瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 电脑桌面的右下角出现了6个小电脑!在线等...

12   1  /  2  页   跳转

[求助] 电脑桌面的右下角出现了6个小电脑!在线等...

电脑桌面的右下角出现了6个小电脑!在线等...

帮帮我!这是我第6次装系统了,,,装好后!升级瑞星杀了毒!可是怎么还会出现这样的问题!到安全模式去杀出了155个病毒后!开机又不得了~~只好在装系统!装好后!宽贷一连接上,电脑桌面的右下角又出现了6个小电脑!QQ被强制退出!所以不能抓图!所以没办法上图!我电脑怎么了?各位高手帮我看看我的日志谢谢了!

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
分享到:
gototop
 

回复:电脑桌面的右下角出现了6个小电脑!在线等...

[CODE]

2009-01-29,11:11:44

System Repair Engineer 2.7.0.1210
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件
    进程特权扫描
    计划任务
    API HOOK
    隐藏进程


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Infected) Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <FlashPlayerUpdate><C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe>  [(Verified)Adobe Systems Incorporated]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <RavTray><"D:\瑞星杀毒\Rising\Rav\RsTray.exe" -system>  [(Verified)Beijing Rising Information Technology Corporation Limited]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <Alcmtr><anymie360.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><C:\WINDOWS\fonts\CtmRes.dll C:\WINDOWS\fonts\ComRes.dll hbjcmaei.dll,fibpajai.dll,aeijmkfn.dll,gbbcbded.dll,mlhcpcol.dll,kjpcllif.dll,jalamgoh.dll,dfdcponb.dll,pappnebo.dll,lgjlhbpe.dll,plannhdn.dll,fknnpecj.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [(Verified)Beijing Rising Information Technology Corporation Limited]
    <{1B3C6AE2-8CEA-402A-B724-A420E436BAC6}><C:\WINDOWS\system32\hbjcmaei.dll>  []
    <{F2B9A3A2-6055-49E7-AD45-D989EBF24879}><C:\WINDOWS\system32\fibpajai.dll>  []
    <{AE2364F7-F880-41AD-A7E8-E71D84BC0FC5}><C:\WINDOWS\system32\aeijmkfn.dll>  []
    <{0BBCBDED-7C19-4402-AD22-6C37181A839F}><C:\WINDOWS\system32\gbbcbded.dll>  []
    <{651C9C85-28D0-4CAE-BAD9-D6C723D2F13C}><C:\WINDOWS\system32\mlhcpcol.dll>  []
    <{439C552F-9C7B-425F-B5E0-E95201DFBE67}><C:\WINDOWS\system32\kjpcllif.dll>  []
    <{3A5A6081-9FA1-46E1-8874-EBD01D85B2F5}><C:\WINDOWS\system32\jalamgoh.dll>  []
    <{DFDC987B-5482-4116-B520-AF1A7972DB77}><C:\WINDOWS\system32\dfdcponb.dll>  []
    <{9A997EB8-0BA9-441F-B67C-085A03050DD2}><C:\WINDOWS\system32\pappnebo.dll>  []
    <{50351B9E-A433-4722-81A6-519C917720C7}><C:\WINDOWS\system32\lgjlhbpe.dll>  []
    <{95A771D7-5A81-423C-B5A7-BA28B1E0D04E}><C:\WINDOWS\system32\plannhdn.dll>  []
    <{F4779EC3-844A-43D7-968D-9B135429D79A}><C:\WINDOWS\system32\fknnpecj.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <WebCheck><%SystemRoot%\system32\webcheck.dll>  [(Verified)Microsoft Windows Publisher]
    <SysTray><C:\WINDOWS\system32\stobject.dll>  [(Verified)Microsoft Windows Publisher]
    <1B3C6AE2><C:\WINDOWS\system32\hbjcmaei.dll>  []
    <F2B9A3A2><C:\WINDOWS\system32\fibpajai.dll>  []
    <AE2364F7><C:\WINDOWS\system32\aeijmkfn.dll>  []
    <0BBCBDED><C:\WINDOWS\system32\gbbcbded.dll>  []
    <651C9C85><C:\WINDOWS\system32\mlhcpcol.dll>  []
    <439C552F><C:\WINDOWS\system32\kjpcllif.dll>  []
    <3A5A6081><C:\WINDOWS\system32\jalamgoh.dll>  []
    <DFDC987B><C:\WINDOWS\system32\dfdcponb.dll>  []
    <9A997EB8><C:\WINDOWS\system32\pappnebo.dll>  []
    <50351B9E><C:\WINDOWS\system32\lgjlhbpe.dll>  []
    <95A771D7><C:\WINDOWS\system32\plannhdn.dll>  []
    <F4779EC3><C:\WINDOWS\system32\fknnpecj.dll>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
    <浏览器自定义组件><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Windows 桌面更新><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe]
    <IFEO[CCenter.exe]><svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe]
    <IFEO[RavMonD.exe]><svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe]
    <IFEO[RavTask.exe]><svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsTray.exe]
    <IFEO[RsTray.exe]><svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Thunder5.exe]
    <IFEO[Thunder5.exe]><svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\ssmypics.scr>  [(Verified)Microsoft Windows Publisher]
gototop
 

回复:电脑桌面的右下角出现了6个小电脑!在线等...

==================================
启动文件夹
N/A

==================================
服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Rav Process Communication Center / RavCCenter][Stopped/Auto Start]
  <D:\瑞星杀毒\Rising\Rav\CCENTER.EXE><Beijing Rising Information Technology Co., Ltd.>
[Rising RavTask Manager / RavTask][Stopped/Auto Start]
  <"D:\瑞星杀毒\Rising\Rav\RavTask.exe" RavTask><Beijing Rising Information Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Stopped/Auto Start]
  <D:\瑞星杀毒\Rising\Rav\RavMonD.exe><Beijing Rising Information Technology Co., Ltd.>
[Rising Scan Service / RsScanSrv][Stopped/Auto Start]
  <D:\瑞星杀毒\Rising\Rav\ScanFrm.exe><Beijing Rising Information Technology Co., Ltd.>

==================================
驱动程序
[Intel(r) 82801 Audio Driver Install Service (WDM) / ac97intc][Stopped/Manual Start]
  <system32\drivers\ac97intc.sys><Intel Corporation>
[AliIde / AliIde][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD K8 Processor Driver / AmdK8][Stopped/Manual Start]
  <System32\DRIVERS\amdk8.sys><Advanced Micro Devices>
[CmdIde / CmdIde][Running/Boot Start]
  <\SystemRoot\System32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver / FETNDIS][Stopped/Manual Start]
  <system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Running/Manual Start]
  <system32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
[hookcont / hookcont][Running/System Start]
  <system32\drivers\HookCont.sys><Beijing Rising Information Technology Co., Ltd.>
[hooksys / hooksys][Running/Disabled]
  <system32\drivers\HookSys.sys><Beijing Rising Information Technology Co., Ltd.>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[RsNTGDI / RsNTGDI][Running/Boot Start]
  <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Information Technology Co., Ltd.>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[TCP/IP Protocol Driver / Tcpip][Running/System Start]
  <system32\DRIVERS\tcpip.sys><Microsoft Corporation>
[ViaIde / ViaIde][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\viaidexp.sys><VIA Technologies, Inc.>
[VIA AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start]
  <system32\drivers\viaudio.sys><VIA Technologies, Inc.>
[io / io][Running/Manual Start]
  <2 - 系统找不到指定的文件。
><N/A>
[Safe Mon 360 / SafeMon0][Running/System Start]
  <\??\C:\WINDOWS\system32\77F12D38.dat><N/A>
[msiffei / msiffei][Stopped/Manual Start]
  <System32\Drivers\msiffei.sys><N/A>

==================================
浏览器加载项
[SrchHook Class]
  {F08555B0-9CC3-11D2-AA8E-000000000000} <C:\WINDOWS\system32\IEBHO.dll, N/A>
[IE搜索工具条]
  {BE830FD4-E393-417F-9F4B-CC70ABB3384C} <C:\WINDOWS\system32\IETool.dll, N/A>
[IE搜索工具条]
  {BE830FD4-E393-417F-9F4B-CC70ABB3384C} <C:\WINDOWS\system32\IETool.dll, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, (Signed) Adobe Systems, Inc.>
[SrchHook Class]
  {F08555B0-9CC3-11D2-AA8E-000000000000} <C:\WINDOWS\system32\IEBHO.dll, N/A>
[]
  {FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
[导出到 Microsoft Office Excel(&X)]
  <res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000, N/A>

==================================
正在运行的进程
[PID: 560 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 632 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 656 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 700 / SYSTEM][C:\WINDOWS\system32\services.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 712 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 868 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\anymie360.dll]  [N/A, ]
[PID: 948 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1084 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1176 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1276 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1536 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1616 / Administrator][C:\WINDOWS\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]
    [C:\WINDOWS\system32\hbjcmaei.dll]  [N/A, ]
    [C:\WINDOWS\system32\fibpajai.dll]  [N/A, ]
    [C:\WINDOWS\system32\aeijmkfn.dll]  [N/A, ]
    [C:\WINDOWS\system32\gbbcbded.dll]  [N/A, ]
    [C:\WINDOWS\system32\mlhcpcol.dll]  [N/A, ]
    [C:\WINDOWS\system32\kjpcllif.dll]  [N/A, ]
    [C:\WINDOWS\system32\jalamgoh.dll]  [N/A, ]
    [C:\WINDOWS\system32\dfdcponb.dll]  [N/A, ]
    [C:\WINDOWS\system32\pappnebo.dll]  [N/A, ]
    [C:\WINDOWS\system32\lgjlhbpe.dll]  [N/A, ]
    [C:\WINDOWS\system32\plannhdn.dll]  [N/A, ]
    [C:\WINDOWS\system32\browselc.dll]  [Microsoft Corporation, 6.00.2600.0000]
    [C:\WINDOWS\system32\anymie360.dll]  [N/A, ]
    [C:\WINDOWS\system32\fknnpecj.dll]  [N/A, ]
    [C:\WINDOWS\system32\lgbpfgkj.dll]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNeNt.Onz]  [N/A, ]
[PID: 1880 / Administrator][C:\WINDOWS\system32\ctfmon.exe]  [(Infected) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNeNt.Onz]  [N/A, ]
[PID: 1144 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.8198]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1576 / SYSTEM][D:\瑞星杀毒\Rising\Rav\ScanFrm.exe]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.11]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [D:\瑞星杀毒\Rising\Rav\combase.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 11]
    [D:\瑞星杀毒\Rising\Rav\moncomm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 12]
    [D:\瑞星杀毒\Rising\Rav\scansrvp.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.11]
    [D:\瑞星杀毒\Rising\Rav\proccomm.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 46]
    [D:\瑞星杀毒\Rising\Rav\ScanSrv.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.9]
    [D:\瑞星杀毒\Rising\Rav\comx3.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.37]
    [D:\瑞星杀毒\Rising\Rav\Syslay.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.6]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [D:\瑞星杀毒\Rising\Rav\ScanRavT.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.23]
    [D:\瑞星杀毒\Rising\Rav\ScanBT.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.38]
    [D:\瑞星杀毒\Rising\Rav\ScanStub.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.8]
    [D:\瑞星杀毒\Rising\Rav\RsLog.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.32]
    [D:\瑞星杀毒\Rising\Rav\ScanAdd.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.14]
    [D:\瑞星杀毒\Rising\Rav\RSAPPMGR.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.1]
    [D:\瑞星杀毒\Rising\Rav\CfgDll.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.18]
    [D:\瑞星杀毒\Rising\Rav\Scanner.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.33]
    [D:\瑞星杀毒\Rising\Rav\recomp.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [D:\瑞星杀毒\Rising\Rav\refs.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3]
    [D:\瑞星杀毒\Rising\Rav\viruslib.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 4]
    [D:\瑞星杀毒\Rising\Rav\relibldr.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [D:\瑞星杀毒\Rising\Rav\mvengine.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3]
    [D:\瑞星杀毒\Rising\Rav\posttrt.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [D:\瑞星杀毒\Rising\Rav\ffr.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 2]
    [D:\瑞星杀毒\Rising\Rav\nvfile.dll]  [Beijing Rising Information Technology Co., Ltd., 21, 0, 0, 3]
[PID: 1652 / LOCAL SERVICE][C:\WINDOWS\system32\wdfmgr.exe]  [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)]
[PID: 1640 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\System32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3672 / Administrator][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\browselc.dll]  [Microsoft Corporation, 6.00.2600.0000]
    [C:\WINDOWS\system32\IETool.dll]  [N/A, ]
    [D:\瑞星杀毒\Rising\Rav\RavScrCh.dll]  [Beijing Rising Information Technology Co., Ltd., 21.0.0.60]
    [C:\WINDOWS\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]
    [C:\WINDOWS\system32\hbjcmaei.dll]  [N/A, ]
    [C:\WINDOWS\system32\fibpajai.dll]  [N/A, ]
    [C:\WINDOWS\system32\aeijmkfn.dll]  [N/A, ]
    [C:\WINDOWS\system32\gbbcbded.dll]  [N/A, ]
    [C:\WINDOWS\system32\mlhcpcol.dll]  [N/A, ]
    [C:\WINDOWS\system32\kjpcllif.dll]  [N/A, ]
    [C:\WINDOWS\system32\jalamgoh.dll]  [N/A, ]
    [C:\WINDOWS\system32\dfdcponb.dll]  [N/A, ]
    [C:\WINDOWS\system32\pappnebo.dll]  [N/A, ]
    [C:\WINDOWS\system32\lgjlhbpe.dll]  [N/A, ]
    [C:\WINDOWS\system32\plannhdn.dll]  [N/A, ]
    [C:\WINDOWS\system32\fknnpecj.dll]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNeNt.Onz]  [N/A, ]
    [C:\WINDOWS\system32\lgbpfgkj.dll]  [N/A, ]
[PID: 2148 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1816204]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNeNt.Onz]  [N/A, ]
[PID: 3648 / Administrator][C:\WINDOWS\system32\conime.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\UxTheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNeNt.Onz]  [N/A, ]
[PID: 3688 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1958209]  [N/A, ]
    [C:\WINDOWS\system32\hbjcmaei.dll]  [N/A, ]
    [C:\WINDOWS\system32\fibpajai.dll]  [N/A, ]
[PID: 3576 / Administrator][D:\扫描\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [C:\WINDOWS\system32\hbjcmaei.dll]  [N/A, ]
    [C:\WINDOWS\system32\fibpajai.dll]  [N/A, ]
    [C:\WINDOWS\system32\aeijmkfn.dll]  [N/A, ]
    [C:\WINDOWS\system32\gbbcbded.dll]  [N/A, ]
    [C:\WINDOWS\system32\mlhcpcol.dll]  [N/A, ]
    [C:\WINDOWS\system32\kjpcllif.dll]  [N/A, ]
    [C:\WINDOWS\system32\jalamgoh.dll]  [N/A, ]
    [C:\WINDOWS\system32\dfdcponb.dll]  [N/A, ]
    [C:\WINDOWS\system32\pappnebo.dll]  [N/A, ]
    [C:\WINDOWS\system32\lgjlhbpe.dll]  [N/A, ]
    [C:\WINDOWS\system32\plannhdn.dll]  [N/A, ]
[PID: 3744 / Administrator][D:\扫描\SRE9b4eb966.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [C:\WINDOWS\system32\gbbcbded.dll]  [N/A, ]
    [C:\WINDOWS\system32\plannhdn.dll]  [N/A, ]
    [C:\WINDOWS\system32\kjpcllif.dll]  [N/A, ]
    [C:\WINDOWS\system32\jalamgoh.dll]  [N/A, ]
    [C:\WINDOWS\system32\fibpajai.dll]  [N/A, ]
    [C:\WINDOWS\system32\mlhcpcol.dll]  [N/A, ]
    [C:\WINDOWS\system32\lgjlhbpe.dll]  [N/A, ]
    [C:\WINDOWS\system32\dfdcponb.dll]  [N/A, ]
    [C:\WINDOWS\system32\hbjcmaei.dll]  [N/A, ]
    [C:\WINDOWS\system32\pappnebo.dll]  [N/A, ]
    [C:\WINDOWS\system32\aeijmkfn.dll]  [N/A, ]
    [C:\WINDOWS\system32\uxtheme.dll]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat]  [N/A, ]
    [D:\扫描\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\WINDOWS\system32\fknnpecj.dll]  [N/A, ]
    [C:\Program Files\Internet Explorer\PowerNeNt.Onz]  [N/A, ]
    [C:\WINDOWS\system32\lgbpfgkj.dll]  [N/A, ]
[PID: 1004 / Administrator][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2173408]  [N/A, ]
    [C:\WINDOWS\system32\hbjcmaei.dll]  [N/A, ]
    [C:\WINDOWS\system32\fibpajai.dll]  [N/A, ]
    [C:\WINDOWS\system32\aeijmkfn.dll]  [N/A, ]
    [C:\WINDOWS\system32\gbbcbded.dll]  [N/A, ]
    [C:\WINDOWS\system32\mlhcpcol.dll]  [N/A, ]
    [C:\WINDOWS\system32\kjpcllif.dll]  [N/A, ]
    [C:\WINDOWS\system32\jalamgoh.dll]  [N/A, ]
    [C:\WINDOWS\system32\dfdcponb.dll]  [N/A, ]
    [C:\WINDOWS\system32\pappnebo.dll]  [N/A, ]
    [C:\WINDOWS\system32\lgjlhbpe.dll]  [N/A, ]
    [C:\WINDOWS\system32\plannhdn.dll]  [N/A, ]
    [C:\WINDOWS\system32\fknnpecj.dll]  [N/A, ]
gototop
 

回复:电脑桌面的右下角出现了6个小电脑!在线等...

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost
0.0.0.0 182838.com
0.0.0.0 204.177.92.68
0.0.0.0 asiafriendfinder.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 www.jpbeauty.com
0.0.0.0 beautishow.com
0.0.0.0 goodmovies88.com
0.0.0.0 hothack.home.chinaren.com
0.0.0.0 hualiao.net
0.0.0.0 iplus.allyes.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 asqin123.51.net
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 jjkafei.longcity.net
0.0.0.0 kaomm.8m.cn
0.0.0.0 l3iaoliao.com
0.0.0.0 l3iaoliao.com
0.0.0.0 lingaonbvm.myrice.com
0.0.0.0 lovejava.boy.net.cn
0.0.0.0 love7liao.com
0.0.0.0 babe520.5188.org
0.0.0.0 music.feifa.com
0.0.0.0 music.v111.com
219.153.32.215 auto.search.msn.com

==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 2148, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\1816204]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2148, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\1816204]
特殊特权被允许: SeDebugPrivilege [PID = 3688, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\1958209]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3688, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\1958209]
特殊特权被允许: SeDebugPrivilege [PID = 3576, D:\扫描\SRENGLDR.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3576, D:\扫描\SRENGLDR.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1004, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\2173408]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1004, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\2173408]

==================================
计划任务
N/A

==================================
API HOOK
N/A

==================================
隐藏进程
    [1424] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2239796

==================================


[/CODE]
gototop
 

回复:电脑桌面的右下角出现了6个小电脑!在线等...

日志文件以附件形式发来
点击我这贴右下角的“引用”或最右下角的那个较大的“回复”然后就应该知道怎么发了。
请不要开新贴发日志,就原贴接贴发日志即可。
gototop
 

回复: 电脑桌面的右下角出现了6个小电脑!在线等...



引用:
原帖由 天月来了 于 2009-1-29 11:19:00 发表
日志文件以附件形式发来
点击我这贴右下角的“引用”或最右下角的那个较大的“回复”然后就应该知道怎么发了。
请不要开新贴发日志,就原贴接贴发日志即可。

附件附件:

文件名:1SREngLOG.log
下载次数:152
文件类型:application/octet-stream
文件大小:
上传时间:2009-1-29 11:26:26
描述:log

gototop
 

回复:电脑桌面的右下角出现了6个小电脑!在线等...

这里下载手工清理木马群工具包,并解压至C盘文件夹里。(全部工具内附操作说明):
http://bbs.ikaka.com/attachment.aspx?attachmentid=480689

首先用工具包内的“可疑文件提取工具”提取下面文件。以附件形式发到论坛上来。

C:\WINDOWS\system32\anymie360.exe
C:\WINDOWS\anymie360.exe
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\fonts\CtmRes.dll
C:\WINDOWS\fonts\ComRes.dll
C:\WINDOWS\system32\hbjcmaei.dll
C:\WINDOWS\system32\fibpajai.dll
C:\WINDOWS\system32\aeijmkfn.dll
C:\WINDOWS\system32\gbbcbded.dll
C:\WINDOWS\system32\mlhcpcol.dll
C:\WINDOWS\system32\kjpcllif.dll
C:\WINDOWS\system32\jalamgoh.dll
C:\WINDOWS\system32\dfdcponb.dll
C:\WINDOWS\system32\pappnebo.dll
C:\WINDOWS\system32\lgjlhbpe.dll
C:\WINDOWS\system32\plannhdn.dll
C:\WINDOWS\system32\fknnpecj.dll
C:\WINDOWS\system32\lgbpfgkj.dll
C:\Program Files\Internet Explorer\PowerNeNt.Onz
C:\WINDOWS\system32\77F12D38.dat
C:\WINDOWS\System32\Drivers\msiffei.sys
C:\WINDOWS\system32\IEBHO.dll
C:\WINDOWS\system32\IETool.dll
C:\WINDOWS\system32\anymie360.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1816204
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1958209
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2173408
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2292814
gototop
 

回复: 电脑桌面的右下角出现了6个小电脑!在线等...

建议使用XDelBox(下载地址:http://bbs.ikaka.com/attachment.aspx?attachmentid=446806
删除以下文件:(使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择剪贴板导入.在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储设备
C:\WINDOWS\system32\hbjcmaei.dll
C:\WINDOWS\system32\fibpajai.dll
C:\WINDOWS\system32\aeijmkfn.dll
C:\WINDOWS\system32\gbbcbded.dll
C:\WINDOWS\system32\mlhcpcol.dll
C:\WINDOWS\system32\kjpcllif.dll
C:\WINDOWS\system32\jalamgoh.dll
C:\WINDOWS\system32\dfdcponb.dll
C:\WINDOWS\system32\pappnebo.dll
C:\WINDOWS\system32\lgjlhbpe.dll
C:\WINDOWS\system32\plannhdn.dll
C:\WINDOWS\system32\anymie360.dll
C:\WINDOWS\system32\fknnpecj.dll
C:\WINDOWS\system32\lgbpfgkj.dll
C:\WINDOWS\system32\anymie360.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat
C:\Program Files\Internet Explorer\PowerNeNt.Onz
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2173408
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1958209
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1816204
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2239796
C:\WINDOWS\system32\anymie360.exe
C:\WINDOWS\anymie360.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\Drivers\msiffei.sys
C:\WINDOWS\system32\77F12D38.dat
C:\WINDOWS\system32\IEBHO.dll

删除重启后使用SREng修复下面各项:

启动项目 -- 注册表之如下项删除:
<Alcmtr><anymie360.exe>  []

    <{1B3C6AE2-8CEA-402A-B724-A420E436BAC6}><C:\WINDOWS\system32\hbjcmaei.dll>  []
    <{F2B9A3A2-6055-49E7-AD45-D989EBF24879}><C:\WINDOWS\system32\fibpajai.dll>  []
    <{AE2364F7-F880-41AD-A7E8-E71D84BC0FC5}><C:\WINDOWS\system32\aeijmkfn.dll>  []
    <{0BBCBDED-7C19-4402-AD22-6C37181A839F}><C:\WINDOWS\system32\gbbcbded.dll>  []
    <{651C9C85-28D0-4CAE-BAD9-D6C723D2F13C}><C:\WINDOWS\system32\mlhcpcol.dll>  []
    <{439C552F-9C7B-425F-B5E0-E95201DFBE67}><C:\WINDOWS\system32\kjpcllif.dll>  []
    <{3A5A6081-9FA1-46E1-8874-EBD01D85B2F5}><C:\WINDOWS\system32\jalamgoh.dll>  []
    <{DFDC987B-5482-4116-B520-AF1A7972DB77}><C:\WINDOWS\system32\dfdcponb.dll>  []
    <{9A997EB8-0BA9-441F-B67C-085A03050DD2}><C:\WINDOWS\system32\pappnebo.dll>  []
    <{50351B9E-A433-4722-81A6-519C917720C7}><C:\WINDOWS\system32\lgjlhbpe.dll>  []
    <{95A771D7-5A81-423C-B5A7-BA28B1E0D04E}><C:\WINDOWS\system32\plannhdn.dll>  []
    <{F4779EC3-844A-43D7-968D-9B135429D79A}><C:\WINDOWS\system32\fknnpecj.dll>  []

  <1B3C6AE2><C:\WINDOWS\system32\hbjcmaei.dll>  []
    <F2B9A3A2><C:\WINDOWS\system32\fibpajai.dll>  []
    <AE2364F7><C:\WINDOWS\system32\aeijmkfn.dll>  []
    <0BBCBDED><C:\WINDOWS\system32\gbbcbded.dll>  []
    <651C9C85><C:\WINDOWS\system32\mlhcpcol.dll>  []
    <439C552F><C:\WINDOWS\system32\kjpcllif.dll>  []
    <3A5A6081><C:\WINDOWS\system32\jalamgoh.dll>  []
    <DFDC987B><C:\WINDOWS\system32\dfdcponb.dll>  []
    <9A997EB8><C:\WINDOWS\system32\pappnebo.dll>  []
    <50351B9E><C:\WINDOWS\system32\lgjlhbpe.dll>  []
    <95A771D7><C:\WINDOWS\system32\plannhdn.dll>  []
    <F4779EC3><C:\WINDOWS\system32\fknnpecj.dll>  []

IFEO[CCenter.exe]><svchost.exe>
IFEO[RavMonD.exe]><svchost.exe
<IFEO[RavTask.exe]><
IFEO[RsTray.exe
IFEO[Thunder5.exe]

<AppInit_DLLs><C:\WINDOWS\fonts\CtmRes.dll C:\WINDOWS\fonts\ComRes.dll hbjcmaei.dll,fibpajai.dll,aeijmkfn.dll,gbbcbded.dll,mlhcpcol.dll,kjpcllif.dll,jalamgoh.dll,dfdcponb.dll,pappnebo.dll,lgjlhbpe.dll,plannhdn.dll,fknnpecj.dll>  [File is missing]  编辑为<AppInit_DLLs><>


启动项目 -- 服务-- 驱动程序之如下项删除:
SREng-在"启动项目->服务->驱动程序中"选中"隐藏已认证的微软项目"然后删除下面名称的驱动程序(选中有问题的驱动后,点"删除服务",点“设置”按钮即可。注意弹出的窗口中要点 "否NO"才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置):

[io / io][Running/Manual Start]
  <2 - 系统找不到指定的文件。
><N/A>
[Safe Mon 360 / SafeMon0][Running/System Start]
  <\??\C:\WINDOWS\system32\77F12D38.dat><N/A>
[msiffei / msiffei][Stopped/Manual Start]
  <System32\Drivers\msiffei.sys><N/A>




系统修复——浏览器加载项之如下项删除
[SrchHook Class]
  {F08555B0-9CC3-11D2-AA8E-000000000000} <C:\WINDOWS\system32\IEBHO.dll, N/A>


http://bbs.ikaka.com/showtopic-8417665.aspx#3487007下载ctfmon.exe释放到C:\WINDOWS\system32下


用下载的“清理临时文件工具ATF-Cleaner-cn”,全选所有项目,点击“立即清理”
下载:http://bbs.ikaka.com/attachment.aspx?attachmentid=447126
用W i n d o w s 清理助手 ,清理系统。
W i n d o w s 清理助手 下载:http://www.arswp.com/
gototop
 

回复:电脑桌面的右下角出现了6个小电脑!在线等...

谢谢了天月!!现在就去
gototop
 

回复:电脑桌面的右下角出现了6个小电脑!在线等...

包括其他盘各软件程序同目录内的usp10.dll文件,以及QQ目录内的psapi.dll文件都得找到压缩后发来。
可以利用工具包内的wsyscheck工具搜索查找我需要的文件。
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT