中了usp10.dll木马群,但没杀净。
建议用下面这个帖子的工具删除下列病毒文件并将可能被病毒替换的系统文件复原(详见该帖内容):
http://bbs.ikaka.com/showtopic-8592394.aspxC:\WINDOWS\system32\anymie360.exe
C:\WINDOWS\system32\anymie360.dll(可能存在)
C:\WINDOWS\system32\biaidmkh.dll
C:\Program Files\Internet Explorer\PowerDn.Rel
C:\Program Files\Internet Explorer\PowerNt.ONZ(可能存在)
C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys
另请用WINRAR检查是否存在下列病毒文件:
C:\WINDOWS\Fonts\目录下的comres.dll
C:\WINDOWS\Fonts\目录下文件名中包含ctm的文件(可能有若干个)
C:\WINDOWS\system32\目录下文件名包含ctm的.exe文件(可能有若干个)
分系统分区含.exe的各个目录下的usp10.dll
C:\WINDOWS\Tasks\目录下的 1
如果有上述病毒文件,也要用此工具重启删除。
删除所有病毒文件后,重置HOSTS,打扫注册表垃圾:
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<Alcmtr><anymie360.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><biaidmkh.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{BE9DEA3A-893C-43F3-BC33-99574575A9F0}><C:\Program Files\Internet Explorer\PowerDn.Rel> []
<{A277029C-72FF-4034-BDF0-3EEFB000EDB9}><C:\WINDOWS\system32\ainngipc.dll> [File is missing]
<{56DC9407-E92D-4151-ADA7-8DC644B6C5ED}><C:\WINDOWS\system32\lmdcpkgn.dll> [File is missing]
<{D0BF4F89-A9E9-4154-BAD5-CED384F803BE}><C:\WINDOWS\system32\dgbfkfop.dll> [File is missing]
<{07698EBD-B04C-4419-B71E-6251F07DF4C5}><C:\WINDOWS\system32\gnmpoebd.dll> [File is missing]
<{7532CB93-84BE-4B4B-A6E8-B2728357E035}><C:\WINDOWS\system32\nljicbpj.dll> [File is missing]
<{9EF8DEC9-2E6C-4EE1-BE21-14FC8A825A24}><C:\WINDOWS\system32\pefodecp.dll> [File is missing]
<{C95F08DE-4FAA-43E2-8E71-DCEBBB2F40B9}><C:\WINDOWS\system32\cplfgode.dll> [File is missing]
<{DE7C4017-1C35-4E47-B872-DA08D71D25D2}><C:\WINDOWS\system32\denckghn.dll> [File is missing]
<{A7C1DF5B-6E0A-44B4-AC40-839B5C5B5F2B}><C:\WINDOWS\system32\anchdflb.dll> [File is missing]
<{A70E7DBE-D2CF-452D-B0A4-F296A454046D}><C:\WINDOWS\system32\angendbe.dll> [File is missing]
<{455CD00F-9193-4115-8792-928D266B84CE}><C:\WINDOWS\system32\kllcdggf.dll> [File is missing]
<{B2A2D641-4A75-428F-B9C7-11A8D889DF3F}><C:\WINDOWS\system32\biaidmkh.dll> []
<{CD9C5551-90F5-4734-9FB4-8CFDD2312C20}><C:\WINDOWS\system32\cdpclllh.dll> [File is missing]
<{CA45D2FC-CD9F-47A6-B3CE-24D529089EF1}><C:\WINDOWS\system32\cakldifc.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<A277029C><C:\WINDOWS\system32\ainngipc.dll> [File is missing]
<56DC9407><C:\WINDOWS\system32\lmdcpkgn.dll> [File is missing]
<D0BF4F89><C:\WINDOWS\system32\dgbfkfop.dll> [File is missing]
<07698EBD><C:\WINDOWS\system32\gnmpoebd.dll> [File is missing]
<7532CB93><C:\WINDOWS\system32\nljicbpj.dll> [File is missing]
<9EF8DEC9><C:\WINDOWS\system32\pefodecp.dll> [File is missing]
<C95F08DE><C:\WINDOWS\system32\cplfgode.dll> [File is missing]
<DE7C4017><C:\WINDOWS\system32\denckghn.dll> [File is missing]
<A7C1DF5B><C:\WINDOWS\system32\anchdflb.dll> [File is missing]
<A70E7DBE><C:\WINDOWS\system32\angendbe.dll> [File is missing]
<455CD00F><C:\WINDOWS\system32\kllcdggf.dll> [File is missing]
<B2A2D641><C:\WINDOWS\system32\biaidmkh.dll> []
<CD9C5551><C:\WINDOWS\system32\cdpclllh.dll> [File is missing]
<CA45D2FC><C:\WINDOWS\system32\cakldifc.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe]
<IFEO[CCenter.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe]
<IFEO[RavMonD.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe]
<IFEO[RavTask.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RfwSrv.exe]
<IFEO[RfwSrv.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsTray.exe]
<IFEO[RsTray.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Thunder5.exe]
<IFEO[Thunder5.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
驱动程序
[Netgroup Packet Filter / NPF][Running/Manual Start]
<system32\drivers\npf.sys><CACE Technologies>
[oreans32 / oreans32][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\oreans32.sys><N/A>
浏览器加载项
[]
{9963387B-212E-4643-B207-82DAEA0E713D} <C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys, N/A>
[]
{BE9DEA3A-893C-43F3-BC33-99574575A9F0} <C:\Program Files\Internet Explorer\PowerDn.Rel, N/A>