日志1
主要的木马文件是
C:\WINDOWS\system32\gdz\svchost.exe
C:\DOCUME~1\tf\LOCALS~1\Temp\738458052.exe
C:\WINDOWS\system32\certmgrkd.dll
首先断开网络,使用冰刀等程序中止进程
PID = 1988, C:\WINDOWS\SYSTEM32\GDZ\SVCHOST.EXE
PID = 3756, C:\DOCUME~1\TF\LOCALS~1\TEMP\738458052.EXE
然后使用xdelbox清除上面三个文件
使用SRENG清除启动项注册表中的下面项,然后重启系统就行了。
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<pgnwkhe><C:\WINDOWS\system32\kbirfcz.dll> [File is missing]
<certmgrkd.dll><C:\WINDOWS\system32\certmgrkd.dll> []
<dpvvoxmh.dll><C:\WINDOWS\system32\dpvvoxmh.dll> [File is missing]
<kbdgrms.dll><C:\WINDOWS\system32\kbdgrms.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5a4cd61a-d2c4-2719-2719-e3d56fa3560f}]
<N/A><C:\WINDOWS\system32\gdz\svchost.exe /t> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing]