23 / PRNIK9848BEQ][Stopped/Disabled]
  <C:\WINDOWS\system32\PRNIK9848BEQ.exe -EI5G9KDNT><drw.kills>
[19ALC3NI / PS0TEF9B][Stopped/Disabled]
  <C:\WINDOWS\system32\PS0TEF9B.exe -RZCD5FU><drw.kills>
[3PQRSBU / PTPDVMFL][Stopped/Disabled]
  <C:\WINDOWS\system32\PTPDVMFL.exe -IX51VJIMG4O><drw.kills>
[GBWRC0H4 / PUQ0L][Stopped/Disabled]
  <C:\WINDOWS\PUQ0L.exe -X9XGETMRPM><drw.kills>
[IA667PB / PVNRBFM2C97G][Stopped/Disabled]
  <C:\WINDOWS\PVNRBFM2C97G.exe -M383OW><drw.kills>
[G8WDDHFVO / Q4BXLB8NPF4][Stopped/Disabled]
  <C:\WINDOWS\system32\Q4BXLB8NPF4.exe -L8N5M><drw.kills>
[46LYD / Q5IFSR][Stopped/Disabled]
  <C:\WINDOWS\system32\Q5IFSR.exe -CBX0MGX><drw.kills>
[J7ZYGV / Q920I5X][Stopped/Disabled]
  <C:\WINDOWS\Q920I5X.exe -2RWST4><drw.kills>
[QB2YN5MASS / Q9V57][Stopped/Disabled]
  <C:\WINDOWS\system32\Q9V57.exe -IHHAB><drw.kills>
[OYR9RVH / QCT63U9PLTC][Stopped/Disabled]
  <C:\WINDOWS\system32\QCT63U9PLTC.exe -H1IKE7KKFZN0><drw.kills>
[OJPBVTTA / QEWARQ6ENF8][Stopped/Disabled]
  <C:\WINDOWS\QEWARQ6ENF8.exe -203C77YZPK><drw.kills>
[ARHQUYFNF6 / QIGBJO6SZ][Stopped/Disabled]
  <C:\WINDOWS\system32\QIGBJO6SZ.exe -FFZ2SUOV1NE><drw.kills>
[MNUTYA / QIGEMBZN][Stopped/Disabled]
  <C:\WINDOWS\QIGEMBZN.exe -EDK0O><drw.kills>
[KGB9TZM / QS6RH][Stopped/Disabled]
  <C:\WINDOWS\system32\QS6RH.exe -P6HZFK5EAL><drw.kills>
[S77SV / R7A0E][Stopped/Disabled]
  <C:\WINDOWS\R7A0E.exe -INU0AAV><drw.kills>
[IQEADK3YLSC / R9IWRGE4LO][Stopped/Disabled]
  <C:\WINDOWS\R9IWRGE4LO.exe -NV7GIX8><drw.kills>
[54TWEM / R9ZFU3I5][Stopped/Disabled]
  <C:\WINDOWS\system32\R9ZFU3I5.exe -Y5WO88M><drw.kills>
[O7D36 / RDPL7VT4SY][Stopped/Disabled]
  <C:\WINDOWS\system32\RDPL7VT4SY.exe -KFRJLUL5HJO><drw.kills>
[4Z6V0I / RHJ3UO2WZ8N][Stopped/Disabled]
  <C:\WINDOWS\RHJ3UO2WZ8N.exe -U5HQIX0H><drw.kills>
[OQP7YE6FHL1 / RJTPJI][Stopped/Disabled]
  <C:\WINDOWS\system32\RJTPJI.exe -OTFWTP6><drw.kills>
[5LC70ZK / RLE0DZB][Stopped/Disabled]
  <C:\WINDOWS\RLE0DZB.exe -PL4SZG4><drw.kills>
[YFHEP1 / RLWDK0AC1M][Stopped/Disabled]
  <C:\WINDOWS\system32\RLWDK0AC1M.exe -BPW9IC><drw.kills>
[LE3QY / RVSZIMP4P][Stopped/Disabled]
  <C:\WINDOWS\system32\RVSZIMP4P.exe -00CEHH><drw.kills>
[P6C5MZ / RXB0EPA3Y][Stopped/Disabled]
  <C:\WINDOWS\system32\RXB0EPA3Y.exe -BSNHKPRS15C><drw.kills>
[2OOU0IWP1 / RYJBH][Stopped/Disabled]
  <C:\WINDOWS\system32\RYJBH.exe -WG4YZWYA><drw.kills>
[T4I0PQZ / S8UQFT2MW5][Stopped/Disabled]
  <C:\WINDOWS\S8UQFT2MW5.exe -QVK98YTQ><drw.kills>
[Security Control / seictrl][Stopped/Auto Start]
  <c:\windows\system32\rundll32.exe dbi100.dll,scan><Microsoft Corporation>
[716O4 / SLGMG9A17][Stopped/Disabled]
  <C:\WINDOWS\SLGMG9A17.exe -CQ3WRBKT><drw.kills>
[Cryptographic Machine / SmallCenter][Stopped/Auto Start]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\vtpsh.dll><N/A>
[8H8GY6P / SN7HY4GS5IV][Stopped/Disabled]
  <C:\WINDOWS\system32\SN7HY4GS5IV.exe -NGFOHYK31WE><drw.kills>
[JPRNCO2 / SVNBA064][Stopped/Disabled]
  <C:\WINDOWS\system32\SVNBA064.exe -VY9YBGEA4A><drw.kills>
[JSTACVFTJ1AJ / T5MITD4FAQ][Stopped/Disabled]
  <C:\WINDOWS\system32\T5MITD4FAQ.exe -86C3YOIU><drw.kills>
[A9HLU / TDJWSWOQ][Stopped/Disabled]
  <C:\WINDOWS\system32\TDJWSWOQ.exe -FNKNYO><drw.kills>
[S730YPY8OJ7 / TFC56][Stopped/Disabled]
  <C:\WINDOWS\system32\TFC56.exe -KN7YOC5PH4NO><drw.kills>
[MC6NQ / TII28GT5][Stopped/Disabled]
  <C:\WINDOWS\system32\TII28GT5.exe -2D24CUJIC7VJ><drw.kills>
[CY2ZDOQ / TM2KCFY6A][Stopped/Disabled]
  <C:\WINDOWS\system32\TM2KCFY6A.exe -5DBFZGEK><drw.kills>
[KKSF38NA4R / TO2R8QK][Stopped/Disabled]
  <C:\WINDOWS\TO2R8QK.exe -B1FVB6TQ><drw.kills>
[mspx / TOlb][Stopped/Disabled]
  <C:\WINDOWS\system32\toolba.exe><N/A>
[L03DDQXP5 / TRRPIBJ][Stopped/Disabled]
  <C:\WINDOWS\TRRPIBJ.exe -A4CM1X9N><drw.kills>
[OV9DZWE7K / U08C89CBH][Stopped/Disabled]
  <C:\WINDOWS\system32\U08C89CBH.exe -OXAGH468PNS1><drw.kills>
[G3H8MRR / U4GEA9H][Stopped/Disabled]
  <C:\WINDOWS\U4GEA9H.exe -J7T1043Z><drw.kills>
[5ZLACQGWY5 / U5F0UT0XPPF][Stopped/Disabled]
  <C:\WINDOWS\system32\U5F0UT0XPPF.exe -9A13NE><drw.kills>
[9I7JK / U9DS22B0E][Stopped/Disabled]
  <C:\WINDOWS\U9DS22B0E.exe -CCRQE9HAYJ5><drw.kills>
[UG9FN / U9V2CJ7SHF8V][Stopped/Disabled]
  <C:\WINDOWS\U9V2CJ7SHF8V.exe -M65B84SA><drw.kills>
[HC172 / U9X6803BPY3X][Stopped/Disabled]
  <C:\WINDOWS\U9X6803BPY3X.exe -XOXER9VUXB9><drw.kills>
[OOYV9 / UAP1V0][Stopped/Disabled]
  <C:\WINDOWS\UAP1V0.exe -POPKIKQHOWC6><drw.kills>
[57WC4T1NBY / UBOH1UJ4OW1][Stopped/Disabled]
  <C:\WINDOWS\system32\UBOH1UJ4OW1.exe -I6VHUQ><drw.kills>
[FDJ2MZAFHSRE / UGXJXV5][Stopped/Disabled]
  <C:\WINDOWS\UGXJXV5.exe -90FAPUIN><drw.kills>
[FI98I / UMZMNEEVLB][Stopped/Disabled]
  <C:\WINDOWS\UMZMNEEVLB.exe -GEYITI2SSK><drw.kills>
[VMC4IC0BR7 / UR0Z8P2][Stopped/Disabled]
  <C:\WINDOWS\UR0Z8P2.exe -VC25IY><drw.kills>
[F0M7NT0NWAJC / UYS9SD][Stopped/Disabled]
  <C:\WINDOWS\UYS9SD.exe -4GZ5T><drw.kills>
[D2PQ7YVK / V0794E3FZ77][Stopped/Disabled]
  <C:\WINDOWS\V0794E3FZ77.exe -J1R4IMWLDY6><drw.kills>
[PRWH3T72CG5 / VAWZ4S0KW][Stopped/Disabled]
  <C:\WINDOWS\system32\VAWZ4S0KW.exe -W40PP><drw.kills>
[X2M956K00XN / VDUZ8LTN8G][Stopped/Disabled]
  <C:\WINDOWS\system32\VDUZ8LTN8G.exe -Y05QMH4PBVD><drw.kills>
[O4MKTK7AK1 / VHGXIWK2AV][Stopped/Disabled]
  <C:\WINDOWS\system32\VHGXIWK2AV.exe -MO3HLP><drw.kills>
[NVIDIA VideoCard Driver / VideoCard][Stopped/Disabled]
  <C:\WINDOWS\IPdriver.exe><(File is missing)>
[A1TEWIZWVO / VNOL70HL6DFV][Stopped/Disabled]
  <C:\WINDOWS\VNOL70HL6DFV.exe -JMLEX5LFJK><drw.kills>
[BT85GATGHFBZ / VR232S7L9W][Stopped/Disabled]
  <C:\WINDOWS\system32\VR232S7L9W.exe -4OWXG7UX><drw.kills>
[RWI16XY / VRAZWCG45QI][Stopped/Disabled]
  <C:\WINDOWS\VRAZWCG45QI.exe -BRXZHWATDY><drw.kills>
[CHTA3IQKNNL2 / VSYM5O][Stopped/Disabled]
  <C:\WINDOWS\VSYM5O.exe -0MAMY29><drw.kills>
[WX09OW / VUYTZD5F][Stopped/Disabled]
  <C:\WINDOWS\system32\VUYTZD5F.exe -SMJ6EGHHTZ><drw.kills>
[CYHWDPG6M / VVN6C9J][Stopped/Disabled]
  <C:\WINDOWS\VVN6C9J.exe -UUISU0T3OH4G><drw.kills>
[19QWAA8E5O / VWU8IE8UQ36I][Stopped/Disabled]
  <C:\WINDOWS\system32\VWU8IE8UQ36I.exe -V4PAO7NX><drw.kills>
[IPDLDP3Y51E / VXEPPHHHNC][Stopped/Disabled]
  <C:\WINDOWS\system32\VXEPPHHHNC.exe -FWSSX90><drw.kills>
[UREPI7 / WC2BOR2][Stopped/Disabled]
  <C:\WINDOWS\WC2BOR2.exe -YLZTZO1><drw.kills>
[VVWWU9NXS / WDZTS0I3F][Stopped/Disabled]
  <C:\WINDOWS\WDZTS0I3F.exe -OG7LPT><drw.kills>
[51736T0T / WKXT71TM][Stopped/Disabled]
  <C:\WINDOWS\WKXT71TM.exe -5JM04FNPM9AN><drw.kills>
[XUF50U2QIJ / WPJ6PXK][Stopped/Disabled]
  <C:\WINDOWS\WPJ6PXK.exe -AHT9V8><drw.kills>
[96EGN / XANSCRYH646][Stopped/Disabled]
  <C:\WINDOWS\XANSCRYH646.exe -5ROCC5T4D1D><drw.kills>
[PMKREZMV40I / XCD34MO85HLH][Stopped/Disabled]
  <C:\WINDOWS\system32\XCD34MO85HLH.exe -K97XRD4GZ1><drw.kills>
[LW6K31PW6UY / XE4QSAXE4RM][Stopped/Disabled]
  <C:\WINDOWS\XE4QSAXE4RM.exe -OVVDL7K4X><drw.kills>
[G2JUYUEXLD9P / XQ2ZE][Stopped/Disabled]
  <C:\WINDOWS\system32\XQ2ZE.exe -IJFPU9JV><drw.kills>
[K82OD2Y49TT / XYIMKRMTXM][Stopped/Disabled]
  <C:\WINDOWS\XYIMKRMTXM.exe -IQY9XUBYEWA><drw.kills>
[8RNQI2KJSC / Y3DWF01][Stopped/Disabled]
  <C:\WINDOWS\Y3DWF01.exe -E5B9B7S><drw.kills>
[DXELH / Y8HTHK0C302][Stopped/Disabled]
  <C:\WINDOWS\Y8HTHK0C302.exe -HBU1RGLNWG><drw.kills>
[0UH5L / Y8N45Q][Stopped/Disabled]
  <C:\WINDOWS\Y8N45Q.exe -9PDDQHMIDI9><drw.kills>
[TBBUB4ZG / YBGST25AS6L][Stopped/Disabled]
  <C:\WINDOWS\YBGST25AS6L.exe -LEFHG0R2><drw.kills>
[6DDISGL744W / YD249PNDB][Stopped/Disabled]
  <C:\WINDOWS\system32\YD249PNDB.exe -KY167YC6T><drw.kills>
[Q9E88JM0 / YEUABZDH][Stopped/Disabled]
  <C:\WINDOWS\system32\YEUABZDH.exe -3FV9E4><drw.kills>
[GU1FTU87SQS / YHX3P707Q][Stopped/Disabled]
  <C:\WINDOWS\YHX3P707Q.exe -BZC0Q><drw.kills>
[SCBUM6P4X / YKIZDZWS][Stopped/Disabled]
  <C:\WINDOWS\system32\YKIZDZWS.exe -F6QY0><drw.kills>
[DYY4EJ4 / YKRWQ7][Stopped/Disabled]
  <C:\WINDOWS\system32\YKRWQ7.exe -VA68W5HVQXU><drw.kills>
[HZGE08EG / YNE215MIQ0FM][Stopped/Disabled]
  <C:\WINDOWS\system32\YNE215MIQ0FM.exe -WU0C09FH><drw.kills>
[J7L6B / YW70N6][Stopped/Disabled]
  <C:\WINDOWS\system32\YW70N6.exe -09N1R9T77F><drw.kills>
[O76TTE2J / Z3STZM0ND][Stopped/Disabled]
  <C:\WINDOWS\system32\Z3STZM0ND.exe -9IAQV0><drw.kills>
[YYX6Y4SX334S / Z7IXF][Stopped/Disabled]
  <C:\WINDOWS\Z7IXF.exe -PEJMBVXRIT><drw.kills>
[89D4RASNGD / Z865QNQFE][Stopped/Disabled]
  <C:\WINDOWS\Z865QNQFE.exe -5IOF3315GFA8><drw.kills>
[E2SE8AXE / ZONG8F3Z][Stopped/Disabled]
  <C:\WINDOWS\ZONG8F3Z.exe -AYRDIKBNJO><drw.kills>
[WQQ98K80P7V0 / ZX4G1XZA3][Stopped/Disabled]
  <C:\WINDOWS\ZX4G1XZA3.exe -D3NQ6LZCCNC><drw.kills>
[YIWR3PUBA / ZZT5GS2ZJMI2][Stopped/Disabled]
  <C:\WINDOWS\ZZT5GS2ZJMI2.exe -SV9IF7TFTK98><drw.kills>
[KOZLCZ9L6 / UTC8T][Stopped/Auto Start]
  <C:\WINDOWS\UTC8T.exe -7V4DZW5><drw.kills>
[L4CTBE5H1BG / MGKUAVGH7ZR][Stopped/Auto Start]
  <C:\WINDOWS\MGKUAVGH7ZR.exe -SREFC1ZLL><drw.kills>
[6G6KNYQ91 / IX9OOD][Stopped/Auto Start]
  <C:\WINDOWS\IX9OOD.exe -GN8BR6><drw.kills>
[95HUV2G / PMD7S5NK57X7][Stopped/Auto Start]
  <C:\WINDOWS\PMD7S5NK57X7.exe -P43YCLZJ0GAU><drw.kills>
[24AZPH / TVEOQK2JW][Stopped/Auto Start]
  <C:\WINDOWS\TVEOQK2JW.exe -B6SOLLP102V><drw.kills>
[KTIGA1 / IQ00M][Stopped/Auto Start]
  <C:\WINDOWS\IQ00M.exe -MIS76><drw.kills>
[8JQ97Z6 / T8QZRFTD][Stopped/Auto Start]
  <C:\WINDOWS\system32\T8QZRFTD.exe -60D0KPRL><drw.kills>
[3JBUO6Y9FE / 42DWZ][Stopped/Auto Start]
  <C:\WINDOWS\system32\42DWZ.exe -8EL06MZKHH><drw.kills>
[S8FX7BJ / BDVVE4HJ][Stopped/Auto Start]
  <C:\WINDOWS\system32\BDVVE4HJ.exe -4XU48LUG9R8><drw.kills>
[2UL92ZQ / Y30X690V63H6][Stopped/Auto Start]
  <C:\WINDOWS\system32\Y30X690V63H6.exe -O4XBSFNVC1><drw.kills>
[ZNSE1RQSH3 / FOTMN8UFH][Stopped/Auto Start]
  <C:\WINDOWS\system32\FOTMN8UFH.exe -13CZEGJ292><drw.kills>
[L3WD96 / CXU1KO][Stopped/Auto Start]
  <C:\WINDOWS\system32\CXU1KO.exe -WG5UQU189><drw.kills>
————————————————————————————————————
在扫日志的SRENG工具》启动项目》服务》驱动程序》里面找下面项删除,
==================================
驱动程序
[LF1UWEY / 6LQPSP][Stopped/Manual Start]
  <\??\C:\WINDOWS\5VOJ81NG5.txt><N/A>

[805m / 805m][Stopped/Boot Start]
  <\SystemRoot\system32\drivers\805m.sys><N/A>

[VMQ7V / 9J2KF8P][Stopped/Manual Start]
  <\??\C:\WINDOWS\2GSSUF.txt><N/A>

[8GCIR6ROY / 9SEXO][Stopped/Manual Start]
  <\??\C:\WINDOWS\XROIGII11.txt><N/A>

[Atixeve2859 / Atixeve2859][Stopped/Manual Start]
  <\??\C:\DOCUME~1\woe\LOCALS~1\Temp\~wxp2ins.656.tmp><N/A>

[BdGuard / BdGuard][Running/Boot Start]
  <\SystemRoot\system32\drivers\BDGuard.SYS><>

[e2o8jcv / e2o8jcva][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\e2o8jcva.sys><N/A>

[ec3e6508c0d7c9ad / ec3e6508c0d7c9ad][Stopped/Manual Start]
  <\??\C:\ec3e6508c0d7c9ad.dat><N/A>

[gqjl / gqjls][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\gqjls.sys><N/A>

[IIS Manager  / IIS Manager ][Stopped/Manual Start]
  <\??\C:\DOCUME~1\woe\LOCALS~1\Temp\1.tmp><N/A>

[IX4IH66SUA1 / KDXOAC51KCL7][Stopped/Manual Start]
  <\??\C:\WINDOWS\BL4VQNJ242.txt><N/A>

[OME5VMY6Q1 / L471JP][Stopped/Manual Start]
  <\??\C:\WINDOWS\7VOMSZ2M.txt><N/A>

[78791 / L66G3AL][Stopped/Manual Start]
  <\??\C:\WINDOWS\ORS4YY52ZG.txt><N/A>

[5ADLK1BHN05Z / MOOQ6][Stopped/Manual Start]
  <\??\C:\WINDOWS\1YE5W.txt><N/A>

[Nessery / Nessery][Stopped/Manual Start]
  <\??\C:\WINDOWS\system32\Nessery.sys><N/A>

[2D76BV6Y942 / T8TYXAB][Stopped/Manual Start]
  <\??\C:\WINDOWS\K2XE5E5GRI2.txt><N/A>

[tdfgcz1 / tdfgcz16][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\tdfgcz16.sys><N/A>

[97Z1WK6W5AW / U5C65TP1DN][Stopped/Manual Start]
  <\??\C:\WINDOWS\IIH5YN6ZSJ.txt><N/A>

[LGE Mobile Composite USB Device / usbbus][Stopped/Manual Start]
  <system32\DRIVERS\lgusbbus.sys><N/A>

[LGE Mobile USB Modem / USBModem][Stopped/Manual Start]
  <system32\DRIVERS\lgusbmodem.sys><N/A>

[TWORA8V8Z4H / WILIGE][Stopped/Manual Start]
  <\??\C:\WINDOWS\LNEH8S2U90T.txt><N/A>

[KDPAXQAFP9IE / ZBQD8MET4][Stopped/Manual Start]
  <\??\C:\WINDOWS\94H1S.txt><N/A>

[BCZ8YR3G / ZC448ZMIZFYG][Stopped/Manual Start]
  <\??\C:\WINDOWS\1YPY1K.txt><N/A>
—————————————————————————————
在扫日志的SRENG工具》系统修复》浏览器加载项》里面找下面删除
==================================
浏览器加载项
[]
  {47AC9076-C898-B098-D098-A18319080974} <C:\WINDOWS\system32\nhmxdjkl.dll, N/A>

附件附件:

下载次数:212
文件类型:application/octet-stream
文件大小:
上传时间:2008-8-21 11:49:17
描述:rar

gototop
 

回复:drw.kills, 不停弹出系统错误,系统崩溃

断网操作

清理以及删除操作做完后

立即重启电脑,再扫日志来看

如果还有异常,请不要关机

就一直等着

我回家了

下午才能再来
gototop
 

回复 13F aaccbbdd 的帖子

raysat_3dsmax8server.exe\data001;c:\program files\autodesk\3dsmax8\mentalray\satellite\raysat_3dsmax8server.exe;Trojan.NtRootKit.318;;
raysat_3dsmax8server.exe\data002;c:\program files\autodesk\3dsmax8\mentalray\satellite\raysat_3dsmax8server.exe;BackDoor.Bifrost;;
raysat_3dsmax8server.exe;c:\program files\autodesk\3dsmax8\mentalray\satellite;发现压缩文件中有被感染的对象;已移动。;
adobelmsvc.exe\data001;c:\program files\common files\adobe systems shared\service\adobelmsvc.exe;Trojan.NtRootKit.318;;
adobelmsvc.exe\data002;c:\program files\common files\adobe systems shared\service\adobelmsvc.exe;BackDoor.Bifrost;;
adobelmsvc.exe;c:\program files\common files\adobe systems shared\service;发现压缩文件中有被感染的对象;已移动。;
adskscsrv.exe\data001;c:\program files\common files\autodesk shared\service\adskscsrv.exe;Trojan.NtRootKit.318;;
adskscsrv.exe\data002;c:\program files\common files\autodesk shared\service\adskscsrv.exe;BackDoor.Bifrost;;
adskscsrv.exe;c:\program files\common files\autodesk shared\service;发现压缩文件中有被感染的对象;已移动。;
qvodterminal.exe;c:\program files\qvodplayer;可能 DLOADER.Trojan;;
adsntzt.dll;c:\windows\system32;Trojan.PWS.Wsgame.6931;已删除。;
avicapwm.dll;c:\windows\system32;Trojan.PWS.Wsgame.6871;已删除。;
boboturbo.exe;c:\windows\system32\boboturbo;可能 DLOADER.Trojan;;
bootvidgj.dll;c:\windows\system32;Trojan.PWS.Wsgame.6889;已删除。;
cliconfgzx.dll;c:\windows\system32;Trojan.PWS.Wsgame.6317;已删除。;
bdguard.sys;c:\windows\system32\drivers;Adware.Borlander;;
gqjls.sys;c:\windows\system32\drivers;Adware.QQHelp;;
tdfgcz16.sys;c:\windows\system32\drivers;Trojan.NtRootKit.924;已删除。;
gdipro.dll;c:\windows\system32;Trojan.PWS.Wsgame.6875;已删除。;
imgutilhx2.dll;c:\windows\system32;BackDoor.Ahn.13;已删除。;
kqeea.dll;c:\windows\system32;Adware.QQHelp;;
lweurqhx.dll;c:\windows\system32;Trojan.PWS.Wsgame.6931;已删除。;
srpcss.dll;c:\windows\system32;Trojan.PWS.Wsgame.6875;已删除。;
sys07003.dll;c:\windows\system32;Trojan.PWS.Wsgame.6876;已删除。;
toolba.exe;c:\windows\system32;DDoS.Attack.19;已删除。;
tuxumyls.dll;c:\windows\system32;Trojan.PWS.Wsgame.6945;已删除。;
atjzq.dll;c:\windows\system32\wbem;Adware.QQHelp.origin;;
ybh7sz.dll;c:\windows\system32;可能 DLOADER.Trojan;;
gototop
 

回复 13F aaccbbdd 的帖子

qvodterminal.exe;c:\program files\qvodplayer;可能 DLOADER.Trojan;;
boboturbo.exe;c:\windows\system32\boboturbo;可能 DLOADER.Trojan;;
bdguard.sys;c:\windows\system32\drivers;Adware.Borlander;;
gqjls.sys;c:\windows\system32\drivers;Adware.QQHelp;;
kqeea.dll;c:\windows\system32;Adware.QQHelp;;
atjzq.dll;c:\windows\system32\wbem;Adware.QQHelp.origin;;
gototop
 
123456   2  /  6  页   跳转
页面顶部
Powered by Discuz!NT