KV2007查杀病毒后桌面无显示?原来是网游盗号木马惹的祸1

KV2007查杀病毒后桌面无显示?原来是网游盗号木马惹的祸1

endurer 原创
2008-02-18 第1

  一位网友安装了从网上下载的游戏,KV2007查杀出了一些病毒。重启电脑后桌面一片空白,没有任务栏,也没有图标。让偶帮忙检修。
  当 windows 的“壳”程序 explorer.exe没有正常加载,就会出现这种故障。
  按Ctrl + Shift+ Esc 打开任务管理器,选择菜单:文件-》新任务(运行...),在弹出的对话框中输入cmd.exe,确定。这样就打开了一个命令提示符窗口,输入命令:

dir c:/windows/explorer.exe

没有列出explorer.exe的信息,原来是explorer.exe这个文件不见了……

  用命令:

copy c:/windows/system32/dllcache/explorer.exe c:/windows

  将c:/windows/system32/dllcache中的 explorer.exe 复制到 c:/windows,然后输入命令:

explorer.exe

这下任务栏、图标都出来了。

升级KV然后全面查杀病毒。
同时下载 pe_xscan 扫描 log,发现如下可疑项(进程模块部分有省略):

/===
pe_xscan 08-01-29 by Purple Endurer
2000-2-16 19:22:27
Windows XP Service Pack 2(5.1.2600)
管理员用户组

[System Process] * 0
  C:/WINDOWS/SYSTEM32/CUHAD.DLL | 2000-2-14 23:56:8
  C:/WINDOWS/SYSTEM32/OQNAUHC.DLL | 2000-2-14 23:55:15
  C:/WINDOWS/SYSTEM32/PAHZIJ.DLL | 2000-2-14 23:56:42
  C:/WINDOWS/SYSTEM32/SVE.DLL | 2000-2-14 23:55:56
  C:/WINDOWS/SYSTEM32/XJXR.DLL | 2000-2-14 23:55:44
  C:/WINDOWS/SYSTEM32/KILUW.DLL | 2000-2-14 23:55:32
  C:/WINDOWS/SYSTEM32/SAUHAD.DLL | 2000-2-14 23:56:21
  C:/WINDOWS/SYSTEM32/ZADNEW.DLL | 2000-2-14 23:55:41
  C:/WINDOWS/SYSTEM32/SHAPROC.DLL | 2000-2-16 19:1:33
C:/WINDOWS/SYSTEM32/ALG.EXE* 336 | 2005-12-15 8:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Application Layer Gateway Service | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | ALG.exe | ALG.exe
  C:/WINDOWS/SYSTEM32/CUHAD.DLL | 2000-2-14 23:56:8
  C:/WINDOWS/SYSTEM32/OQNAUHC.DLL | 2000-2-14 23:55:15
  C:/WINDOWS/SYSTEM32/PAHZIJ.DLL | 2000-2-14 23:56:42
  C:/WINDOWS/SYSTEM32/SVE.DLL | 2000-2-14 23:55:56
  C:/WINDOWS/SYSTEM32/XJXR.DLL | 2000-2-14 23:55:44
  C:/WINDOWS/SYSTEM32/KILUW.DLL | 2000-2-14 23:55:32
  C:/WINDOWS/SYSTEM32/SAUHAD.DLL | 2000-2-14 23:56:21
  C:/WINDOWS/SYSTEM32/ZADNEW.DLL | 2000-2-14 23:55:41
C:/WINDOWS/SYSTEM32/CONIME.EXE* 3752 | 2005-12-15 8:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | Console IME | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | Console | CONIME.EXE
  C:/WINDOWS/SYSTEM32/CUHAD.DLL | 2000-2-14 23:56:8
  C:/WINDOWS/SYSTEM32/OQNAUHC.DLL | 2000-2-14 23:55:15
  C:/WINDOWS/SYSTEM32/PAHZIJ.DLL | 2000-2-14 23:56:42
  C:/WINDOWS/SYSTEM32/SVE.DLL | 2000-2-14 23:55:56
  C:/WINDOWS/SYSTEM32/XJXR.DLL | 2000-2-14 23:55:44
  C:/WINDOWS/SYSTEM32/KILUW.DLL | 2000-2-14 23:55:32
  C:/WINDOWS/SYSTEM32/SAUHAD.DLL | 2000-2-14 23:56:21
  C:/WINDOWS/SYSTEM32/ZADNEW.DLL | 2000-2-14 23:55:41
  C:/WINDOWS/SYSTEM32/SHAPROC.DLL | 2000-2-16 19:1:33
C:/WINDOWS/EXPLORER.EXE* 568 | 2005-12-15 8:0:0 | Microsoft(R) Windows(R) Operating System | 6.00.2900.2180 | Windows Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | explorer | EXPLORER.EXE
  C:/WINDOWS/SYSTEM32/SHAPROC.DLL | 2000-2-16 19:1:33
C:/WINDOWS/SYSTEM32/CTFMON.EXE* 2264 | 2005-12-15 8:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | CTF Loader | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | CTFMON | CTFMON.EXE
  C:/WINDOWS/SYSTEM32/CUHAD.DLL | 2000-2-14 23:56:8
  C:/WINDOWS/SYSTEM32/OQNAUHC.DLL | 2000-2-14 23:55:15
  C:/WINDOWS/SYSTEM32/PAHZIJ.DLL | 2000-2-14 23:56:42
  C:/WINDOWS/SYSTEM32/SVE.DLL | 2000-2-14 23:55:56
  C:/WINDOWS/SYSTEM32/XJXR.DLL | 2000-2-14 23:55:44
  C:/WINDOWS/SYSTEM32/KILUW.DLL | 2000-2-14 23:55:32
  C:/WINDOWS/SYSTEM32/SAUHAD.DLL | 2000-2-14 23:56:21
  C:/WINDOWS/SYSTEM32/ZADNEW.DLL | 2000-2-14 23:55:41
  C:/WINDOWS/SYSTEM32/SHAPROC.DLL | 2000-2-16 19:1:33
C:/PROGRAM FILES/JIANGMIN/ANTIVIRUS/KVXP.KXP* 3076 | 2000-1-22 16:55:4 | Jiangmin Antivirus Software | 10, 0, 0, 600 | KvXP Control Module | Copyright (C) 2006 Jiangmin Co., Ltd. All rights reserved | 1, 0, 7, 1102 | Jiangmin Co.,Ltd| ? | KvxpCM | KvXpCm.exe
  C:/WINDOWS/SYSTEM32/CUHAD.DLL | 2000-2-14 23:56:8
  C:/WINDOWS/SYSTEM32/OQNAUHC.DLL | 2000-2-14 23:55:15
  C:/WINDOWS/SYSTEM32/PAHZIJ.DLL | 2000-2-14 23:56:42
  C:/WINDOWS/SYSTEM32/SVE.DLL | 2000-2-14 23:55:56
  C:/WINDOWS/SYSTEM32/XJXR.DLL | 2000-2-14 23:55:44
  C:/WINDOWS/SYSTEM32/KILUW.DLL | 2000-2-14 23:55:32
  C:/WINDOWS/SYSTEM32/SAUHAD.DLL | 2000-2-14 23:56:21
  C:/WINDOWS/SYSTEM32/ZADNEW.DLL | 2000-2-14 23:55:41
  C:/WINDOWS/SYSTEM32/SHAPROC.DLL | 2000-2-16 19:1:33
C:/WINDOWS/SYSTEM32/DLLHOST.EXE* 2468 | 2005-12-15 8:0:0 | Microsoft? Windows? Operating System | 5.1.2600.2180 | COM Surrogate | ? Microsoft Corporation. All rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | dllhost.exe | dllhost.exe
  C:/WINDOWS/SYSTEM32/CUHAD.DLL | 2000-2-14 23:56:8
  C:/WINDOWS/SYSTEM32/OQNAUHC.DLL | 2000-2-14 23:55:15
  C:/WINDOWS/SYSTEM32/PAHZIJ.DLL | 2000-2-14 23:56:42
  C:/WINDOWS/SYSTEM32/SVE.DLL | 2000-2-14 23:55:56
  C:/WINDOWS/SYSTEM32/XJXR.DLL | 2000-2-14 23:55:44
  C:/WINDOWS/SYSTEM32/KILUW.DLL | 2000-2-14 23:55:32
  C:/WINDOWS/SYSTEM32/SAUHAD.DLL | 2000-2-14 23:56:21
  C:/WINDOWS/SYSTEM32/ZADNEW.DLL | 2000-2-14 23:55:41
  C:/WINDOWS/SYSTEM32/SHAPROC.DLL | 2000-2-16 19:1:33
C:/PROGRAM FILES/INTERNET EXPLORER/IEXPLORE.EXE* 2680 | 2005-12-15 8:0:0 | Microsoft(R) Windows(R) Operating System | 6.00.2900.2180 | Internet Explorer | (C) Microsoft Corporation. All rights reserved. | 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Microsoft Corporation| ? | iexplore | IEXPLORE.EXE
  C:/WINDOWS/SYSTEM32/SHAPROC.DLL | 2000-2-16 19:1:33

O2 - BHO - {6167F471-EF2B-41DD-A5E5-C26ACDB5C096} -C:/PROGRAM FILES/INTERNET EXPLORER/PLUGINS/WINSYS8K.SYS

O4 - HKLM/../RUN: [SHAPROC]C:/WINDOWS/SHAPROC.EXE
O4 - HKLM/../POLICIES/EXPLORER/RUN: [EZIVAUNSP] EZIVAUNSP.EXE

O20 - APPINIT_DLLS = UTGNEHZ.DLL,nauhgnem.dll,auhad.dll,nuygnef.dll,uohsom.dll,uyom.dll,gnolnait.dll,ijiq.dll,ijougiemnaw.dll,iemnaw.dll,niluw.dll,naixuhz.dll,xhtd.dll,oadgnohiac.dll,iqnauhc.dll,nahzij.dll,gnefnaib.dll,gsqq.dll,3auhad.dll,naijoad.dll,aixauh.dll,xhqq.dll,QQ.dll,hjxr.dll,zqhs.dll,oadnew.dll,dgzg.dll,hz.dll,2ty.dll,jsfg.dll,rj.dll,fmxh.dll,jmx.dll,wtwx.dll,ddtj.dll,fz.dll,gnaixnauhuoyizqq.dll,gnaixnauhqq.dll,2nauygniqaixnaij.dll,naijihzeuyouhz.dll,uyomielnux.dll,vlihzouhgnfe.dll,sfhx.dll,eve.dll,jsqc.dll,wtiemnaw.dll,dqncj.dll


O23 - 服务: MSEQSY (MSEQSY) -C:/WINDOWS/SYSTEM32/DRIVERS/MSACPE.SYS (手动)
O23 - 服务: MSERTK (MSERTK) - SYSTEM32/DRIVERS/MSYECP.SYS (自动)
O23 - 服务: MSSKYE (MSSKYE) - SYSTEM32/DRIVERS/MSACLUE.SYS (自动)
O23 - 服务: NPF (NETGROUP PACKET FILTER) - SYSTEM32/DRIVERS/NPF.SYS | WinPcap Netgroup Packet Filter Driver | 3, 1, 0, 27 | npf | Copyright ? 2005 CACE Technologies. Copyright ? 2003-2005 NetGroup, Politecnico di Torino. | 3, 1, 0, 27 | CACE Technologies | | NPF + TME | npf.sys(手动)
O23 - 服务: UXOHOJTY (UXOHOJTY) - SYSTEM32/DRIVERS/UXOHOJTY.SYS | ? | 1.6.9.1084| ?| ? | 1.8.0.1096 | Yahoo! China Corporation| ?| ?| ?(引导)

O24 - SHLEXECHOOK: [0] - {D7B21266-AA85-44B8-B516-3B1A69827400} = 0
===/

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值