New face of the robot dog: 0x0000008e blue screen Error 2
EndurerOriginal
2008-03-17 th1Version
(Continued: new face of the BOT: 0x0000008e blue screen Error 1 when logging on to the server)
Iii. Repair
First, download fileinfo, bat_do to the http://purpleendurer.ys168.com to extract, package, and delete suspicious files in the log.
Next, open registry editor and delete
O26-ifeo: ras.exe-> ntsd-d
The corresponding registry key.
In this way, we can start the rising Kaka Security Assistant.
After startup, N rogue software is automatically scanned and cleared.
In [advanced functions]-> [plug-in management and uninstallation], uninstall o24 items
In [advanced functions]-> [system enable item management], click [logon item] on the left, find the project corresponding to the O4 item on the right, right-click, select Delete from the pop-up menu.
In [advanced functions]-> [system enable item management], click [Application initialization dynamic Connection Library] on the left, find the o20 project on the right, right-click, select Delete from the pop-up menu.
In [advanced functions]-> [system enable item management], click [service items] and [Driver] on the left, find the project corresponding to o23 on the right, right-click, select Delete from the pop-up menu.
In addition, the system service items of Jiangmin kV are found in the log and manually deleted.
In [advanced functions]-> [system enable item management], click [Resource Manager plug-in] on the left, find the o25 project on the right, right-click, select Delete from the pop-up menu
In [advanced functions]-> [system enable item management], click [Application hijacking item] on the left, find the project corresponding to O26 on the right, right-click, select Delete from the pop-up menu.
Use WinRAR to delete windows temporary folders, ie temporary folders, and files that can be deleted in D:/Windows/prefetch.
Download Rising Antivirus assistant to http://endurer.ys168.com, use rising online free scan on the C:/Windows folder was killed, and the results are exported as follows:
12:41:56 Rising Antivirus assistant Windows XP Service Pack 2 (5.1.2600)
File Name virus name
C:/Windows/system32/Drivers/wxptdi. sys Trojan. win32.mnless. zyq
C:/Windows/system32/Drivers/mselk. sys rootkit. win32.gamehack. GFA
C:/Windows/system32/gdjzi32.dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/hookhelp. sys rootkit. win32.keylogger. m
C:/Windows/system32/msosmhfp00.dll. Del> upack0.34 backdoor. win32.gameol.
C:/Windows/system32/foxitxcwow. dll. Del> upack0.34 Trojan. psw. win32.sunonline. Mr
C:/Windows/system32/hhhcompress. dll. Del> upx_c Trojan. psw. win32.sunonline. Mr
C:/Windows/system32/msosdohs00.dll. Del> upack0.34 Trojan. psw. win32.xyonline. ACD
C:/Windows/system32/tsqc. dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/mnauygniqaixnaij. dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/wsockdrv32.dll. Del Trojan. psw. win32.so2game. m
C:/Windows/system32/msosmhfp01.dll. Del> upack0.34 backdoor. win32.gameol.
C:/Windows/system32/8f2da66b. EXE. Del> upack0.39 Trojan. immsg. win32.tbmsg. ykq
C:/Windows/system32/slcs. dll. Del> upack0.34 Trojan. psw. win32.roconline. kJ
C:/Windows/system32/winsvr32.dll. Del Trojan. psw. win32.gameol. mjj
C:/Windows/system32/duygnef. dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/24.exe>> upack0.34 Trojan. psw. win32f. AHC
C:/Windows/system32/taijoad. dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/lotushlp. dll. Del Trojan. psw. win32.gamesonline. Qu
C:/Windows/system32/oqnauhc. dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/msnnebb32.dll. Del> fsg2.0 Trojan. psw. win32.sunonline. MQ
C:/Windows/system32/vfqnsxzx. dll. Del> upack0.34 Trojan. psw. win32.sunonline. MQ
C:/Windows/system32/dbghlp32.dll. Del Trojan. psw. win32.so2game. k
C:/Windows/system32/fyom. dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/gnolnait. dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/qyiurwawm. dll. Del> upack0.34 Trojan. psw. win32.sunonline. mt
C:/Windows/system32/mswmgog32.dll. Del> upx_c Trojan. psw. win32.sunonline. Mu
C:/Windows/system32/atgnehz. dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/ddljex. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/zmajnx. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/lywdwr. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/jxvtvq. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/ifsfgr. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/pbfkkr. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/vfxfla. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/kqihbp. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/uwlcdk. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/ezyyii. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/bqxxil. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/bexjss. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/fnosgo. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/ynelcd. dll. Del Trojan. psw. win32.qqgame. gen
C:/Windows/system32/gddh3i32. dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/gdqqhxi32.dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/gdwli32.dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/gdqqsgi32.dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/gddji32.dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/gdzxi32.dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/gdcqi32.dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/gddhi32.dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/gdm1_2.dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/gdmhi32.dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
C:/Windows/system32/gdmoyi32.dll. Del> upack0.34 Trojan. psw. win32.gameol. mjf
Most of them are account theft Trojans ......