Encountered sqmapi32.dll, kvmxfma. dll, rarjdpi. dll, Google. dll, a0b1. dll, etc.
EndurerOriginal
1Version
IE is not working normally after recruitment, the computer occasionally plays the advertisement window, and the recommended Firefox information appears at the top of any web page;
When the program is started, the svchost.exe error is reported, and cmd.exe, WinRAR, and so on cannot be run ...... When the security mode is enabled, a blue screen error occurs: Unknown hard error.
Pe_xscan 07-08-30 by Purple endurer
2007-11-6 16:54:44
Windows XP Service Pack 2 (5.1.2600)
Administrator user group
[System process] * 0
C:/Windows/system32/allatl. dll | 15:21:22
C:/Windows/system32/dh3atl. dll | 14:51:20
C:/Windows/system32/myatl. dll | 14:51:18
C:/Windows/system32/qqsgatl. dll | 14:51:10
C:/Windows/system32/wlatl. dll | 14:51:14, 2007-11-6
C:/Windows/system32/msatl. dll | 14:51:14, 2007-11-6
C:/Windows/system32/addrz_thelp.dll |
C:/Windows/system32/dhatl. dll | 14:51:12
C:/progra ~ 1/wqjm/jdwz. dll | stdstub | 5, 0, 1, 1 | stdstub | copyright 2005 | 5, 0, 1, 1 | stdstub |
C:/progra ~ 1/wqjm/oibe. dll | 2007-11-5 :32:6 | stdplay | 5, 0, 1, 1 | stdplay | copyright? 2006 | 5, 0, 1, 1 | stdvote | stdplay. dll
C:/Windows/explorer. EXE * 1436 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Windows Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Explorer | EXPLORER. EXE
C:/progra ~ 1/wqjm/jdwz. dll | stdstub | 5, 0, 1, 1 | stdstub | copyright 2005 | 5, 0, 1, 1 | stdstub |
C:/progra ~ 1/wqjm/oibe. dll | 2007-11-5 :32:6 | stdplay | 5, 0, 1, 1 | stdplay | copyright? 2006 | 5, 0, 1, 1 | stdvote | stdplay. dll
C:/Windows/system32/ravext. DLL | Rising Antivirus 2008 | 20.00 | rising shell ext module | rising Corp. all rights reserved. | 2.160.0.16 | Beijing rising Technology Co ., ltd. |? | Beijing rising Technology Co., Ltd. | ravext. dll
C:/Windows/system32/sqmapi32.dll | 15:21:22, 2007-11-6
C:/Windows/system32/qdshm. dll |
C:/Windows/system32/dhatl. dll | 14:51:12
C:/Windows/system32/addrz_thelp.dll |
C:/Windows/system32/msatl. dll | 14:51:14, 2007-11-6
C:/Windows/system32/wlatl. dll | 14:51:14, 2007-11-6
C:/Windows/system32/qqsgatl. dll | 14:51:10
C:/Windows/system32/myatl. dll | 14:51:18
C:/Windows/system32/dh3atl. dll | 14:51:20
C:/Windows/system32/allatl. dll | 15:21:22
C:/Windows/system32/ctfmon.exe * 1764 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | CTF loader |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Ctfmon. exe
C:/progra ~ 1/wqjm/jdwz. dll | stdstub | 5, 0, 1, 1 | stdstub | copyright 2005 | 5, 0, 1, 1 | stdstub |
C:/progra ~ 1/wqjm/oibe. dll | 2007-11-5 :32:6 | stdplay | 5, 0, 1, 1 | stdplay | copyright? 2006 | 5, 0, 1, 1 | stdvote | stdplay. dll
C:/Windows/system32/svchost.exe * 1820 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/progra ~ 1/wqjm/gatw. dll | ADDM | 5, 0, 1, 1 | ADDM | copyright? 2006 | 5, 0, 1, 1 | ADDM | addm.exe
C:/progra ~ 1/wqjm/jdwz. dll | stdstub | 5, 0, 1, 1 | stdstub | copyright 2005 | 5, 0, 1, 1 | stdstub |
C:/progra ~ 1/wqjm/oibe. dll | 2007-11-5 :32:6 | stdplay | 5, 0, 1, 1 | stdplay | copyright? 2006 | 5, 0, 1, 1 | stdvote | stdplay. dll
C:/progra ~ 1/wqjm/lfyb. dll | 2007-11-5 :32:6 | stdvote | 5, 0, 1, 1 | stdvote | copyright? 2006 | 5, 0, 1, 1 | stdvote. dll
C:/progra ~ 1/wqjm/cwps. dll | 2007-11-5 :32:6 | 5, 0, 1, 1 | stdseg | copyright? 2007 | 5, 0, 1, 1 | stdseg |
C:/Windows/system32/sqmapi32.dll | 15:21:22, 2007-11-6
C:/Windows/system32/svchost.exe * 1832 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/Windows/system32/conime. dll | PC inetinfo | 1, 0, 0, 1 | used to support the debugging of Windows network services. | (C) Microsoft Corporation. All Rights Reserved. | 1, 0, 0, 1 | Microsoft Corporation | UPnP | inetinfo. dll
C:/Windows/system32/0b911.exe * 1864 | 9:29:58 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | Windows progman group converter | copyright zhongsou (c) 2005 | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Maid |?
C:/Windows/system32/nvsvc32.exe * 124 | NVIDIA driver Helper Service, version 93.71 | 6.14.10.9371 | NVIDIA driver Helper Service, version 93.71 | (c) NVIDIA Corporation. all rights reserved. | 6.14.10.9371 | NVIDIA Corporation |? | Nvsvc | nvsvc32.exe
C:/progra ~ 1/wqjm/jdwz. dll | stdstub | 5, 0, 1, 1 | stdstub | copyright 2005 | 5, 0, 1, 1 | stdstub |
C:/progra ~ 1/wqjm/oibe. dll | 2007-11-5 :32:6 | stdplay | 5, 0, 1, 1 | stdplay | copyright? 2006 | 5, 0, 1, 1 | stdvote | stdplay. dll
C:/Windows/system32/winlogon.exe * 340 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | Windows NT logon application | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Winlogon. exe
C:/Windows/system32/sqmapi32.dll | 15:21:22, 2007-11-6
C:/Windows/system32/qdshm. dll |
C:/Windows/system32/svchost.exe * 352 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/progra ~ 1/wqjm/jdwz. dll | stdstub | 5, 0, 1, 1 | stdstub | copyright 2005 | 5, 0, 1, 1 | stdstub |
C:/progra ~ 1/wqjm/oibe. dll | 2007-11-5 :32:6 | stdplay | 5, 0, 1, 1 | stdplay | copyright? 2006 | 5, 0, 1, 1 | stdvote | stdplay. dll
C:/Windows/system32/sqmapi32.dll | 15:21:22, 2007-11-6
C:/Windows/system32/rundll32.exe * 2368 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | run a DLL as an app | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Rundll. exe
C:/Windows/system32/0A1. DLL | player dynamic link library | 1, 0, 0, 3 | player dynamic link library | copyright (c) 2006 | 1, 0, 0, 3 |? | Player. dll
C:/progra ~ 1/wqjm/jdwz. dll | stdstub | 5, 0, 1, 1 | stdstub | copyright 2005 | 5, 0, 1, 1 | stdstub |
C:/progra ~ 1/wqjm/oibe. dll | 2007-11-5 :32:6 | stdplay | 5, 0, 1, 1 | stdplay | copyright? 2006 | 5, 0, 1, 1 | stdvote | stdplay. dll
C:/program files/Internet Explorer/iw.e. EXE * 2260 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Internet Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Iexplore. exe
C:/progra ~ 1/wqjm/jdwz. dll | stdstub | 5, 0, 1, 1 | stdstub | copyright 2005 | 5, 0, 1, 1 | stdstub |
C:/progra ~ 1/wqjm/oibe. dll | 2007-11-5 :32:6 | stdplay | 5, 0, 1, 1 | stdplay | copyright? 2006 | 5, 0, 1, 1 | stdvote | stdplay. dll
C:/Windows/system32/a0b1. DLL | iehpr module | 1, 0, 0, 2 | iehpr module | Copyright 2007 | 1, 0, 0, 2 | iehpr. DLL
C:/Windows/system32/msurlpar. DLL | msurlpar module | 1, 0, 0, 1 | msurlpar module | Copyright 2007 | 1, 0, 0, 1 | statistics | msurlpar. DLL
C:/Windows/system32/gujxvpzjcsrlu. dll | 1.0.0.0 | 1.0.0.0 |
C:/Windows/iloveg ~ 1/Google. DLL | 8:11:38 | MICROSOFT module | 4, 0, 2,111 | MICROSOFT module | (c) Microsoft Corporation. all rights reserved. | 4, 0, 2,111 | Microsoft Corporation | MICROSOFT. DLL
C:/Windows/system32/dh3atl. dll | 14:51:20
C:/Windows/system32/myatl. dll | 14:51:18
C:/Windows/system32/qqsgatl. dll | 14:51:10
C:/Windows/system32/wlatl. dll | 14:51:14, 2007-11-6
C:/Windows/system32/msatl. dll | 14:51:14, 2007-11-6
C:/Windows/system32/addrz_thelp.dll |
C:/Windows/system32/dhatl. dll | 14:51:12
C:/Windows/system32/sqmapi32.dll | 15:21:22, 2007-11-6
C:/Windows/system32/allatl. dll | 15:21:22
C:/program files/xuebing speed-up/msdxm. OCX | 12:18:16 | DirectShow | 6.4.07.1119 | Windows Media Player 2 ActiveX control | copyright (c) 1992-1999 Microsoft Corp. | 6.4.07.1119 | Microsoft Corporation |? | Msdxm. ocx | msdxm. ocx
C:/Windows/system32/conime.exe * 1188 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | console IME |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Console | conime. exe
C:/progra ~ 1/wqjm/jdwz. dll | stdstub | 5, 0, 1, 1 | stdstub | copyright 2005 | 5, 0, 1, 1 | stdstub |
C:/progra ~ 1/wqjm/oibe. dll | 2007-11-5 :32:6 | stdplay | 5, 0, 1, 1 | stdplay | copyright? 2006 | 5, 0, 1, 1 | stdvote | stdplay. dll
C:/program files/rising/rav/ravmond.exe * 3444 | Rising Antivirus 2008 | 20.00 | rising realtime moniter | rising Corp. all rights reserved. | 2.160.0.59 | Beijing rising Technology Co ., ltd. |? | Beijing rising Technology Co., Ltd. | ravmond.exe
C:/progra ~ 1/wqjm/jdwz. dll | stdstub | 5, 0, 1, 1 | stdstub | copyright 2005 | 5, 0, 1, 1 | stdstub |
C:/progra ~ 1/wqjm/oibe. dll | 2007-11-5 :32:6 | stdplay | 5, 0, 1, 1 | stdplay | copyright? 2006 | 5, 0, 1, 1 | stdvote | stdplay. dll
C:/Windows/system32/sqmapi32.dll | 15:21:22, 2007-11-6
C:/program files/rising/rav/ravmon. EXE * 2548 | 9:53:40 | Rising Antivirus 2008 | 20.00 | rising realtime monitor shell | rising Corp. all rights reserved. | 2.160.0.98 | Beijing rising Technology Co ., ltd. |? | Beijing rising Technology Co., Ltd. | ravtray. exe
C:/Windows/system32/allatl. dll | 15:21:22
C:/Windows/system32/dh3atl. dll | 14:51:20
C:/Windows/system32/myatl. dll | 14:51:18
C:/Windows/system32/qqsgatl. dll | 14:51:10
C:/Windows/system32/wlatl. dll | 14:51:14, 2007-11-6
C:/Windows/system32/msatl. dll | 14:51:14, 2007-11-6
C:/Windows/system32/addrz_thelp.dll |
C:/Windows/system32/dhatl. dll | 14:51:12
C:/progra ~ 1/wqjm/jdwz. dll | stdstub | 5, 0, 1, 1 | stdstub | copyright 2005 | 5, 0, 1, 1 | stdstub |
C:/progra ~ 1/wqjm/oibe. dll | 2007-11-5 :32:6 | stdplay | 5, 0, 1, 1 | stdplay | copyright? 2006 | 5, 0, 1, 1 | stdvote | stdplay. dll
C:/program files/rising/rav/rsguilib. DLL | 9:53:16 | Rising Antivirus 2008 | 20, 0, 0, 0 | rising GUI library loader | rising Corp. all rights reserved. | 20, 0, 0, 79 | Beijing rising Technology Co ., ltd. |? | Beijing rising Technology Co., Ltd. | rsguilib. dll
D:/program files/rising/AntiSpyware/runiep.exe * 2404 | runiep application | 4.00 | rising AntiSpyware monitor | rising Corp. all rights reserved. | 4.0.0.18 | Beijing rising Technology Co ., ltd. | Beijing rising Technology Co ., ltd. | runiep.exe
C:/Windows/system32/allatl. dll | 15:21:22
C:/Windows/system32/dh3atl. dll | 14:51:20
C:/Windows/system32/myatl. dll | 14:51:18
C:/Windows/system32/qqsgatl. dll | 14:51:10
C:/Windows/system32/wlatl. dll | 14:51:14, 2007-11-6
C:/Windows/system32/msatl. dll | 14:51:14, 2007-11-6
C:/Windows/system32/addrz_thelp.dll |
C:/Windows/system32/dhatl. dll | 14:51:12
C:/progra ~ 1/wqjm/jdwz. dll | stdstub | 5, 0, 1, 1 | stdstub | copyright 2005 | 5, 0, 1, 1 | stdstub |
C:/progra ~ 1/wqjm/oibe. dll | 2007-11-5 :32:6 | stdplay | 5, 0, 1, 1 | stdplay | copyright? 2006 | 5, 0, 1, 1 | stdvote | stdplay. dll
O2-BHO invoke class-{3aa0903b-1e13-4865-b114-15792d413c41}-C:/Windows/system32/a0b1. dll
O2-BHO msurl class-{6cdd9d1f-7501-4b0f-90cd-5ada4f15e6e8}-C:/Windows/system32/msurlpar. dll
O2-BHO-{98836b5f-4e24-4207-952d-a5ea63c7a645}-C:/Windows/system32/gujxvpzjcsrlu. dll
O2-BHO Google class-{CE7C3CF0-4B15-11D1-ABED-709549C10531}-C:/Windows/iloveg ~ 1/Google. dll
O3-IE Toolbar: shortcut toolbar 3.1-{BE830FD4-E393-417F-9F4B-CC70ABB3384C}-C:/Windows/system32/ietool. dll
O3-IE Toolbar: popocytoolbar-{691afbc1-3c46-406d-ad22-eb3a0f665fc1}-C:/program files/hxnotify/popocybar. dll
O3-IE Toolbar:-{8e718888-423f-11d2-876e-00a0c9011667}-C:/program files/xuebing five-stroke speed-up/msdxm. ocx
O23-service: adprot (adprot)-C:/Windows/system32/Drivers/adprot. sys (system)
O23-service: bvor (Windows bvor runthem)-C:/Windows/system32/svchost.exe-K netsvcs-> C:/progra ~ 1/wqjm/gatw. dll | ADDM | 5, 0, 1, 1 | ADDM | copyright? 2006 | 5, 0, 1, 1 | ADDM | addm.exe (automatic)
O23-service: conime (conime)-C:/Windows/system32/svchost.exe-K netsvcs-> C:/Windows/system32/conime. DLL | PC inetinfo | 1, 0, 0, 1 | used to support debugging for Windows network services. | (C) Microsoft Corporation. All Rights Reserved. | 1, 0, 0, 1 | Microsoft Corporation | UPnP | inetinfo. dll (automatic)
O23-service: ms_2fax (ms_2fax)-C:/Windows/system32/0b911.exe | 9:29:58 | MICROSOFT (r) Windows (r) operating System | 5.1.2600.2180 | Windows progman group converter | copyright zhongsou (c) 2005 | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Maid |? (Automatic)
O23-service: Provisioning (shell logs and alerts)-C:/Windows/system32/drpcoev.exe | 10:50:14 (automatic)
O23-service: wuauserv (Automatic Updates)-C:/Windows/system32/Drivers/svchost.exe | 10:50:24 (automatic)
O24-shlexechook: [6]-{6d47b341-43df-4563-753f-345ffa3157d6} = C:/Windows/system32/kvmxfma. dll
O24-shlexechook: [4]-{4598ff45-da60-f48a-bc43-10ac47853d54} = C:/Windows/system32/rarjdpi. dll