123   2  /  3  页   跳转

版主baohe的贴

<mppds><C:\WINNT\mppds.exe> [N/A]
<msccrt><C:\WINNT\msccrt.exe> [N/A]
<wsttrs><C:\WINNT\wsttrs.exe> [N/A]
<cmdbcs><C:\WINNT\cmdbcs.exe> [N/A]
<wWinlogin><C:\DOCUME~1\xishuai1\LOCALS~1\Temp\wkernel33.exe> [N/A]
<System><C:\Program Files\Common Files\System\Updaterun.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<twin><C:\WINNT\system32\ctfnom.exe> [N/A]
<main><rundll32.exe "C:\program files\internet explorer\use17.dll" mymain> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><userinit.exe,> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINNT\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.rxk> [N/A]
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys> [N/A]
<{DD7D4640-4464-48C0-82FD-21338366D2D2}><C:\Program Files\Internet Explorer\InfoMs.tdm> [N/A]
<{99F1D023-7CEB-4586-80F7-BB1A98DB7602}><C:\Program Files\Internet Explorer\IEXPLORE.Sys> [N/A]
<{FEB94F5A-69F3-4645-8C2B-9E71D270AF2E}><C:\Program Files\Internet Explorer\IEXPLORE.Dat> [N/A]
<{923509F1-45CB-4EC0-BDE0-1DED35B8FD60}><C:\Program Files\Internet Explorer\IEXPLORE.win> [N/A]
<{4DEC9B29-F08F-4cbc-B179-592B9283FAC9}><c:\program files\rising\rav\puifefkj.dll> [N/A]
[HKEY_CURRENT_USER\Control Panel\Desktop]




有大半是毒.........说起来麻烦
gototop
 

建议格了吧...
好乱...
gototop
 

<9bebulc0stir><C:\WINNT\rundl13a.exe> [N/A]
<wc0ldm><C:\WINNT\Servera.exe> [N/A]
<svc><C:\DOCUME~1\xishuai1\LOCALS~1\Temp\sysonling.exe> [Microsoft Corporation]
<jiy46ift><C:\WINNT\iexpl0re.exe> [N/A]

同意楼上
gototop
 

运行  SRENG 启动 注册表
删除
9bebulc0stir><C:\WINNT\rundl13a.exe> [N/A]
<wc0ldm><C:\WINNT\Servera.exe> [N/A]
<svc><C:\DOCUME~1\xishuai1\LOCALS~1\Temp\sysonling.exe> [Microsoft Corporation]
<jiy46ift><C:\WINNT\iexpl0re.exe> [N/A]
<JobHisInit><C:\Program Files\RMClient\JobHisInit.exe> [N/A]
<mppds><C:\WINNT\mppds.exe> [N/A]
<msccrt><C:\WINNT\msccrt.exe> [N/A]
<wsttrs><C:\WINNT\wsttrs.exe> [N/A]
<cmdbcs><C:\WINNT\cmdbcs.exe> [N/A]
<wWinlogin><C:\DOCUME~1\xishuai1\LOCALS~1\Temp\wkernel33.exe> [N/A]
<System><C:\Program Files\Common Files\System\Updaterun.exe> [N/A]
main><rundll32.exe "C:\program files\internet explorer\use17.dll" mymain> [N/A]
<{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.rxk> [N/A]
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys> [N/A]
<{DD7D4640-4464-48C0-82FD-21338366D2D2}><C:\Program Files\Internet Explorer\InfoMs.tdm> [N/A]
<{99F1D023-7CEB-4586-80F7-BB1A98DB7602}><C:\Program Files\Internet Explorer\IEXPLORE.Sys> [N/A]
<{FEB94F5A-69F3-4645-8C2B-9E71D270AF2E}><C:\Program Files\Internet Explorer\IEXPLORE.Dat> [N/A]
<{923509F1-45CB-4EC0-BDE0-1DED35B8FD60}><C:\Program Files\Internet Explorer\IEXPLORE.win> [N/A]
<{4DEC9B29-F08F-4cbc-B179-592B9283FAC9}><c:\program files\rising\rav\puifefkj.dll> [N/A]


至于自启动项
都是日文,LZ自己看吧。。。。
建议都删除。。。。
gototop
 

运行SRENG 启动 服务
隐藏已认证的微软服务
选中20A3C0A7 / 20A3C0A7,8D3C2EE6 / 8D3C2EE6
设置 点否删除 重启后删除
C:\WINNT\system32\20A3C0A7.EXE
C:\WINNT\system32\8D3C2EE6.EXE

运行SRENG 启动 服务 驱动服务
隐藏已认证的微软服务
选中Cdsys / Cdsys,rrsx / rrsxv
设置 点否删除
重启后删除
C:\WINNT\System32\cdcd.sys
SystemRoot\System32\DRIVERS\rrsxv.sys
C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.rxk] [N/A, N/A]
[C:\Program Files\Internet Explorer\InfoMs.tdm] [N/A, N/A]
[C:\Program Files\Internet Explorer\IEXPLORE.Sys] [N/A, N/A]

gototop
 

谢谢了!!
这就照办去....
gototop
 

<jiy46ift><C:\WINNT\iexpl0re.exe> [N/A]
又是这个东西,不知道你中了多久了,看你系统病毒实在太多,建议重装吧,这样比较安全,重新安装完了记得立刻安装并升级杀毒软件,然后杀毒
gototop
 

好复杂..不如重装下还比较快
gototop
 

学习一下~~~~~~~~~
gototop
 

请教各位
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
下的各个键值全都删了有问题吗?

因为IE的START PAGE给改成了恶意网页
据说是WINDOWS启动组中加载了恶意程序
我又不知道是哪个.....
一古脑全删了行吗?
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT