| 引用: |
【镰刀手的贴子】瑞星监控经系统后自动关闭 卡卡和防火墙无法打开 全部无法升级 优化大师查出开机自动运行很多网络游戏盗号木马反复出现 C:\Program Files\Internet Explorer\PLUGINS里有个Ns_Sys55可疑文件 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks里3个可疑项{50632D5C-B71B-4ba0-B012-3DC6F15C011B} {5E907A48-400E-4EA8-9792-FFAE052D59E9} {D29DCEE0-457B-45A2-A92D-741B95B7723B}
[用户系统信息]Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)
……………… |
1、用XDELBOX删除(重启删除)下列加载项指向的文件:
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<upxdnd><C:\WINDOWS\upxdnd.exe> []
<rhlvrhyt><C:\WINDOWS\hvhtldvf.exe> []
<Kvsc3><C:\WINDOWS\Kvsc3.exE> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<DbgHlp32><C:\WINDOWS\DbgHlp32.exe> []
<PTSShell><C:\WINDOWS\PTSShell.exe> []
<WSockDrv32><C:\WINDOWS\WSockDrv32.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{50632D5C-B71B-4ba0-B012-3DC6F15C011B}><C:\WINDOWS\system32\msosiocp.dll> []
<{D29DCEE0-457B-45A2-A92D-741B95B7723B}><C:\Program Files\Internet Explorer\PLUGINS\Ns_Sys55.Sys> []
服务
[4D900DF0 / 4D900DF0][Stopped/Auto Start]
<C:\WINDOWS\system32\9FCB27C0.EXE -d><Microsoft Corporation>
[HTTP SSL / HTTPFilter][Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k HTTPFilter-->%SystemRoot%\System32\w3ssl.dll><N/A>
[KailleraServer / KailleraServer][Stopped/Manual Start]
<C:\WINDOWS\system32\kaillera\srvany.exe><N/A>
[kailleraServerJK / kailleraServerJK][Stopped/Manual Start]
<C:\WINDOWS\system32\kaillera\srvany.exe><N/A>
[PnkBstrA / PnkBstrA][Stopped/Manual Start]
<C:\WINDOWS\system32\PnkBstrA.exe><N/A>
驱动程序
[drop / drop][Stopped/Auto Start]
<\??\C:\DOCUME~1\镰刀手\LOCALS~1\Temp\tmp926.tmp><N/A>
[fpids32 / fpids32][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosfpids32.sys><N/A>
[mhfp / mhfp][Stopped/Auto Start]
<\??\C:\DOCUME~1\镰刀手\LOCALS~1\Temp\tmp9.tmp><N/A>
[msert / msert][Running/Auto Start]
<system32\drivers\mselk.sys><N/A>
浏览器加载项
[]
{D29DCEE0-457B-45A2-A92D-741B95B7723B} <C:\Program Files\Internet Explorer\PLUGINS\Ns_Sys55.Sys, N/A>
2、重启后,用SRENG(就是你扫这份日志的工具)删除上述加载项。