问题项目如下:
一、注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<kcien32><kncer30.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HBService><explore.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{E0F3526A-4165-4589-80CD-50B6FBAC3BDA}><C:\WINDOWS\system32\adsntzt.dll> []
<{7A6DF30E-D0F2-446f-B4F0-BF4232D60E07}><C:\WINDOWS\system32\cliconfgzx.dll> []
<{D3112B69-A745-4805-874E-ABD480EA1299}><C:\WINDOWS\system32\bootvidgj.dll> []
<{67AC9076-C898-B098-D098-A18319080976}><C:\WINDOWS\system32\nhmxfjkl.dll> []
<{2CB77746-8ECC-40ca-8217-10CA8BE5EFC8}><C:\WINDOWS\system32\tscfgwmijxsj.dll> []
<{628DF602-9541-A985-210A-984A698C6F26}><C:\WINDOWS\Fonts\ptjhfhlp.dll> []
<{A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9}><C:\WINDOWS\system32\nwapi32dj.dll> []
<{1A093234-9201-3412-8952-1254379023A1}><C:\WINDOWS\Fonts\edchakae.dll> []
<{7A069845-2036-6084-9054-6087502480A7}><C:\WINDOWS\Fonts\ozfygbyt.dll> []
<{EB9660D8-E1CD-4ff0-B4A9-00CD907F928A}><C:\WINDOWS\system32\slbiopfs2.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<adsntzt.dll><C:\WINDOWS\system32\adsntzt.dll> []
<cliconfgzx.dll><C:\WINDOWS\system32\cliconfgzx.dll> []
<bootvidgj.dll><C:\WINDOWS\system32\bootvidgj.dll> []
<tscfgwmijxsj.dll><C:\WINDOWS\system32\tscfgwmijxsj.dll> []
<nwapi32dj.dll><C:\WINDOWS\system32\nwapi32dj.dll> []
<slbiopfs2.dll><C:\WINDOWS\system32\slbiopfs2.dll> []
类似以下项目的众多IFEO项:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe]
<IFEO[360rpt.exe]>
二、服务
[HBKernel Driver / HBKernel][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\HBKernel.sys><N/A>
三、正在运行的进程
正在运行的进程
[C:\WINDOWS\system32\HBmhly.dll] [N/A, ]
[C:\WINDOWS\system32\nhmxfjkl.dll] [N/A, ]
[C:\WINDOWS\system32\nhmxfjkl.dll] [N/A, ]
[C:\WINDOWS\system32\slbiopfs2.dll] [N/A, ]
[C:\WINDOWS\system32\nwapi32dj.dll] [N/A, ]
[C:\WINDOWS\system32\tscfgwmijxsj.dll] [N/A, ]
[C:\WINDOWS\system32\bootvidgj.dll] [N/A, ]
[C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ]
[C:\WINDOWS\system32\adsntzt.dll] [N/A, ]
[C:\WINDOWS\Fonts\ptjhfhlp.dll] [N/A, ]
[C:\WINDOWS\Fonts\edchakae.dll] [N/A, ]
[C:\WINDOWS\Fonts\ozfygbyt.dll] [N/A, ]
[C:\WINDOWS\system32\explore.exe] [N/A, ]
没仔细看,应该还有遗漏,反正是中了木马群,可以考虑先用瑞星的木马群专杀搞下……