启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<MSConfig><"C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto> [(Verified)Microsoft Windows Publisher]
<RAVCQMON><C:\Program Files\Internet Explorer\RAVCQMON.exe> []
<MsIMMs32><C:\WINDOWS\MsIMMs32.exe> []
<wdfmgrnt><C:\WINDOWS\system32\wdfmgrnt.exe> []
<TIMHost><C:\WINDOWS\TIMHost.exe> [N/A]
<RAVCHDMON><C:\Program Files\Internet Explorer\RAVCHDMON.exe> []
<RAVZTMON><C:\Program Files\Internet Explorer\RAVZTMON.exe> []
<RAVDHMON><C:\Program Files\Internet Explorer\RAVDHMON.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<MSDEG32><LYLoader.exe> []
<MSDWG32><LYLoadbr.exe> [N/A]
<MSDCG32 ><LYLeador.exe> [N/A]
<MSDOG32><LYLoador.exe> [N/A]
<MSDSG32><LYLoadar.exe> [N/A]
<MSDMG32><LYLoadmr.exe> [N/A]
<MSDHG32><LYLoadhr.exe> [N/A]
<MSDQG32><LYLoadqr.exe> [N/A]
<visin><C:\WINDOWS\system32\visin.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><zxgpri.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{64123FF1-8371-9834-9021-184518451FA6}><C:\WINDOWS\system32\qjfpri.dll> []
<{40117B96-998D-4D80-8F89-5E9DBD9F3460}><C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys> []
<{5D83AD9C-3BFC-43F5-979D-2904DBC54A8E}><C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys> []
<{42311A42-AC1B-158F-FD32-5674345F23A4}><C:\WINDOWS\system32\dhdpri.dll> []
<{5EED7056-B89D-4DE8-A060-D285EA746799}><C:\WINDOWS\Netijo.dll> []
<{7A65498A-7653-9801-1647-987114AB7F47}><C:\WINDOWS\system32\zxgpri.dll> []
<{5562452F-FA36-BA4F-892A-FF5FBBAC5315}><C:\WINDOWS\system32\myepri.dll> []
<{A12BC423-3713-224D-3F55-32B35C62B11A}><C:\WINDOWS\system32\tlupri.dll> []
<{759AFD5B-159F-ACD8-954C-ACD545FA6587}><C:\WINDOWS\system32\jzgpri.dll> [N/A]
<{3182C1EB-375C-573D-1F5E-234552345213}><C:\WINDOWS\system32\wlfpri.dll> []
<{A13AF41A-21B1-131B-1BFC-D2A90DF4A2BA}><C:\WINDOWS\system32\xyipri.dll> []
<{D1351752-5628-1547-FFAB-BADC13512AFD}><C:\WINDOWS\system32\ztmpri.dll> []
<{46368135-64FA-BC34-DA32-DCF4FD431C94}><C:\WINDOWS\system32\qhdpri.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rpcc]
<WinlogonNotify: rpcc><C:\WINDOWS\system32\rpcc.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<cmdbcs><; C:\WINDOWS\cmdbcs.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<jfproc><; C:\Program Files\ppfilm\jfCacheMgr.exe> [浙江浩影网络有限公司]
<Kvsc3><; C:\WINDOWS\Kvsc3.exe> []
<mppds><; C:\WINDOWS\mppds.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<RAVZXMON><; C:\Program Files\Internet Explorer\RAVZXMON.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<upxdnd><; C:\WINDOWS\upxdnd.exe> []
<windowsupdate><; C:\WINDOWS\system32\winupdate.exe> [N/A]
<WinForm><; C:\WINDOWS\WinForm.exe> []
<WinSys><; C:\WINDOWS\IG.exe> [N/A]
==================================
服务
[1FDF3E90 / 1FDF3E90][Stopped/Auto Start]
<C:\WINDOWS\system32\C24C0548.EXE -a><N/A>
[445460B0 / 445460B0][Stopped/Auto Start]
<C:\WINDOWS\system32\D171BA70.EXE -g><N/A>
[4A8B028 / 4A8B028][Stopped/Auto Start]
<C:\WINDOWS\system32\11F7FAB0.EXE -k><Microsoft Corporation>
[7497C5B0 / 7497C5B0][Stopped/Auto Start]
<C:\WINDOWS\system32\D77A2710.EXE -k><Microsoft Corporation>
[C92F01A0 / C92F01A0][Stopped/Auto Start]
<C:\WINDOWS\system32\BC4398A8.EXE -p><N/A>
[D24C4A28 / D24C4A28][Stopped/Auto Start]
<C:\WINDOWS\system32\F2B0B578.EXE -d><N/A>
[husjdd8s / husjdd8s][Stopped/Auto Start]
<C:\WINDOWS\system32\husjdd8s.exe -j><N/A>
[SRCSVC / SRCSVC][Stopped/Auto Start]
<C:\WINDOWS\srcsvc.exe><N/A>
[svchost / svchost][Stopped/Auto Start]
<C:\WINDOWS\system32\dllcache\svchost.exe -g><Microsoft Corporation>
[TSECleanUpAssist / TSECleanUpAssist][Stopped/Auto Start]
<C:\WINDOWS\system32\5fe6.com><N/A>
[WebPrint / WebPrint][Stopped/Auto Start]
<c:\windows\system32\webprint.exe><>
[Windows Accounts Driver / windows_0][Stopped/Auto Start]
<C:\WINDOWS\system32\888.exe><N/A>
[Remote Debug Service / RemoteDbg][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe RemoteDbg.dll,input><Microsoft Corporation>
[Win32 Debug Service / MSDebugsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe msdebug.dll,input><Microsoft Corporation>
==================================
驱动程序
[acpidisk / acpidisk][Stopped/Boot Start]
<2 - 系统找不到指定的文件。
><N/A>
[IGALIVE / IGALIVE][Running/Auto Start]
<\??\C:\Program Files\IGALIVE\IGALIVE.sys><N/A>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
<system32\DRIVERS\ipinip.sys><N/A>
[kqxuxv8 / kqxuxv80][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\kqxuxv80.sys><N/A>
[mssock / mssock][Running/Manual Start]
<\??\C:\WINDOWS\system32\mssock.sys><N/A>
[Netgroup Packet Filter / NPF][Running/Manual Start]
<system32\DRIVERS\npf.sys><CACE Technologies>
[Input and output operations / ntio256][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\ntio256.sys><N/A>
[odtecd1 / odtecd16][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\odtecd16.sys><N/A>
==================================
[C:\WINDOWS\system32\msdebug.dll] [N/A, ]
[C:\WINDOWS\system32\RemoteDbg.dll] [N/A, ]
[C:\WINDOWS\system32\down1.DAT] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\SysWin64.Sys] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
[C:\WINDOWS\system32\85D67BD8.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\B12E9A50.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\8AE30D90.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\A10D0A40.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\E28F2568.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\osiesd3.dll] [Microsoft Corporation, ]
[C:\WINDOWS\system32\D26D9558.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\Netijo.dll] [N/A, ]
[C:\WINDOWS\winow.dll] [N/A, ]
[C:\WINDOWS\system32\zxgpri.dll] [N/A, ]
[C:\WINDOWS\system32\qhdpri.dll] [N/A, ]
[C:\WINDOWS\system32\ztmpri.dll] [N/A, ]
[C:\WINDOWS\system32\xyipri.dll] [N/A, ]
[C:\WINDOWS\system32\wlfpri.dll] [N/A, ]
[C:\WINDOWS\system32\tlupri.dll] [N/A, ]
[C:\WINDOWS\system32\myepri.dll] [N/A, ]
[C:\WINDOWS\system32\dhdpri.dll] [N/A, ]
[C:\WINDOWS\system32\qjfpri.dll] [N/A, ]
C:\WINDOWS\system32\mscomm.dll(, N/A)
C:\Autorun.inf
C:\auto.exe
D:\Autorun.inf
D:\auto.exe
E:\Autorun.inf
E:\auto.exe
F:\Autorun.inf
F:\auto.exe
==================================
HOSTS 文件
127.0.0.1 localhost
59.60.21.155 habao.lajiren.com
59.60.30.216 www.baidu.com
59.60.30.216 www.sina.com.cn
59.60.30.216 www.163.com
59.60.30.216 cn.yahoo.com
59.60.30.216 www.google.com
59.60.30.216 www.freedh.com
59.60.30.216 www.hao123.com
59.60.30.216 www.qq.com
59.60.30.216 qq.com
59.60.30.216 hao123.com
59.60.30.216 www.51kuo.com
59.60.30.216 51kuo.com
59.60.30.216 google.com
以上都是有问题的项目和文件(请不要直接删除文件或注册表项、服务项目、驱动程序,因为其中一些的项目我尚不能确定,但可以很负责的说,你的机中了无数病毒,手工杀太麻烦)。
建议重装系统,之后不要访问任何驱动器,直接上网下载冰刃到
桌面,解压后用冰刃删除以下文件:
D:\Autorun.inf
D:\auto.exe
E:\Autorun.inf
E:\auto.exe
F:\Autorun.inf
F:\auto.exe