异常项目如下:
=========================================
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RsTray><C:\WINDOWS\system32\scvhost.exe> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{1ECE2FCB-C1BB-4706-920C-F4C1076FD155}><C:\WINDOWS\system32\kT2NuqZeGma.dll> []
<{EF6EF2D9-CDC7-481D-B17C-DA8DBA33BB01}><C:\WINDOWS\system32\kW5xUYZjcSnWs.dll> []
<{7A93621D-BFFE-4EB1-AAE1-CD487F429840}><C:\WINDOWS\system32\PkVyCX5kHnftC7BXjt.dll> []
<{3BF06F2A-7AA8-4474-90A2-CFAFC22D43AB}><C:\WINDOWS\fonts\cC8kqzNExNc.fon> []
<{028A997C-4262-4107-BD46-2ABBC6143E8C}><C:\WINDOWS\system32\efc0c52cc1.dll> []
<{76CBCF38-0583-44C7-A1AE-D463DFE625EC}><C:\WINDOWS\system32\skcfujQ5EDN.dll> [File is missing]
<{36AC68E6-0C26-4D39-B98E-54B49DAB6BAA}><C:\WINDOWS\system32\dhDhwS7fFW.dll> []
<{6B74576A-BB20-47B3-AE0A-046B062897D0}><C:\WINDOWS\system32\ACg9ycsarj8y.dll> []
<{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8}><C:\WINDOWS\system32\A1A6BC2E.dll> []
<{C722AD57-35DA-4460-8353-328372F32AB2}><C:\WINDOWS\system32\ufQCU5.dll> []
<{E4814792-EFA3-4C20-93D0-8B130A59F9A8}><C:\WINDOWS\system32\E4814792.dll> []
<{704C3595-DB85-40F6-A601-8D6F346907BD}><C:\WINDOWS\system32\704C3595.dll> []
<{171565E3-F0BB-4FF0-9A42-C9406C79DB78}><C:\WINDOWS\system32\wF87W8XjgDW5Es6tuA.dll> []
<{A0C86020-5935-4B87-B20E-0B656D450264}><C:\WINDOWS\system32\A0C86020.dll> []
<{E88AE11C-26DF-4F4D-8726-C043F513990E}><C:\WINDOWS\system32\yp77Tt3UCG74J.dll> []
<{2EF0D734-21FD-4225-A1A2-BCD296182AAF}><C:\WINDOWS\system32\2EF0D734.dll> []
<{56BC86C7-0692-4F94-A2C1-6CF1DBF8096C}><C:\WINDOWS\system32\56BC86C7.dll> []
<{16886058-6A31-4D53-B4AC-4CC7D2248D69}><C:\WINDOWS\fonts\vwuXtYbhj.fon> []
<{0D267113-499A-4EEF-998D-C45731C1B313}><C:\WINDOWS\system32\VnTU2WAqUcZA6.dll> []
<{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}><C:\WINDOWS\system32\08223B03.dll> []
<{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}><C:\WINDOWS\system32\122B901E.dll> []
<{19250D1E-B733-4F49-BC56-44EFCF3BF650}><C:\WINDOWS\system32\m37tEtTX7Ye5c.dll> []
<{CD95107F-52A5-42A4-9914-18949993E798}><C:\WINDOWS\fonts\tY5UFS434YYd.fon> []
<{CCCA2FB9-2D5D-4481-8BFE-1CDDC458A3F4}><C:\WINDOWS\system32\CCCA2FB9.dll> []
<{4E5CFE74-700B-4A8B-B0BF-A6B47D896C18}><C:\WINDOWS\system32\GrTZqH5SnRhAt.dll> []
<{71C4F360-FF1E-413E-B17A-0CA267A78E97}><C:\WINDOWS\system32\qB5BKZy7vR5m.dll> []
<{08CBFE20-8DC8-4195-B8E2-DD66F860469D}><C:\Program Files\Internet Explorer\PowerJa.ask> [File is missing]
<{E11FB24A-F766-4D0F-ADF5-237958FFA262}><C:\WINDOWS\fonts\f13ERxR2Urh.fon> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<assistse><; > [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<CnsMin>
<helper.dll>
==================================
驱动程序
[CnsStd / CnsStd][Stopped/Auto Start]
<\SystemRoot\System32\drivers\CnsStd.sys><N/A>
[sx / sx][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\sx.ahc><N/A>
[xpt / xpt][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\xpt.ahc><N/A>
==================================
浏览器加载项
[]
{08CBFE20-8DC8-4195-B8E2-DD66F860469D} <C:\Program Files\Internet Explorer\PowerJa.ask, N/A>
[]
{08CBFE20-8DC8-4195-B8E2-DD66F860469D} <C:\Program Files\Internet Explorer\PowerJa.ask, N/A>
==================================
正在运行的进程
[C:\WINDOWS\system32\kT2NuqZeGma.dll] [N/A, ]
[C:\WINDOWS\system32\kW5xUYZjcSnWs.dll] [N/A, ]
[C:\WINDOWS\system32\PkVyCX5kHnftC7BXjt.dll] [N/A, ]
[C:\WINDOWS\fonts\cC8kqzNExNc.fon] [N/A, ]
[C:\WINDOWS\system32\efc0c52cc1.dll] [N/A, ]
[C:\WINDOWS\system32\dhDhwS7fFW.dll] [N/A, ]
[C:\WINDOWS\system32\ACg9ycsarj8y.dll] [N/A, ]
[C:\WINDOWS\system32\A1A6BC2E.dll] [N/A, ]
[C:\WINDOWS\system32\ufQCU5.dll] [N/A, ]
[C:\WINDOWS\system32\E4814792.dll] [N/A, ]
[C:\WINDOWS\system32\704C3595.dll] [N/A, ]
[C:\WINDOWS\system32\wF87W8XjgDW5Es6tuA.dll] [N/A, ]
[C:\WINDOWS\system32\A0C86020.dll] [N/A, ]
[C:\WINDOWS\system32\yp77Tt3UCG74J.dll] [N/A, ]
[C:\WINDOWS\system32\2EF0D734.dll] [N/A, ]
[C:\WINDOWS\system32\56BC86C7.dll] [N/A, ]
[C:\WINDOWS\fonts\vwuXtYbhj.fon] [N/A, ]
[C:\WINDOWS\system32\VnTU2WAqUcZA6.dll] [N/A, ]
[C:\WINDOWS\system32\08223B03.dll] [N/A, ]
[C:\WINDOWS\system32\122B901E.dll] [N/A, ]
[C:\WINDOWS\system32\m37tEtTX7Ye5c.dll] [N/A, ]
[C:\WINDOWS\fonts\tY5UFS434YYd.fon] [N/A, ]
[C:\WINDOWS\system32\CCCA2FB9.dll] [N/A, ]
[C:\WINDOWS\system32\GrTZqH5SnRhAt.dll] [N/A, ]
[C:\WINDOWS\system32\qB5BKZy7vR5m.dll] [N/A, ]
[C:\WINDOWS\fonts\f13ERxR2Urh.fon] [N/A, ]
==================================
计划任务
[已启用] At5.job
rundll32.exe C:\Program Files\Love\qtvuwyxh.dll,uninstall
[已启用] At4.job
rundll32.exe C:\Program Files\Love\qtvuwyxh.dll,uninstall
[已启用] At3.job
rundll32.exe C:\Program Files\Love\qtvuwyxh.dll,uninstall
[已启用] At2.job
rundll32.exe C:\Program Files\Love\qtvuwyxh.dll,uninstall
[已启用] At1.job
rundll32.exe C:\Program Files\Love\qtvuwyxh.dll,uninstall
==================================
比较麻烦。
一是输入法进程c:\windows\system32\ctfmon.exe丢失,需要找个正常的放在c:\windows\system32目录下;
二是有3721等流氓软件残留;
三是木马较多。