一位网友的电脑开机进入桌面后总自动弹出“开天西游”游戏登录画面,关也关不掉。请我帮忙解决。
初步分析,这个应该是网友安装了什么免费软件后,附带的免费“福利 ”。
弹广告也还罢了,关不掉就有点过份了。
用pe_xscan 扫描 log并分析,发现如下可疑项:
pe_xscan 11-03-17 by Purple Endurer
2025-3-15 10:44:43
9.11.19041.0
MSIE:9.11.19041.0
管理员用户组
正常模式
C:\Windows\SysWOW64\svchost.exe * 4172 |$M$ | 2021-10-6 21:27:30 | Microsoft? Windows? Operating System | 10.0.19041.1 | Windows 服务主进程 | ? Microsoft Corporation. All rights reserved. | 10.0.19041.1 (WinBuild.160101.0800) | Microsoft Corporation| ? | svchost.exe | svchost.exe.mui
c:\program files (x86)\ldslite\lpi\tmsvc.dll |$Chengdu Qilu Technology Co. Ltd. | 2024-7-23 20:7:41 | genral protect service | 6.5023.1165.914 | general protect service | Copyright (C) 2008-2023 | 6.5023.1165.914| ?| ? | Svc.dll | Svc.dll
C:\Windows\System32\netload.dll |$Beijing Qihu Technology Co., Ltd. | 2024-7-18 9:3:48 | 网卡负载功能支持模块 | 1.5019.1001.430 | 网卡负载功能支持模块| ? | 1.5019.1001.430 | 成都奇鲁科技有限公司| ?| ?| ?
c:\program files (x86)\ldslite\lpi\CheckHp.dll |$Beijing Qihu Technology Co., Ltd. | 2024-7-23 20:7:39 | 鲁大师 | 2, 5019, 1001, 1227 | 鲁大师 | Copyright (C) 2015 | 2, 5019, 1001, 1227 | www.ludashi.com| ? | LockHome | LockHome.exe
c:\program files (x86)\ldslite\360base.dll |$Beijing Qihu Technology Co., Ltd. | 2024-7-16 19:50:6 | 360安全卫士 | 1, 0, 0, 1245 | 360安全卫士 基础模块 | (C) 360.cn Inc. All Rights Reserved. | 1, 0, 0, 1245 | 360.cn| ? | 360Base | 360Base.dll
C:\Program Files (x86)\LdsLite\Utils\guardhp.exe * 9604 |$Chengdu Qilu Technology Co. Ltd. | 2024-12-29 12:41:14| ? | 1.5024.1105.321 | BroSafeTips | Copyright (C) 2015-2023 | 1.5024.1105.321| ?| ? | ghp.exe | ghp.exe
C:\Program Files (x86)\LdsLite\Utils\guardhp.exe |$Chengdu Qilu Technology Co. Ltd. | 2024-12-29 12:41:14| ? | 1.5024.1105.321 | BroSafeTips | Copyright (C) 2015-2023 | 1.5024.1105.321| ?| ? | ghp.exe | ghp.exe
C:\Windows\System32\netload.dll |$Beijing Qihu Technology Co., Ltd. | 2024-7-18 9:3:48 | 网卡负载功能支持模块 | 1.5019.1001.430 | 网卡负载功能支持模块| ? | 1.5019.1001.430 | 成都奇鲁科技有限公司| ?| ?| ?
C:\Program Files (x86)\LdsLite\SuperApp\proc_opt\proc_opt_ui.exe * 8352 |$成都奇鲁科技有限公司 | 2025-2-5 14:31:53| ? | 1.1025.1055.121 | 电脑智能防卡顿 | Copyright (C) 2025 | 1.1025.1055.121 | 鲁大师| ? | proc_opt_ui.exe | proc_opt_ui.exe
C:\Program Files (x86)\LdsLite\SuperApp\proc_opt\proc_opt_ui.exe |$成都奇鲁科技有限公司 | 2025-2-5 14:31:53| ? | 1.1025.1055.121 | 电脑智能防卡顿 | Copyright (C) 2025 | 1.1025.1055.121 | 鲁大师| ? | proc_opt_ui.exe | proc_opt_ui.exe
C:\Program Files (x86)\LdsLite\independent_product.dll |$成都奇鲁科技有限公司 | 2025-1-15 20:5:21| ? | 1.5025.1050.113| ? | Copyright (C) 2025 | 1.5025.1050.113| ?| ?| ?| ?
C:\Program Files (x86)\LdsLite\Utils\product_helper.dll |$Chengdu Qilu Technology Co. Ltd. | 2023-2-21 14:35:1 | product_helper | 1.5022.1035.1116 | 产品必要组件 | Copyright (C) 2021 | 1.5022.1035.1116| ?| ?| ? | product_helper.dll
C:\Program Files (x86)\LdsLite\netul.dll |$成都奇鲁科技有限公司 | 2025-3-5 17:4:22 | netul | 1.5024.1080.1008 | 网络基础库 | Copyright (C) 2023 | 1.5024.1080.1008| ?| ? | netul.dll | netul.dll
C:\Program Files (x86)\LdsLite\Utils\js_basic.dll |$成都奇鲁科技有限公司 | 2025-2-7 15:30:48 | js_basic Dynamic Link Library | 1.5025.1535.109 | js_basic Dynamic Link Library | Copyright (C) 2024 | 1.5025.1535.109| ?| ? | js_basic.dll | js_basic.dll
C:\Program Files (x86)\LdsLite\Plugin\Basic.tpi |$成都奇鲁科技有限公司 | 2024-12-29 12:41:5 | 基础功能模块 | 2.5024.1305.528 | 基础功能模块| ? | 2.5024.1305.528| ?| ? | Basic | Basic.dll
C:\Program Files (x86)\LdsLite\Utils\WebView.dll |$成都奇鲁科技有限公司 | 2024-12-29 12:41:16 | WebView Dynamic Link Library | 2.5024.3195.912 | WebView Dynamic Link Library | 版权所有 (C) 2008-2024 | 2.5024.3195.912| ?| ? | WebView | WebView.dll
C:\Windows\System32\netload.dll |$Beijing Qihu Technology Co., Ltd. | 2024-7-18 9:3:48 | 网卡负载功能支持模块 | 1.5019.1001.430 | 网卡负载功能支持模块| ? | 1.5019.1001.430 | 成都奇鲁科技有限公司| ?| ?| ?
C:\Program Files (x86)\LdsLite\plugin\PopMgrStub.dll |$Chengdu Qilu Technology Co. Ltd. | 2024-12-29 12:41:7 | PopMgrSu Dynamic Link Library | 1.5024.1060.416 | PopMgrSu Dynamic Link Library | Copyright (C) 2024 | 1.5024.1060.416| ?| ? | PopMgrSu | PopMgrSu.dll
C:\Program Files (x86)\LdsLite\Utils\paap32.exe * 6628 |$成都奇鲁科技有限公司 | 2025-3-1 9:39:29 | tools | 2.5024.1020.1113 | tools | TODO: (C) <=URhP~_R)Gaferhartjteywr>。 保留所有权利。 | 2.5024.1020.1113 | <=URhP~_R)Gaferhartjteywr>| ? | tools.exe | tools.exe
C:\Program Files (x86)\LdsLite\Utils\paap32.exe |$成都奇鲁科技有限公司 | 2025-3-1 9:39:29 | tools | 2.5024.1020.1113 | tools | TODO: (C) <=URhP~_R)Gaferhartjteywr>。 保留所有权利。 | 2.5024.1020.1113 | <=URhP~_R)Gaferhartjteywr>| ? | tools.exe | tools.exe
C:\Program Files (x86)\LdsLite\Utils\product_helper.dll |$Chengdu Qilu Technology Co. Ltd. | 2023-2-21 14:35:1 | product_helper | 1.5022.1035.1116 | 产品必要组件 | Copyright (C) 2021 | 1.5022.1035.1116| ?| ?| ? | product_helper.dll
C:\Program Files (x86)\LdsLite\Utils\popex.dll |$成都奇鲁科技有限公司 | 2024-12-24 17:34:35 | PopEx | 1.5024.1090.1209 | PopEx | 版权所有 (C) 2008-2024 all right reserved | 1.5024.1090.1209| ?| ? | PopEx | PopEx.dll
C:\Windows\System32\netload.dll |$Beijing Qihu Technology Co., Ltd. | 2024-7-18 9:3:48 | 网卡负载功能支持模块 | 1.5019.1001.430 | 网卡负载功能支持模块| ? | 1.5019.1001.430 | 成都奇鲁科技有限公司| ?| ?| ?
C:\Program Files (x86)\LdsLite\Plugin\Basic.tpi |$成都奇鲁科技有限公司 | 2024-12-29 12:41:5 | 基础功能模块 | 2.5024.1305.528 | 基础功能模块| ? | 2.5024.1305.528| ?| ? | Basic | Basic.dll
C:\Program Files (x86)\LdsLite\netul.dll |$成都奇鲁科技有限公司 | 2025-3-5 17:4:22 | netul | 1.5024.1080.1008 | 网络基础库 | Copyright (C) 2023 | 1.5024.1080.1008| ?| ? | netul.dll | netul.dll
C:\Program Files (x86)\LdsLite\NetBridge.dll |$Beijing Qihu Technology Co., Ltd. | 2024-7-23 20:7:43 | net bridge | 1,5019,1033,521 | net bridge | All Rights Reserved | 1,5019,1033,521 | net| ? | NetBridge.dll | NetBridge.dll
C:\Program Files (x86)\LdsLite\utils\public_config.dll |$Chengdu Qilu Technology Co. Ltd. | 2024-8-14 16:29:38 | PB | 1.5022.1030.720 | PB Dynamic Link Library | Copyright (C) 2021 | 1.5022.1030.720| ?| ? | pb.dll | pb.dll
C:\Program Files (x86)\LdsLite\lpi\TmSvc.dll |$Chengdu Qilu Technology Co. Ltd. | 2024-7-23 20:7:41 | genral protect service | 6.5023.1165.914 | general protect service | Copyright (C) 2008-2023 | 6.5023.1165.914| ?| ? | Svc.dll | Svc.dll
C:\Users\Administrator\AppData\Roaming\MicroGame\ktxy\ktxy.exe * 9344 |$成都奇鲁科技有限公司 | 2025-2-18 14:57:28 | cscq | 65535.0.350.119 | cscq | Copyright (C) 2024 | 65535.0.350.119 | | ? | mgbox.exe | mgbox.exe
C:\Users\Administrator\AppData\Roaming\MicroGame\ktxy\ktxy.exe |$成都奇鲁科技有限公司 | 2025-2-18 14:57:28 | cscq | 65535.0.350.119 | cscq | Copyright (C) 2024 | 65535.0.350.119 | | ? | mgbox.exe | mgbox.exe
C:\Windows\System32\netload.dll |$Beijing Qihu Technology Co., Ltd. | 2024-7-18 9:3:48 | 网卡负载功能支持模块 | 1.5019.1001.430 | 网卡负载功能支持模块| ? | 1.5019.1001.430 | 成都奇鲁科技有限公司| ?| ?| ?
C:\Users\Administrator\AppData\Roaming\MicroGame\NetBridge.dll |$Chengdu Qilu Technology Co. Ltd. | 2024-9-14 20:42:17 | net bridge | 1,5019,1033,521 | net bridge | All Rights Reserved | 1,5019,1033,521 | net| ? | NetBridge.dll | NetBridge.dll
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\WebView.dll |$Chengdu Qilu Technology Co. Ltd. | 2023-12-14 13:50:10 | WebView Dynamic Link Library | 2.5023.3160.405 | WebView Dynamic Link Library | 版权所有 (C) 2008-2022 | 2.5023.3160.405| ?| ? | WebView | WebView.dll
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\CefView.exe * 3904 |$成都奇鲁科技有限公司 | 2025-2-18 10:50:7 | CefView Application | 4.5024.3055.920 | CefView Application | 版权所有 (C) 2008-2024 | 4.5024.3055.920| ?| ? | CefView | CefView.exe
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\CefView.exe |$成都奇鲁科技有限公司 | 2025-2-18 10:50:7 | CefView Application | 4.5024.3055.920 | CefView Application | 版权所有 (C) 2008-2024 | 4.5024.3055.920| ?| ? | CefView | CefView.exe
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\libcef.dll |$Chengdu Qilu Technology Co. Ltd. | 2023-6-16 16:6:12 | Chromium Embedded Framework (CEF) Dynamic Link Library | 3.3497.1841.g7f37a0a | Chromium Embedded Framework (CEF) Dynamic Link Library | Copyright (C) 2022 The Chromium Embedded Framework Authors | 3.3497.1841.g7f37a0a| ?| ? | libcef | libcef.dll
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\chrome_elf.dll |$Chengdu Qilu Technology Co. Ltd. | 2023-6-16 16:6:11 | Chromium | 69.0.3497.100 | Chromium | Copyright 2017 The Chromium Authors. All rights reserved. | 69.0.3497.100 | The Chromium Authors| ? | chrome_elf_dll | chrome_elf.dll
C:\Windows\System32\netload.dll |$Beijing Qihu Technology Co., Ltd. | 2024-7-18 9:3:48 | 网卡负载功能支持模块 | 1.5019.1001.430 | 网卡负载功能支持模块| ? | 1.5019.1001.430 | 成都奇鲁科技有限公司| ?| ?| ?
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\CefView.exe * 3076 |$成都奇鲁科技有限公司 | 2025-2-18 10:50:7 | CefView Application | 4.5024.3055.920 | CefView Application | 版权所有 (C) 2008-2024 | 4.5024.3055.920| ?| ? | CefView | CefView.exe
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\CefView.exe |$成都奇鲁科技有限公司 | 2025-2-18 10:50:7 | CefView Application | 4.5024.3055.920 | CefView Application | 版权所有 (C) 2008-2024 | 4.5024.3055.920| ?| ? | CefView | CefView.exe
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\libcef.dll |$Chengdu Qilu Technology Co. Ltd. | 2023-6-16 16:6:12 | Chromium Embedded Framework (CEF) Dynamic Link Library | 3.3497.1841.g7f37a0a | Chromium Embedded Framework (CEF) Dynamic Link Library | Copyright (C) 2022 The Chromium Embedded Framework Authors | 3.3497.1841.g7f37a0a| ?| ? | libcef | libcef.dll
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\chrome_elf.dll |$Chengdu Qilu Technology Co. Ltd. | 2023-6-16 16:6:11 | Chromium | 69.0.3497.100 | Chromium | Copyright 2017 The Chromium Authors. All rights reserved. | 69.0.3497.100 | The Chromium Authors| ? | chrome_elf_dll | chrome_elf.dll
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\D3DCompiler_47.dll |$Microsoft Corporation | 2023-6-16 16:6:11 | Microsoft? Windows? Operating System | 10.0.10572.1000 | Direct3D HLSL Compiler for Redistribution | ? Microsoft Corporation. All rights reserved. | 10.0.10572.1000 (th2_release_sa.151014-2155) | Microsoft Corporation| ? | d3dcompiler_47.dll | d3dcompiler_47.dll
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\libglesv2.dll |$Chengdu Qilu Technology Co. Ltd. | 2023-6-16 16:6:11 | ANGLE libGLESv2 Dynamic Link Library | 2.1.0.6ffc489d4f18 | ANGLE libGLESv2 Dynamic Link Library | Copyright (C) 2015 Google Inc. | 2.1.0.6ffc489d4f18| ?| ? | libGLESv2 | libGLESv2.dll
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\libegl.dll |$Chengdu Qilu Technology Co. Ltd. | 2023-6-16 16:6:11 | ANGLE libEGL Dynamic Link Library | 2.1.0.6ffc489d4f18 | ANGLE libEGL Dynamic Link Library | Copyright (C) 2015 Google Inc. | 2.1.0.6ffc489d4f18| ?| ? | libEGL | libEGL.dll
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\CefView.exe * 9240 |$成都奇鲁科技有限公司 | 2025-2-18 10:50:7 | CefView Application | 4.5024.3055.920 | CefView Application | 版权所有 (C) 2008-2024 | 4.5024.3055.920| ?| ? | CefView | CefView.exe
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\CefView.exe |$成都奇鲁科技有限公司 | 2025-2-18 10:50:7 | CefView Application | 4.5024.3055.920 | CefView Application | 版权所有 (C) 2008-2024 | 4.5024.3055.920| ?| ? | CefView | CefView.exe
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\libcef.dll |$Chengdu Qilu Technology Co. Ltd. | 2023-6-16 16:6:12 | Chromium Embedded Framework (CEF) Dynamic Link Library | 3.3497.1841.g7f37a0a | Chromium Embedded Framework (CEF) Dynamic Link Library | Copyright (C) 2022 The Chromium Embedded Framework Authors | 3.3497.1841.g7f37a0a| ?| ? | libcef | libcef.dll
C:\Users\Administrator\AppData\Roaming\MicroGame\Utils\cef69\chrome_elf.dll |$Chengdu Qilu Technology Co. Ltd. | 2023-6-16 16:6:11 | Chromium | 69.0.3497.100 | Chromium | Copyright 2017 The Chromium Authors. All rights reserved. | 69.0.3497.100 | The Chromium Authors| ? | chrome_elf_dll | chrome_elf.dllO2 - IeAddOn(jlgplayer3 Control) - {0A1B1EE5-E5AD-48E1-A74A-6DE132B3F8ED}
= C:\PROGRA~2\Sogou\SOGOUE~1\gamesp\NPJLGP~2.DLL |$chengdu jule technology co.,ltd | 2025-2-28 18:40:18 | Jule game player version 3 | 3.0.0.1 | Jule game player version 3 | Copyright (C)2015 Jule game technology co.,ltd. All rights reserved. | 3.0.0.1 | Jule game technology co.,ltd| ? | npjlgplayer3.dll | npjlgplayer3.dll
O2 - IeAddOn(Fancy3DOCX Control) - {B2E8D85E-C0C5-48DF-8DBC-1359B339AE32}
= C:\PROGRA~2\Sogou\SOGOUE~1\gamesp\FANCYG~2.DLL |$Hongfeng Hengyu (Beijing) Tech Ltd. | 2025-2-28 18:40:18 | Fancy3D Game Plugin | 1,16,0223,1406 | Fancy3D Game Plugin | Copyright (C) Hongfeng Hengyu 2009 - 2015. All rights reserved. | 1,16,0223,1406 | Hongfeng Hengyu (Beijing) Tech Ltd.| ? | Fancy3D Game Plugin | fancy3d.ocx
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions 存在 IE或Internet选项可能受到限制
O10 - LSP: Network Adapter Load Library [TCP/IP] = C:\Windows\System32\netload.dll |$Beijing Qihu Technology Co., Ltd. | 2024-7-18 9:3:48 | 网卡负载功能支持模块 | 1.5019.1001.430 | 网卡负载功能支持模块| ? | 1.5019.1001.430 | 成都奇鲁科技有限公司| ?| ?| ?
O10 - LSP: Network Adapter Load Library [UDP/IP] = C:\Windows\System32\netload.dll |$Beijing Qihu Technology Co., Ltd. | 2024-7-18 9:3:48 | 网卡负载功能支持模块 | 1.5019.1001.430 | 网卡负载功能支持模块| ? | 1.5019.1001.430 | 成都奇鲁科技有限公司| ?| ?| ?
O10 - LSP: Network Adapter Load Library [RAW/IP] = C:\Windows\System32\netload.dll |$Beijing Qihu Technology Co., Ltd. | 2024-7-18 9:3:48 | 网卡负载功能支持模块 | 1.5019.1001.430 | 网卡负载功能支持模块| ? | 1.5019.1001.430 | 成都奇鲁科技有限公司| ?| ?| ?
O10 - LSP: Network Adapter Load Library LSP = C:\Windows\System32\netload.dll |$Beijing Qihu Technology Co., Ltd. | 2024-7-18 9:3:48 | 网卡负载功能支持模块 | 1.5019.1001.430 | 网卡负载功能支持模块| ? | 1.5019.1001.430 | 成都奇鲁科技有限公司| ?| ?| ?O23 - 服务: TmSvc (Temperature Monitoring Service) - C:\Windows\System32\svchost.exe -k netsvcs |$M$ | 2021-10-6 21:27:30 | Microsoft? Windows? Operating System | 10.0.19041.1 | Windows 服务主进程 | ? Microsoft Corporation. All rights reserved. | 10.0.19041.1 (WinBuild.160101.0800) | Microsoft Corporation| ? | svchost.exe | svchost.exe.mui
-> C:\Program Files (x86)\LdsLite\lpi\TmSvc.dll |$Chengdu Qilu Technology Co. Ltd. | 2024-7-23 20:7:41 | genral protect service | 6.5023.1165.914 | general protect service | Copyright (C) 2008-2023 | 6.5023.1165.914| ?| ? | Svc.dll | Svc.dll(自动)
居然还带有数字签名,应该要点面子,讲点武德吧?
检查“控制面板”里的“应用和功能”,发现了“卸载开天西游”和“卸载维京传奇”两个选项。
文件说明符 : C:\PROGRA~2\Sogou\SOGOUE~1\gamesp\NPJLGP~2.DLL
属性 : A---
数字签名:chengdu jule technology co.,ltd
PE文件:是
语言 : 英语(美国)
文件版本 : 3.0.0.1
说明 : Jule game player version 3
版权 : Copyright (C)2015 Jule game technology co.,ltd. All rights reserved.
产品版本 : 3.0.0.1
产品名称 : Jule game player version 3
公司名称 : Jule game technology co.,ltd
内部名称 : npjlgplayer3.dll
源文件名 : npjlgplayer3.dll
创建时间 : 2024-6-29 18:13:30
修改时间 : 2025-2-28 18:40:18
大小 : 795120 字节 776.496 KB
MD5 : 971c8968b06b6b46891c248b825c11c4
SHA1: C3AB5FBD880C7F25F6526D984A5325FEF11C62C9
CRC32: 2b49b91c
文件说明符 : C:\PROGRA~2\Sogou\SOGOUE~1\gamesp\FANCYG~2.DLL
属性 : A---
数字签名:Hongfeng Hengyu (Beijing) Tech Ltd.
PE文件:是
语言 : 英语(美国)
文件版本 : 1,16,0223,1406
说明 : Fancy3D Game Plugin
版权 : Copyright (C) Hongfeng Hengyu 2009 - 2015. All rights reserved.
产品版本 : 1,16,0223,1406
产品名称 : Fancy3D Game Plugin
公司名称 : Hongfeng Hengyu (Beijing) Tech Ltd.
内部名称 : Fancy3D Game Plugin
源文件名 : fancy3d.ocx
创建时间 : 2024-6-29 18:13:30
修改时间 : 2025-2-28 18:40:18
大小 : 770592 字节 752.544 KB
MD5 : be133fea55ba53ab1bb8f768db492623
SHA1: 0D37D2AE96F9078DF96F5887AEEE5FC197ABBF92
CRC32: c25473f9