In the event of vchelp.exe, videodevice.dll, swchost.exe, I %e32.sys, etc. 1
EndurerOriginal
1Version
When a netizen's computer enters the desktop, an error occurs, such as svchost.exe and d401ab94. EXE. Use one-click recovery to recover the C drive, which is invalid. Please try again.
Download the pe_xscan scan log and analyze it. The following suspicious items are found:
/=
Pe_xscan 07-08-30 by Purple endurer
Windows XP Service Pack 2 (5.1.2600)
Administrator user group
[System process] * 0
C:/Windows/system32/gdjzi32.dll | 19:42:52, 2005-11-21
C:/Windows/system32/gdwdi32.dll | 19:40:52, 2005-11-21
C:/Windows/system32/gdwli32.dll | 19:41:44, 2005-11-21
C:/Windows/system32/gdzxi32.dll | 19:41:18, 2005-11-21
C:/Windows/system32/gdm1_2.dll | 19:41:16
C:/Windows/system32/gdzhtui32.dll | 19:40:42, 2005-11-21
C:/program files/Internet Explorer/plugins/nvsys74.sys | 2000-10-22 0:30:14
C:/program files/Internet Explorer/plugins/ninsys74.sys | 2000-10-22 0:29:56
C:/Windows/system32/gwhqiotagms. dll | 2000-10-22
C:/program files/Internet Explorer/iw.e32.dat | 19:46:34
C:/program files/Internet Explorer/iw.e32.sys | 19:46:56
C:/Windows/system32/zhjtrx. dll |
C:/Windows/system32/winlogon.exe * 500 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | Windows NT logon application | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Winlogon. exe
C:/Windows/system32/winlib. dll
C:/Windows/system32/videodevice. dll | 19:42:50
C:/Windows/system32/services.exe * 544 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | services and controller app | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Services.exe
C:/Windows/system32/lymangr. dll |
C:/Windows/system32/svchost.exe * 824 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | generic host process for Win32 services |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Svchost.exe
C:/Windows/INF/wnlyuhkh. dll | 2000-10-22 0:21:30
C:/Windows/system32/videodevice. dll | 19:42:50
C:/Windows/explorer.exe * 1212 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Windows Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Explorer | EXPLORER. EXE
C:/program files/Internet Explorer/plugins/newtemp. dll | 2000-10-22 0:29:34
C:/Windows/system32/gwhqiotagms. dll | 2000-10-22
C:/program files/Internet Explorer/plugins/ninsys74.sys | 2000-10-22 0:29:56
C:/Windows/system32/zhjtrx. dll |
C:/program files/Internet Explorer/plugins/nvsys74.sys | 2000-10-22 0:30:14
C:/program files/Internet Explorer/iw.e32.sys | 19:46:56
C:/program files/Internet Explorer/iw.e32.dat | 19:46:34
C:/program files/Internet Explorer/iw.e32.win | 19:46:46
C:/Windows/system32/iczqb. dll
C:/Windows/system32/hhhqcz46.dll |
C:/Windows/system32/vcshow. dll | 1.0.0.0 | 1.1.1.435 |
C:/Windows/system32/jfwjoo56.dll | 11:30:10 | 1, 1, 1, 1036 | c | 1, 1, 1, 1051 |
C:/Windows/system32/videodevice. dll | 19:42:50
C:/Windows/system32/gdzhtui32.dll | 19:40:42, 2005-11-21
C:/Windows/system32/gdm1_2.dll | 19:41:16
C:/Windows/system32/gdwli32.dll | 19:41:44, 2005-11-21
C:/Windows/system32/gdzxi32.dll | 19:41:18, 2005-11-21
C:/Windows/system32/gdwdi32.dll | 19:40:52, 2005-11-21
C:/Windows/system32/gdjzi32.dll | 19:42:52, 2005-11-21
C:/docume ~ 1/admini ~ 1/locals ~ 1/temp/wncktngc. dll |
C:/Windows/system32/rundll32.exe * 1504 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | run a DLL as an app | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Rundll. exe
C:/Windows/system32/winsys16_071021.dll | 0:17:20, 2000-10-22
C:/program files/Internet Explorer/plugins/nvsys74.sys | 2000-10-22 0:30:14
C:/program files/Internet Explorer/plugins/ninsys74.sys | 2000-10-22 0:29:56
C:/Windows/system32/gwhqiotagms. dll | 2000-10-22
C:/program files/Internet Explorer/iw.e32.dat | 19:46:34
C:/program files/Internet Explorer/iw.e32.sys | 19:46:56
C:/Windows/system32/zhjtrx. dll |
C:/Windows/system32/ctfmon.exe * 1820 | MICROSOFT? Windows? Operating System | 5.1.2600.2180 | CTF loader |? Microsoft Corporation. All Rights Reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Ctfmon. exe
C:/program files/Internet Explorer/plugins/nvsys74.sys | 2000-10-22 0:30:14
C:/program files/Internet Explorer/plugins/ninsys74.sys | 2000-10-22 0:29:56
C:/Windows/system32/gwhqiotagms. dll | 2000-10-22
C:/program files/Internet Explorer/iw.e32.dat | 19:46:34
C:/program files/Internet Explorer/iw.e32.sys | 19:46:56
C:/Windows/system32/zhjtrx. dll |
C:/Windows/system32/gdjzi32.dll | 19:42:52, 2005-11-21
C:/Windows/system32/gdwdi32.dll | 19:40:52, 2005-11-21
C:/Windows/system32/gdwli32.dll | 19:41:44, 2005-11-21
C:/Windows/system32/gdzxi32.dll | 19:41:18, 2005-11-21
C:/Windows/system32/gdm1_2.dll | 19:41:16
C:/Windows/system32/gdzhtui32.dll | 19:40:42, 2005-11-21
C:/program files/Internet Explorer/iexplore.exe * 1924 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Internet Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Iexplore. exe
C:/Windows/system32/winsys32_071021.dll |
C:/program files/Internet Explorer/plugins/nvsys74.sys | 2000-10-22 0:30:14
C:/program files/Internet Explorer/plugins/ninsys74.sys | 2000-10-22 0:29:56
C:/Windows/system32/gwhqiotagms. dll | 2000-10-22
C:/Windows/system32/videodevice. dll | 19:42:50
C:/Windows/system32/gdjzi32.dll | 19:42:52, 2005-11-21
C:/Windows/system32/gdwdi32.dll | 19:40:52, 2005-11-21
C:/Windows/system32/gdwli32.dll | 19:41:44, 2005-11-21
C:/Windows/system32/gdzxi32.dll | 19:41:18, 2005-11-21
C:/Windows/system32/gdm1_2.dll | 19:41:16
C:/Windows/system32/gdzhtui32.dll | 19:40:42, 2005-11-21
C:/Windows/system32/wuauclt.exe * 2856 | 19:19:16 | MICROSOFT? Windows? Operating System | 7.0.6000.381 | Windows Update Automatic Updates |? Microsoft Corporation. All Rights Reserved. | 7.0.6000.381 (winmain (wmbla). 070730-1740) | Microsoft Corporation |? | Wuauclt.exe
C:/Windows/system32/gdjzi32.dll | 19:42:52, 2005-11-21
C:/Windows/system32/gdwdi32.dll | 19:40:52, 2005-11-21
C:/Windows/system32/gdwli32.dll | 19:41:44, 2005-11-21
C:/Windows/system32/gdzxi32.dll | 19:41:18, 2005-11-21
C:/Windows/system32/gdm1_2.dll | 19:41:16
C:/Windows/system32/gdzhtui32.dll | 19:40:42, 2005-11-21
C:/program files/Internet Explorer/plugins/nvsys74.sys | 2000-10-22 0:30:14
C:/program files/Internet Explorer/plugins/ninsys74.sys | 2000-10-22 0:29:56
C:/Windows/system32/gwhqiotagms. dll | 2000-10-22
C:/program files/Internet Explorer/iw.e32.dat | 19:46:34
C:/program files/Internet Explorer/iw.e32.sys | 19:46:56
C:/Windows/system32/zhjtrx. dll |
C:/Windows/system32/INF/svchost.exe * 3336 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | run a DLL as an app | (c) microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Rundll. exe
C:/Windows/system32/lwisys16_071113.dll |
C:/Windows/system32/gdjzi32.dll | 19:42:52, 2005-11-21
C:/Windows/system32/gdwdi32.dll | 19:40:52, 2005-11-21
C:/Windows/system32/gdwli32.dll | 19:41:44, 2005-11-21
C:/Windows/system32/gdzxi32.dll | 19:41:18, 2005-11-21
C:/Windows/system32/gdm1_2.dll | 19:41:16
C:/Windows/system32/gdzhtui32.dll | 19:40:42, 2005-11-21
C:/program files/Internet Explorer/plugins/nvsys74.sys | 2000-10-22 0:30:14
C:/program files/Internet Explorer/plugins/ninsys74.sys | 2000-10-22 0:29:56
C:/Windows/system32/gwhqiotagms. dll | 2000-10-22
C:/program files/Internet Explorer/iexplore.exe * 3748 | MICROSOFT (r) Windows (r) Operating System | 6.00.2900.2180 | Internet Explorer | (c) Microsoft Corporation. all rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation |? | Iexplore. exe
C:/Windows/system32/mwisys32_071113.dll |
C:/Windows/system32/gdjzi32.dll | 19:42:52, 2005-11-21
C:/Windows/system32/gdwdi32.dll | 19:40:52, 2005-11-21
C:/Windows/system32/gdwli32.dll | 19:41:44, 2005-11-21
C:/Windows/system32/gdzxi32.dll | 19:41:18, 2005-11-21
C:/Windows/system32/gdm1_2.dll | 19:41:16
C:/Windows/system32/gdzhtui32.dll | 19:40:42, 2005-11-21
C:/program files/Internet Explorer/plugins/nvsys74.sys | 2000-10-22 0:30:14
C:/program files/Internet Explorer/plugins/ninsys74.sys | 2000-10-22 0:29:56
C:/Windows/system32/gwhqiotagms. dll | 2000-10-22
C:/Windows/system32/videodevice. dll | 19:42:50
C:/program files/Internet Explorer/plugins/newtemp. dll | 2000-10-22 0:29:34
C:/Windows/system32/zhjtrx. dll |
C:/program files/Internet Explorer/iw.e32.sys | 19:46:56
C:/program files/Internet Explorer/iw.e32.dat | 19:46:34
C:/program files/Internet Explorer/iw.e32.win | 19:46:46
C:/Windows/system32/0734/svchost.exe * 3632 | 2000-10-22 0:21:30
C:/Windows/system32/gdjzi32.dll | 19:42:52, 2005-11-21
C:/Windows/system32/gdwdi32.dll | 19:40:52, 2005-11-21
C:/Windows/system32/gdwli32.dll | 19:41:44, 2005-11-21
C:/Windows/system32/gdzxi32.dll | 19:41:18, 2005-11-21
C:/Windows/system32/gdm1_2.dll | 19:41:16
C:/Windows/system32/gdzhtui32.dll | 19:40:42, 2005-11-21
C:/program files/Internet Explorer/plugins/nvsys74.sys | 2000-10-22 0:30:14
C:/program files/Internet Explorer/plugins/ninsys74.sys | 2000-10-22 0:29:56
C:/Windows/system32/gwhqiotagms. dll | 2000-10-22
C:/Windows/system32/videodevice. dll | 19:42:50
C:/program files/Internet Explorer/iw.e32.dat | 19:46:34
C:/program files/Internet Explorer/iw.e32.sys | 19:46:56
C:/Windows/system32/zhjtrx. dll |
F2-rshell = <assumer.exe vchelp.exe>
O2-BHO cadlogic object-{11f09afd-75ad-4e51-ab43-e09e9351ce16}-C:/program files/common files/cpush/cpush0.dll
O2-BHO ieaux class-{7605cc7c-00fd-4a5f-bafd-828342de6279}-C:/progra ~ 1/ocins/ieaux. dll
O2-BHO wzcnbho class-{D500885E-E400-41CA-804B-CD6373A7EEF2}-C:/program files/wzcn/cn_ie_wzcn.dll
O4-HKLM/../run: [winsysw] C:/Windows/swchost.exe
O4-HKLM/../run: [winsysm] C:/Windows/igm.exe
O4-HKLM/../run: [winform] C:/Windows/winform.exe
O4-HKLM/../run: [upxdnd] C:/Windows/upxdnd.exe
O4-HKLM/../run: [Switch] C:/Windows/system32/automatically replace .exe
O4-HKLM/../run: [svchost] C:/Windows/svchost.exe
O4-HKLM/../run: [smctrldrv] D;] xjoepxt] tztufn43] svoemm43/fyf! D;] xjoepxt] tztufn43] deoqsi/emm! Tubsu
O4-HKLM/../run: [quicknews] "C:/Windows/system32/WBEM/kryemtzgovbiqwc. EXE"
O4-HKLM/../run: [nvdispdrv] C:/Windows/lyngig.exe
O4-HKLM/../run: [msimms32] C:/Windows/msimms32.exe
O4-HKLM/../run: [kvsc3] C:/Windows/kvsc3.exe
O4-HKLM/../run: [kVp] C:/Windows/system32/Drivers/svchost.exe
O4-HKLM/../run: [jfwjoo56] % SystemRoot %/system32/rundll32.exe "% SystemRoot %/system32/jfwjoo56.dll", dllcanunloadnow
O4-HKLM/../run: [genprotect] C:/Windows/genprotect. exe
O4-HKLM/../run: [cmdbcs] C:/Windows/cmdbcs.exe
O4-HKLM/../run: [avpsrv] C:/Windows/avpsrv.exe
O4-HKLM/../policies/Explorer/run: [msdeg32] lyloader.exe
O4-HKLM/../policies/Explorer/run: [msdwg32] lyloadbr.exe
O4-HKLM/../policies/Explorer/run: [msdcg32] lyleador.exe
O4-HKLM/../policies/Explorer/run: [msdog32] lyloador.exe
O4-HKLM/../policies/Explorer/run: [msdsg32] lyloadar.exe
O4-HKLM/../policies/Explorer/run: [msdmg32] lyloadmr.exe
O4-HKLM/../policies/Explorer/run: [msdhg32] lyloadhr.exe
O4-HKLM/../policies/Explorer/run: [msdqg32] lyloadqr.exe
O4-HKLM/../policies/Explorer/run: [userinit] rundll32.exe C:/Windows/system32/winsys16_071021.dll start
C:/autorun. inf
/-----
[Autorun]
Open = pegefile. pif
ShellExecute = pegefile. pif
Shell/auto/command = pegefile. pif
Shell = auto
-----/
D:/autorun. inf
/-----
[Autorun]
Open = pegefile. pif
ShellExecute = pegefile. pif
Shell/auto/command = pegefile. pif
Shell = auto
-----/
E:/autorun. inf
/-----
[Autorun]
Open = pegefile. pif
ShellExecute = pegefile. pif
Shell/auto/command = pegefile. pif
Shell = auto
-----/
F:/autorun. inf
/-----
[Autorun]
Open = pegefile. pif
ShellExecute = pegefile. pif
Shell/auto/command = pegefile. pif
Shell = auto
-----/
O8-ie shortcut menu additional items: & access general website-C:/program files/ocins/cnrbtn.html
O9-IE Toolbar extension button HKLM: Chinese Internet-{B012491E-8FA4-4851-AA9B-22E33784FBAD}-C:/program files/ocins/config.exe
O9-ie tool menu extension item HKLM: Chinese Internet-{B012491E-8FA4-4851-AA9B-22E33784FBAD}-C:/program files/ocins/config.exe
O10-unknown LSP: C:/Windows/system32/videodevice. dll
O23-service: 100133 (100133)-system32/Drivers/100133.sys( disabled)
O23-service: 219829da (219829da)-C:/Windows/system32/d401ab94. exe-G | 19:47:44 |? |? |? |? |? | Microsoft Corporation |? |? |? (Automatic)
O23-service: cnprov (cnprov)-system32/Drivers/cnprov. sys | official Chinese Version | 2, 6, 0, 0 | auxiliary international domain name module | copyright (c ). all rights reserved. | 2.6.0.0 | China Internet Network Information Center (CNNIC) |? | Cnprov. sys | cnprov. sys (pilot)
O23-service: cnsminkp (cnsminkp)-system32/Drivers/cnsminkp. sys | KMD | 2.0.5.1001 | KMD | copyright (c) 3721 Corporation. | 2.0.5.1001 | copyright (c) 3721 Corporation. |? | Cnsminkp. sys | cnsminkp. sys (pilot)
O23-service: hhhqcz46 (hhhqcz46)-system32/Drivers/hhhqcz46.sys (pilot)
O23-service: idnaux (idnaux)-system32/Drivers/idnaux. sys | CNNIC idnaux | 2, 6, 0, 0 | international domain name support module | copyright? 2005 | 2, 6, 0, 0 | China Internet Network Information Center (CNNIC) | idnaux. sys (automatic)
O23-service: iqxemtahowc (Automated)-C:/Windows/system32/svchost.exe-K aipyfnub-> C:/Windows/system32/WBEM/jqyentzfmsyekq. dll | 2000-10-22 0:19:22 (automatic)
O23-service: jfwjoo56 (jfwjoo56)-system32/Drivers/jfwjoo56.sys (pilot)
O23-service: q5j6iyhhw (q5j6iyhhw)-C:/Windows/system32/Drivers/q5j6iyhhw. sys | (automatic)
O23-service: servicevchelp (servicevchelp)-C:/Windows/system32/vcplay.exe | 1.0.0.0 | 1.0.0.5 | (disabled)
O23-service: svchost (svchost)-C:/Windows/system32/dllcache/svchost.exe-G | 19:40:58 | MICROSOFT (r) Windows (r) Operating System |? |? | (C) Microsoft Corporation. All Rights Reserved. |? | Microsoft Corporation |? |? |? (Automatic)
O23-service: w32time (Windows Time)-C:/Windows/system32/svchost.exe-K netsvcs-> C:/Windows/INF/wnlyuhkh. dll | 0:21:30 (automatic)
O23-service: wdswsdewn (telephotsgoogle)-C:/Windows/system32/serdst.exe | 0:29:18 (automatic)
O23-service: zefdcx (zefdcx)-system32/Drivers/zefdcx. sys (pilot)
O24-shlexechook: []-{0ea66ad2-cf26-2e23-532b-b292e22f3266} = C:/program files/Internet Explorer/plugins/newtemp. dll
O24-shlexechook: [hm_wow]-{383d0d27-789f-4543-9760-d4e199623476} = C:/Windows/system32/gwhqiotagms. dll
O24-shlexechook: []-{AAF3B135-E338-491A-B3CB-9D75DA02C5D1} = C:/program files/Internet Explorer/plugins/ninsys74.sys
O24-shlexechook: [Microsoft Data tools query designe]-{09f8a0eb-ed61-4714-b0ad-7eaff5361a8b} = C:/Windows/system32/zhjtrx. dll
O24-shlexechook: []-{5bd45097-4503-4133-820e-fdac57af00e2} = C:/program files/Internet Explorer/plugins/nvsys74.sys
O24-shlexechook: []-{C5E87A05-F463-4841-B19E-DD3EC3862368} = C:/program files/Internet Explorer/iexplore32.sys
O24-shlexechook: []-{EE12D60D-AD9A-4095-B839-3BE6862679FD} = C:/program files/Internet Explorer/iexplore32.dat
O24-shlexechook: []-{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E} = C:/program files/Internet Explorer/iexplore32.win
The HKLM/showall value is not 1.
===/