瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【原创】新病毒WINSP00L.exe 是高手的才进来谢谢

12   1  /  2  页   跳转

【原创】新病毒WINSP00L.exe 是高手的才进来谢谢

【原创】新病毒WINSP00L.exe 是高手的才进来谢谢

WINSP00L.exe  0是伪装字母O
启动进程WINSP00L.exe
服务lanmanworkstation

安全模式下断网清理所有临时文件系统垃圾文件,进入WINDOWS/SYSTEM/杀掉WINSP00L.exe,再进注册表搜索所有WINSP00L.exe删掉整个项,重启后问题没有解决 进程中依然存在WINSP00L.exe服务依然有

日志如下请看:
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Corporation]
    <1MJPM1G9.l><; C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system\MSVIDE0.dll,Run>  [mcsoft]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <SoundMan><SOUNDMAN.EXE>  [(Verified)Realtek Semiconductor Corp.]
    <AGRSMMSG><AGRSMMSG.exe>  [(Verified)Agere Systems]
    <KTPWare><C:\Program Files\Elantech\ktp.exe>  [(Verified)ELANTECH Devices Corp.]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
    <BigDog303><C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)>  [N/A]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [(Verified)RealNetworks, Inc.]
    <ISUSScheduler><"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start>  [InstallShield Software Corporation]
    <vmTrayProcess><D:\VMware workststion\vmTrayProcess.exe>  [(Verified)VMware, Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}><C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll>  [Anti-Malware Development a.s.]

==================================
启动文件夹
N/A

==================================
服务
[Application Management / AppMgmt][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard][Running/Auto Start]
  <C:\Program Files\ewido anti-spyware 4.0\guard.exe><Anti-Malware Development a.s.>
[General Updater/AutoUpdater Service / GUA][Running/Auto Start]
  <"C:\Program Files\lenovo\GUA\GUA.exe"><lenovo>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[IGRS / IGRS][Running/Auto Start]
  <C:\Program Files\lenovo\IGRS\IGRS.exe><Lenovo Group Limited>
[IGRSFILE / IGRSFILE][Running/Auto Start]
  <C:\Program Files\lenovo\IGRS Profiles\File Profile\IgrsFile.exe><Lenovo Group Limited>
[IgrsFileShare / IgrsFileShare][Running/Auto Start]
  <"C:\Program Files\lenovo\IGRS EasyShare\FileShare.exe"><联想集团有限公司>
[IgrsMonitor / IgrsMonitor][Running/Auto Start]
  <"C:\Program Files\lenovo\IGRS\Ext\IgrsMonitor.exe"><Lenovo Group Limited>
[MicroGrid DirectRouter / MicroGrid.DirectRouter][Running/Auto Start]
  <C:\Program Files\lenovo\IGRS\Ext\router.exe><Lenovo Group Limited>
[P4P Service / P4P Service][Running/Auto Start]
  <C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[VMware Agent Service / ufad-p2v][Running/Auto Start]
  <"D:\VMware workststion\vmware-ufad.exe" -d "D:\VMware workststion\\" -s ufad-p2v.xml><VMware, Inc.>
[Visual Studio Analyzer RPC bridge / Visual Studio Analyzer RPC bridge][Stopped/Manual Start]
  <C:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\varpc.exe><Microsoft Corporation>
[VMware Authorization Service / VMAuthdService][Running/Auto Start]
  <D:\VMware workststion\vmware-authd.exe><VMware, Inc.>
[VMware DHCP Service / VMnetDHCP][Running/Auto Start]
  <C:\WINDOWS\system32\vmnetdhcp.exe><VMware, Inc.>
[VMware Virtual Mount Manager Extended / vmount2][Running/Auto Start]
  <"C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe"><VMware, Inc.>
[VMware NAT Service / VMware NAT Service][Running/Auto Start]
  <C:\WINDOWS\system32\vmnat.exe><VMware, Inc.>
[WMCSVC / WMCSVC][Running/Auto Start]
  <C:\Program Files\lenovo\IGRS\Ext\wmcsvc.exe><Lenovo Group Limited>
[W0RKSTATI0N / LANMANW0RKSTATI0N][Running/Auto Start]
  <C:\WINDOWS\system\WINSP00L.EXE><N/A>
==================================
驱动程序
[Agere Systems Soft Modem / AgereSoftModem][Running/Manual Start]
  <system32\DRIVERS\AGRSM.sys><Agere Systems>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[Atheros Wireless Network Adapter Service / AR5211][Stopped/Manual Start]
  <system32\DRIVERS\ar5211.sys><Atheros Communications, Inc.>
[EMSCR / EMSCR][Running/Manual Start]
  <system32\DRIVERS\EMS7SK.sys><ENE Technology Inc.>
[ESDCR / ESDCR][Running/Manual Start]
  <system32\DRIVERS\ESD7SK.sys><ENE Technology Inc.>
[ewido anti-spyware 4.0 driver / ewido anti-spyware 4.0 driver][Running/System Start]
  <\??\C:\Program Files\ewido anti-spyware 4.0\guard.sys><N/A>
[VMware hcmon / hcmon][Running/Auto Start]
  <\??\C:\WINDOWS\system32\Drivers\hcmon.sys><VMware, Inc.>
[ialm / ialm][Running/Manual Start]
  <system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[Elantech Touchpad / Ktp][Running/Manual Start]
  <system32\DRIVERS\Ktp.sys><ELANTECH Devices Corp.>
[npkcrypt / npkcrypt][Running/Auto Start]
  <\??\C:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  <system32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[vmfilter303 / vmfilter303][Stopped/Manual Start]
  <system32\drivers\vmfilter303.sys><Vimicro Corporation>
[VMware Virtual Ethernet Adapter Driver / VMnetAdapter][Running/Manual Start]
  <system32\DRIVERS\vmnetadapter.sys><VMware, Inc.>
[VMware Bridge Protocol / VMnetBridge][Running/Auto Start]
  <system32\DRIVERS\vmnetbridge.sys><VMware, Inc.>
[VMware Network Application Interface / VMnetuserif][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\vmnetuserif.sys><VMware, Inc.>
[VMware vmx86 / vmx86][Running/Auto Start]
  <\??\C:\WINDOWS\system32\Drivers\vmx86.sys><VMware, Inc.>
[Vstor2 Virtual Storage Driver / vstor2][Running/Auto Start]
  <\??\C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys><VMware, Inc.>
[Vstor2 P2V30 Virtual Storage Driver / vstor2-p2v30][Running/Auto Start]
  <\??\D:\VMware workststion\vstor2-p2v30.sys><VMware, Inc.>
[用于 Windows XP 的英特尔(R) PRO/无线 2200BG 网络连接驱动程序 / w29n51][Running/Manual Start]
  <system32\DRIVERS\w29n51.sys><Intel? Corporation>
[Intel(R) PRO/Wireless 7100 Adapter 驱动程序 / w70n51][Stopped/Manual Start]
  <system32\DRIVERS\w70n51.sys><Intel? Corporation>
[Wireless Monitor & Config Protocol Driver / WMCDRV][Running/Auto Start]
  <system32\DRIVERS\wmcdrv.sys><Lenovo Group Limited>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
  <system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[IVU USB PC Camera (Vimicro301 Neptune) / ZSMC303][Stopped/Manual Start]
  <System32\Drivers\usbVM303.sys><Vimicro Corporation>

==================================
最后编辑2007-02-17 09:56:54
分享到:
gototop
 


==================================
正在运行的进程
[PID: 796][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 864][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 888][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 932][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 944][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1104][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1148][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1796][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1848][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 428][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1020][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[PID: 1544][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\Program Files\lenovo\IGRS EasyShare\IgrsAnywhere.dll]  [Lenovo Group Limited, 1, 0, 2, 60]
    [E:\MPC\Codecs\mmfinfo.dll]  [N/A, N/A]
    [E:\MPC\Codecs\mkunicode.dll]  [N/A, N/A]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\WINDOWS\system32\igfxpph.dll]  [Intel Corporation, 3.0.0.4291]
    [C:\WINDOWS\system32\hccutils.DLL]  [Intel Corporation, 3.0.0.4291]
    [C:\WINDOWS\system32\igfxres.dll]  [Intel Corporation, 3.0.0.4291]
    [C:\WINDOWS\system32\igfxsrvc.dll]  [Intel Corporation, 3.0.0.4291]
    [C:\WINDOWS\system32\igfxdev.dll]  [Intel Corporation, 3.0.0.4291]
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.7.2006011200]
    [C:\WINDOWS\system32\hooridrb.dll]  [Microsoft Corporation, 1, 0, 0, 27]
    [C:\WINDOWS\system\C0MMDLG.DLL]  [adobe, 1.0.0.1]
    [C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll]  [Thunder Networking Technologies,LTD, 5, 0, 0, 3]
    [E:\360safe\safemon\safemon.dll]  [, 1, 0, 0, 1003]
    [C:\WINDOWS\system\PDFAid.dll]  [adobe system, 1.0.0.1]
    [C:\Program Files\Elantech\KtpDll.Dll]  [ELANTECH Devices Corp., 5.0.1.5]
    [C:\Program Files\Tencent\QQ\qdshm.dll]  [, 1, 0, 101, 20]
    [C:\Program Files\IDM Computer Solutions\UltraCompare\UC_ShellExt.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\Program Files\IDM Computer Solutions\UltraEdit-32\ue32ctmn.dll]  [, 1, 0, 0, 2]
    [C:\Program Files\lenovo\IGRS\Ext\IgrsMonitorPS.dll]  [N/A, N/A]
    [C:\Program Files\ewido anti-spyware 4.0\context.dll]  [Anti-Malware Development a.s., 4, 0, 0, 172]
    [C:\WINDOWS\system32\LgdGuard.dll]  [, ]
    [C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll]  [Anti-Malware Development a.s., 4, 0, 0, 172]
[PID: 1696][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.33]
[PID: 1704][C:\WINDOWS\AGRSMMSG.exe]  [Agere Systems, 2.1.49 2.1.49 12/20/2004 15:10:02]
[PID: 1712][C:\Program Files\Elantech\ktp.exe]  [ELANTECH Devices Corp., 5, 0, 1, 5]
    [C:\Program Files\Elantech\KtpXPdll.dll]  [ELANTECH Devices Corp., 5, 0, 0, 0]
    [C:\Program Files\Elantech\KtpDll.Dll]  [ELANTECH Devices Corp., 5.0.1.5]
    [C:\Program Files\Elantech\ELANDLL.Dll]  [ELANTECH Devices Corp., 5.0.0.0]
[PID: 1728][C:\WINDOWS\VM303_STI.EXE]  [Vimicro, 3, 6, 227, 13]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
[PID: 1736][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  [RealNetworks, Inc., 0.1.0.3760]
[PID: 1744][C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe]  [InstallShield Software Corporation, 3, 00, 100, 1161]
[PID: 1768][D:\VMware workststion\vmTrayProcess.exe]  [VMware, Inc., e.x.p build-36983]
    [D:\VMware workststion\VIX.DLL]  [VMware, Inc., e.x.p build-36983]
    [D:\VMware workststion\sigc-2.0.dll]  [The libsigc++ development team (see AUTHORS), 2.0.17]
    [D:\VMware workststion\libeay32.dll]  [N/A, N/A]
    [D:\VMware workststion\ssleay32.dll]  [N/A, N/A]
    [D:\VMware workststion\vmnetMgr.dll]  [VMware, Inc., e.x.p build-36983]
    [D:\VMware workststion\vmapplib.DLL]  [VMware, Inc., e.x.p build-36983]
    [D:\VMware workststion\VNETLIB.dll]  [VMware, Inc., e.x.p build-36983]
[PID: 1824][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 612][C:\Program Files\ewido anti-spyware 4.0\guard.exe]  [Anti-Malware Development a.s., 4, 0, 0, 172]
    [C:\Program Files\ewido anti-spyware 4.0\engine.dll]  [Anti-Malware Development a.s., 4, 0, 0, 172]
[PID: 632][C:\Program Files\lenovo\GUA\GUA.exe]  [lenovo, 1.0.0.19]
[PID: 656][C:\Program Files\lenovo\IGRS\IGRS.exe]  [Lenovo Group Limited, 1.0.0.174]
    [C:\Program Files\lenovo\IGRS\framework.dll]  [Lenovo Group Limited, 1.0.0.174]
    [C:\Program Files\lenovo\IGRS\ReliablePlugin.dll]  [Lenovo Group Limited, 1.0.0.174]
    [C:\WINDOWS\system32\WMCAPI.dll]  [Lenovo Group Limited, 2, 0, 2, 19]
    [C:\WINDOWS\system32\wmcdrv.dll]  [Lenovo Group Limited, 3, 1, 0, 10]
    [C:\WINDOWS\system32\wmcinst.dll]  [Lenovo Group Limited, 2, 0, 1, 3]
    [C:\Program Files\lenovo\IGRS\CorePlugin.dll]  [Lenovo Group Limited, 1.0.0.174]
    [C:\Program Files\lenovo\IGRS\SocketPlugin.dll]  [Lenovo Group Limited, 1.0.0.174]
    [C:\Program Files\lenovo\IGRS\BTComPlugin.dll]  [Lenovo Group Limited, 1.0.0.174]
    [C:\Program Files\lenovo\IGRS\SerialPortMonitor.dll]  [lenovo, 1, 0, 1, 19]
    [C:\Program Files\lenovo\IGRS\ProxyPlugin.dll]  [Lenovo Group Limited, 1.0.0.174]
    [C:\Program Files\lenovo\IGRS\LoggingPlugin.dll]  [Lenovo Group Limited, 1.0.0.174]
    [C:\Program Files\lenovo\IGRS\DebugPlugin.dll]  [Lenovo Group Limited, 1.0.0.174]
[PID: 696][C:\Program Files\lenovo\IGRS\Ext\IgrsMonitor.exe]  [Lenovo Group Limited, 1, 0, 1, 13]
    [C:\WINDOWS\system32\IgrsApi.dll]  [Lenovo Group Limited, 1.0.0.174]
    [C:\WINDOWS\system32\WMCAPI.dll]  [Lenovo Group Limited, 2, 0, 2, 19]
    [C:\WINDOWS\system32\wmcdrv.dll]  [Lenovo Group Limited, 3, 1, 0, 10]
    [C:\WINDOWS\system32\wmcinst.dll]  [Lenovo Group Limited, 2, 0, 1, 3]
    [C:\Program Files\lenovo\IGRS\Ext\IgrsMonitorPS.dll]  [N/A, N/A]
[PID: 772][C:\Program Files\lenovo\IGRS\Ext\router.exe]  [Lenovo Group Limited, 1, 3, 0, 12]
    [C:\WINDOWS\system32\WMCAPI.DLL]  [Lenovo Group Limited, 2, 0, 2, 19]
    [C:\WINDOWS\system32\wmcdrv.dll]  [Lenovo Group Limited, 3, 1, 0, 10]
    [C:\WINDOWS\system32\wmcinst.dll]  [Lenovo Group Limited, 2, 0, 1, 3]
[PID: 1896][C:\WINDOWS\system32\rundll32.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
gototop
 

[C:\WINDOWS\system\MSVIDE0.dll]  [mcsoft, 1, 0, 0, 0]
[PID: 1832][C:\Program Files\Common Files\Sogou PXP\p2psvr.exe]  [Sohu.com Inc., 2, 0, 0, 27]
[PID: 1780][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1980][D:\VMware workststion\vmware-ufad.exe]  [VMware, Inc., e.x.p build-36835]
    [D:\VMware workststion\vmacore.dll]  [VMware, Inc., 1.0]
    [D:\VMware workststion\LIBEAY32.dll]  [N/A, N/A]
    [D:\VMware workststion\SSLEAY32.dll]  [N/A, N/A]
    [D:\VMware workststion\vmomi.dll]  [VMware, Inc., 1.0]
    [D:\VMware workststion\ufa-common.dll]  [VMware, Inc., e.x.p build-36835]
    [D:\VMware workststion\types.dll]  [N/A, N/A]
    [D:\VMware workststion\ufa-types.dll]  [N/A, N/A]
    [D:\VMware workststion\ufa-agent.dll]  [N/A, N/A]
    [D:\VMware workststion\ufa-vmsvc.dll]  [N/A, N/A]
    [D:\VMware workststion\ufa-client.dll]  [N/A, N/A]
    [D:\VMware workststion\ufa-slave.dll]  [N/A, N/A]
    [D:\VMware workststion\ufa-sysMigration.dll]  [N/A, N/A]
    [D:\VMware workststion\ufa-sysReconfig.dll]  [N/A, N/A]
    [D:\VMware workststion\mspack.dll]  [N/A, N/A]
    [D:\VMware workststion\ufa-vmImporter.dll]  [N/A, N/A]
    [D:\VMware workststion\deployPkg.dll]  [VMware, Inc., 4.0.0 build-34969]
    [D:\VMware workststion\vssSnapXP.dll]  [VMware, Inc., e.x.p build-36835]
[PID: 1284][D:\VMware workststion\vmware-authd.exe]  [VMware, Inc., e.x.p build-36983]
    [D:\VMware workststion\SSLEAY32.dll]  [N/A, N/A]
    [D:\VMware workststion\LIBEAY32.dll]  [N/A, N/A]
[PID: 1336][C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe]  [VMware, Inc., e.x.p build-36983]
    [C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmxScsiLib.dll]  [VMware, Inc., e.x.p build-36983]
    [C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\SSLEAY32.dll]  [N/A, N/A]
    [C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\LIBEAY32.dll]  [N/A, N/A]
[PID: 1368][C:\WINDOWS\system32\vmnat.exe]  [VMware, Inc., e.x.p build-36983]
[PID: 1412][C:\Program Files\lenovo\IGRS\Ext\wmcsvc.exe]  [Lenovo Group Limited, 2, 0, 2, 17]
    [C:\WINDOWS\system32\wmcdrv.dll]  [Lenovo Group Limited, 3, 1, 0, 10]
    [C:\WINDOWS\system32\wmcinst.dll]  [Lenovo Group Limited, 2, 0, 1, 3]
[PID: 2032][C:\Program Files\lenovo\IGRS Profiles\File Profile\IgrsFile.exe]  [Lenovo Group Limited, 1, 0, 0, 4]
    [C:\WINDOWS\system32\IgrsApi.dll]  [Lenovo Group Limited, 1.0.0.174]
    [C:\Program Files\lenovo\IGRS Profiles\File Profile\Util.dll]  [N/A, 1, 0, 1, 1]
    [C:\Program Files\lenovo\IGRS Profiles\File Profile\FrameWork.dll]  [Lenovo, 1, 0, 1, 1]
    [C:\Program Files\lenovo\IGRS Profiles\File Profile\FileProfileModule.dll]  [Lenovo Group Limited, 2, 0, 2, 35]
    [C:\Program Files\lenovo\IGRS Profiles\File Profile\BFileDialog.dll]  [Lenovo Group Limited, 2, 0, 1, 32]
[PID: 2220][C:\WINDOWS\system32\vmnetdhcp.exe]  [VMware, Inc., e.x.p build-36983]
[PID: 2316][C:\Program Files\lenovo\IGRS EasyShare\FileShare.exe]  [联想集团有限公司, 1, 0, 2, 23]
    [C:\Program Files\lenovo\IGRS EasyShare\IGRSAVSDK.dll]  [联想集团有限公司, 1, 0, 1, 50204]
    [C:\WINDOWS\system32\IgrsApi.dll]  [Lenovo Group Limited, 1.0.0.174]
    [C:\Program Files\lenovo\IGRS EasyShare\QuickDB.dll]  [N/A, N/A]
[PID: 3116][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3372][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 1420][E:\Maxthon\Maxthon.exe]  [Maxthon International Ltd., 1, 5, 9, 30]
    [E:\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
    [C:\Program Files\lenovo\IGRS EasyShare\IgrsAnywhere.dll]  [Lenovo Group Limited, 1, 0, 2, 60]
    [D:\VMware workststion\vmPerfmon.dll]  [VMware, Inc., e.x.p build-36983]
    [D:\VMware workststion\LIBEAY32.dll]  [N/A, N/A]
    [D:\VMware workststion\SSLEAY32.dll]  [N/A, N/A]
    [E:\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [C:\Program Files\Elantech\KtpDll.Dll]  [ELANTECH Devices Corp., 5.0.1.5]
    [C:\WINDOWS\system32\ac3filter.ax]  [, 0.70b]
    [E:\MPC\Codecs\ffdshow.ax]  [N/A, 1.0.2.1997]
    [C:\WINDOWS\system32\mlcom.ax]  [Moonlight Cordless Ltd., 1.00]
    [E:\MPC\Codecs\vsfilter.dll]  [Gabest, 1, 0, 1, 3]
[PID: 1924][C:\Program Files\Tencent\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [C:\Program Files\Tencent\QQ\CoralAssist.DLL]  [Coral Team, 4.5.0 build 20060515]
    [C:\Program Files\Tencent\QQ\CoralQQ.DLL]  [Coral Team, 4.5.1 Build 20060620]
    [C:\Program Files\Tencent\QQ\ipsearcher.dll]  [N/A, 1.0.0.4]
    [C:\Program Files\Tencent\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 160]
    [C:\Program Files\Tencent\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [C:\Program Files\Tencent\QQ\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 3, 2, 1]
    [C:\Program Files\Tencent\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [C:\Program Files\Tencent\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQMainFrame.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\CQQApplication.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Elantech\KtpDll.Dll]  [ELANTECH Devices Corp., 5.0.1.5]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\GroupLive.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [C:\Program Files\Tencent\QQ\QQPlugin.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\QQAllInOne.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\SCCore.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\QQCustomFace.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\QQSettingCtrl.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\Program Files\Tencent\QQ\QQAvatar.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\QRingMng.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [C:\Program Files\Tencent\QQ\QQPet.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\BQQApplication.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [C:\Program Files\Tencent\QQ\QQSceneMng.dll]  [N/A, N/A]
    [C:\Program Files\Tencent\QQ\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [C:\Program Files\Tencent\QQ\GroupConnection.dll]  [Tencent, 5, 0, 202, 170]
    [C:\Program Files\Tencent\QQ\CommercesMng.dll]  [, 1, 0, 0, 1]
    [C:\Program Files\Tencent\QQ\QQUdpGetFileLib.dll]  [tencent, 0, 2, 2, 3]
    [C:\Program Files\Tencent\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 200]
    [C:\Program Files\Tencent\QQ\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 5, 50]
[PID: 1248][C:\Program Files\Tencent\QQ\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [C:\Program Files\Tencent\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 3900][C:\WINDOWS\system\WINSP00L.EXE]  [N/A, N/A]
[PID: 444][C:\WINDOWS\system32\wuauclt.exe]  [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[PID: 3824][E:\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
gototop
 

没人看 自己顶一下下哈
gototop
 

晕呼,,我来顶哈
gototop
 

[W0RKSTATI0N / LANMANW0RKSTATI0N][Running/Auto Start]
<C:\WINDOWS\system\WINSP00L.EXE><N/A
gototop
 

掉了我再顶起来
gototop
 

谁有解决办法啊 我自己再顶
gototop
 

再顶一次哈!
gototop
 

用SREng删除服务,重启后删除文件:[W0RKSTATI0N / LANMANW0RKSTATI0N][Running/Auto Start]
<C:\WINDOWS\system\WINSP00L.EXE><N/A>


其它结束进程的方法你都会:[PID: 3900][C:\WINDOWS\system\WINSP00L.EXE] [N/A, N/A]
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT