Xiaoniu.exe木马病毒清除
工具xdelbox 1.6
IFEO
Icesword
sreng
C:\Xiaoniu.exe
C:\autorun.inf
c:\windows\Xiaoniu.exe
C:\windows\system32\Xiaoniu.exe
C:\windows\system32\Xiaoniu2.exe
……………
C:\windows\system32\Xiaoniu34.exe
C:\windows\system32\Xiaoniu35.exe
……………
C:\windows\system32\Xiaoniu55.exe
C:\windows\system32\xiaoniu.txt
C:\WINDOWS\system32\ttVUFVUF1011.exe C:\WINDOWS\system32\ayHADHAD1058.exe C:\WINDOWS\system32\ayJHVJHV1015.exe C:\WINDOWS\system32\ayFKKFKK1055.exe C:\WINDOWS\system32\ayBAIBAI1054.exe
[C:\WINDOWS\system32\msepbe.dll]
[C:\WINDOWS\system32\rhs.dll]
[C:\WINDOWS\system32\kiluw.dll]
[c:\windows\system32\vmvreg32.dll]
C:\Xiaoniu.exe
C:\WINDOWS\System32\Drivers\043298ae.sys
C:\WINDOWS\System32\Drivers\0432b2cd.sys
C:\WINDOWS\System32\Drivers\Changer.sys
C:\WINDOWS\System32\Drivers\i2omgmt.sys
C:\WINDOWS\System32\Drivers\lbrtfdc.sys
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<xiaomm><C:\WINDOWS\system32\xiaoniu.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><mrjhtjd.dll,qrhhb.dll,xdfntt.dll,hgfhk.dll,hjaiq.dll,kduy.dll,frntrn.dll,dnteh.dll,chmfcmh.dll,jwlah.dll,crugd.dll,lariytrz.dll,thurh.dll,mgmgmm.dll,oqrthc.dll,ydgn.dll,dbfb.dll,fjnbv.dll,wmsat.dll,gmnait.dll,hfjg.dll,xdndn.dll,rgfjj.dll,dscef.dll,xfng.dll,njritc.dll,setrhes.dll,cdxbfxdb.dll,xfgnxfn.dll,gjkhj.dll,fxnfnh.dll,bjrvm.dll,ektvm.dll,fehom.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll,zdbdb.dll,rhs.dll,atehhz.dll,gjjte.dll,xgnfn.dll,xfgnhcgfm.dll,serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,xfgnfx.dll,serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,hkfgh.dll,drghszd.dll,fngn.dll,xdhdg.dll,zdbfbd.dll,fjyjy.dll,awef.dll,msepbe.dll,> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{D7B21266-AA85-44b8-B516-3B1A69827400}><> [N/A]
<{29fab913-d0cd-477b-a3f0-3d7c3a90379b}><C:\WINDOWS\system32\ttVUFVUF1011.dll> []
<{08443b98-2313-4616-9080-7c886e965ca6}><C:\WINDOWS\system32\ayHADHAD1058.dll> []
<{fe0ebc25-107f-4fda-ada3-7238573f90ad}><C:\WINDOWS\system32\ayJHVJHV1015.dll> []
<{6ce08af1-5f70-4c1a-8d1a-8aba11619e87}><C:\WINDOWS\system32\ayFKKFKK1055.dll> []
<{3711ff72-e89f-4bdb-ad59-140f5da60968}><C:\WINDOWS\system32\ayBAIBAI1054.dll> []
驱动程序
[043298ae / 043298ae][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\043298ae.sys><N/A>
[0432b2cd / 0432b2cd][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\0432b2cd.sys><N/A>
C:\autorun.inf
d:\autorun.inf
e:\autorun.inf
f:\autorun.inf
!!!!!!!!!!!!!!!!!!!!!病毒体!!!!!
Autorun.inf
[C:\] [D:\]………
[AutoRun]
Open=xiaoniu.exe
Shell\Open=打开(&O)
Shell\Open\Command=xiaoniu.exe
Shell\Open\Default=1
Shell\Explore=资源管理器(&X)
Shell\Explore\Command=xiaoniu.exe
http://hi.baidu.com/hongsehule/blog/item/ead1ab2bbe1931ffe6cd4088.html