电脑中木马 右下角不停的显示“YOUR COMPUTER IS INFECTED,……CLICK HERE TO ……SPYWARE,左面强行加了很多图标,现在C盘已经快暴了
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
+ C:\WINDOWS\System32\kernels32.exe c:\windows\system32\kernels32.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ ControlPanel c:\windows\system32\priva.exe
+ KavStart Kingsoft Antivirus Security Center Kingsoft Corporation c:\kav2005\kavstart.exe
+ Microsoft standard protector c:\windows\inet20066\socks.exe
+ SoundMan Realtek Sound Manager Realtek Semiconductor Corp. c:\windows\soundman.exe
+ System c:\windows\system32\kernels32.exe
+ TkBellExe RealNetworks Scheduler RealNetworks, Inc. c:\program files\common files\real\update_ob\realsched.exe
+ WindowsUpdate c:\windows\system\svchost.exe
+ WindowsUpdateNT c:\windows\system\svwhost.exe
+ xp_system c:\windows\inet20066\services.exe
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run
+ C:\WINDOWS\inet20066\services.exe c:\windows\inet20066\services.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ Windows installer c:\winstall.exe
+ WindowsUpdateNT c:\windows\system\svwhost.exe
+ xp_system c:\windows\inet20066\services.exe
HKLM\System\CurrentControlSet\Services
+ Alive Auto-Update Service c:\program files\antiy labs\alive\alivecenter.exe
+ Ati HotKey Poller ATI External Event Utility EXE Module ATI Technologies Inc. c:\windows\system32\ati2evxx.exe
+ ATI Smart ATI Smart c:\windows\system32\ati2sgag.exe
+ GrayPigeonServer 灰鸽子服务端程序。远程监控管理. File not found: C:\WINDOWS\G_Server.exe
+ KPfwSvc Kingsoft Firewall Service for Windows 2000 Kingsoft Corporation c:\kav2005\kpfwsvc.exe
+ KWatchSvc 金山毒霸文件实时防毒服务程序 Kingsoft Corporation c:\kav2005\kwatch.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
+ DDE c:\windows\system32\birdihuy32.dll
+ Module c:\windows\system32\chp.dll
+ OLE Module c:\windows\system32\bre.dll
+ st3 c:\windows\q48129.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ AlcoholShellEx \
+ Display Panning CPL Extension File not found: deskpan.dll
+ HyperTerminal Icon Ext HyperTerminal Applet Library Hilgraeve, Inc. c:\windows\system32\hticons.dll
+ Shell extensions for file compression \
+ Shell Extensions for RealOne Player RealOne Player Shell Extensions RealNetworks c:\program files\real\realone player\rpshellext.dll
+ WinRAR shell extension d:\program files\winrar\rarext.dll
+ 粉碎文件 File not found: C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\ywiper.dll
+ 加密上下文菜单 \
+ 木马防线 \
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects
+ DragSearch BHO File not found: C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
+ HBO Class Replace Module c:\windows\inet20066\3.00.11.dll
+ IeCatch2 Class jccatch Module Amaze Soft c:\program files\flashget\jccatch.dll
+ Infofo 工具栏 珊瑚虫 Infofo 工具栏 珊瑚虫工作室 泰格工作室 c:\program files\infofo bar\infofobar.dll
+ ThunderIEHelper Class xunleibho BHO c:\windows\system32\xunleibho_v8.dll
+ ZToolbar Activator Class ZToolbar Module c:\windows\system32\ztoolb011.dll
+ {9C5875B8-93F3-429D-FF34-660B206D897A} c:\windows\system32\performent217.dll
+ {B75F75B8-93F3-429D-FF34-660B206D897A} c:\windows\system32\zolker011.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ {B75F75B8-93F3-429D-FF34-660B206D897A} \
HKLM\Software\Microsoft\Internet Explorer\Extensions
+ &FlashGet FlashGet Amaze Soft c:\program files\flashget\flashget.exe
+ @shdoclc.dll,-864 c:\windows\web\related.htm
+ 浩方对战平台 浩方对战平台 上海浩方在线信息技术有限公司 c:\program files\浩方对战平台\gameclient.exe
+ 易趣购物 File not found: http://click2.ad4all.net/url2/urlmanage/url.asp?id=5
Task Scheduler
+ DDD_Install_Program.job remotesetup dudu c:\documents and settings\a\local settings\temp\remotesetup.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
+ AtiExtEvent ATI External Event Utility DLL Module ATI Technologies Inc. c:\windows\system32\ati2evxx.dll
+ st3 c:\windows\q48129.dll