可疑文件:
c:\gua123.exe
c:\windows\system32\e1384213.dll
c:\windows\system32\a1a6bc2e.dll
c:\windows\system32\x8rbvcvpmmw.dll
c:\windows\system32\122b901e.dll
c:\windows\system32\cc80f0b4.dll
c:\windows\system32\rbwn2dra.dll
c:\windows\system32\cc0ec2c9.dll
c:\windows\system32\drivers\etc\iwaq1qbi.dll
c:\windows\system32\drivers\oreans32.sys
启动项目:
[{E1384213-0948-4A60-A9E3-875B191CC2E7}] <E1384213.dll>
[{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8}] <A1A6BC2E.dll>
[foxy] <; "C:\Documents and Settings\cyg\桌面\专用下载\Foxy\Foxy.exe" -tray>
[IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] <; "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020>
[SkinClock] <; C:\Program Files\Free Desktop Clock\DesktopClock.exe>
[Babylon Client] <; C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart>
[360Safebox] <; C:\Program Files\360\360safebox\safeboxTray.exe" /r>
[360Safetray] <; C:\Program Files\360\360Safe\safemon\360tray.exe /start>
[百度安全中心] <; C:\Program Files\baidu\SafeCenter\baccore.exe>
[{92E496B3-2E80-4FE0-B6F8-B3308BB6BFB9}] <C:\WINDOWS\system32\x8RbVCvpMmw.dll>
[{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}] <C:\WINDOWS\system32\122B901E.dll>
[{CC80F0B4-04D7-44D0-8DB9-9109B5B72141}] <C:\WINDOWS\system32\CC80F0B4.dll>
[{DDFDCED2-075A-4910-986E-B2BDA2B0E916}] <C:\WINDOWS\system32\rBWN2dra.dll>
[{CC0EC2C9-432D-4DCC-91E7-A7C5CEA748D8}] <C:\WINDOWS\system32\CC0EC2C9.dll>
[FishDesk] <; C:\Program Files\鱼鱼桌面\FishDesk.exe>
.......映像劫持...........................
服务:
[SRAT_Service / SRAT_Service] <C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\drivers\etc\IWAq1qBi.dll>
[oreans32 / oreans32] <\??\C:\WINDOWS\system32\drivers\oreans32.sys>
HOSTS文件要重置