Qq Remote Assistance in displaying the recipient's desktop window skew solution & uninstall bonjour Method
A netizen downloaded and installed a software from the Internet, and was reported as a virus by guard 360. Although the 360 guard has been cleared, he is still not at ease, so I can use QQ Remote Assistance to check again.
After the connection is successful, we can see that the desktop windows of netizens are skewed and cannot be operated.
I encountered this problem for the first time. It is estimated that it is related to the display settings of a netizen's computer. I will ask him what the screen resolution is? He said: 1366X768. After changing it to 1024x768, it is normal.
Download pe_xscan to scan logs and analyze the logs. The following suspicious items are found:
Pe_xscan 09-06-21 by Purple endurer
20:44:35
Windows XP Service Pack 3 (5.1.2600)
MSIE: 6.0.2900.5512
Administrator user group
Normal ModeC:/Windows/system32/svchost.exe * 1528 |
C:/program files/Bonjour/mdnsnsp. DLL | 12:42:30 | bonjour | 2003, 2006 | bonjour namespace provider | copyright (c)-Apple Computer, Inc. | 1, 0, 3, 1 | Apple Computer, Inc. |? | Mdnsnsp. dll | mdnsnsp. dll
C:/Windows/system32/spoolsv.exe * 892 |
C:/program files/Bonjour/mdnsnsp. DLL | 12:42:30 | bonjour | 2003, 2006 | bonjour namespace provider | copyright (c)-Apple Computer, Inc. | 1, 0, 3, 1 | Apple Computer, Inc. |? | Mdnsnsp. dll | mdnsnsp. dll
C:/program files/Bonjour/mdnsresponder.exe * 1012 | 12:42:38 | bonjour | 2003, 2006, | bonjour service | copyright (c)-Apple Computer, Inc. | 1, 0, 3, 1 | Apple Computer, Inc. |? | Mdnsresponder.exe
D:/program files/Tencent/QQ/bin/qq.exe * 3524 | 20:15:30
C:/program files/Bonjour/mdnsnsp. DLL | 12:42:30 | bonjour | 2003, 2006 | bonjour namespace provider | copyright (c)-Apple Computer, Inc. | 1, 0, 3, 1 | Apple Computer, Inc. |? | Mdnsnsp. dll | mdnsnsp. dll
O1-hosts: 127.0.0.1 localhost 127.0.0.1 activate.adobe.com
O2-BHO haokanbar browserhelper-{7366d35a-5b70-4a5b-b789-b25fe09b4af3} = C:/program files/Super Rabbit/magicset/haokanbar. dll | 16:36:54
O3-IE Toolbar: haokanbar class-{43869bb3-22fd-4f15-9b46-23820.ba2f4e} = C:/program files/Super Rabbit/magicset/haokanbar. dll | 16:36:54
The existence of IE or Internet Options in o6-hkcu/software/policies/Microsoft/Internet Explorer/control panel may be limited
O23-service: Bonjour Service (#####)-"C:/program files/Bonjour/mdnsresponder.exe" | 12:42:38 | bonjour |, 3, 1 | bonjour service | copyright (c) 2003-2006 Apple Computer, Inc. | 1, 0, 3, 1 | Apple Computer, Inc. |? | Mdnsresponder.exe (automatic)
Google once found that bonjour is included in Photoshop CS, and many netizens said they could not clear it. On Adobe's official website, a command is provided to uninstall it:
"C:/program files/Bonjour/mdnsresponder.exe"-Remove
(See: http://kb2.adobe.com/cps/400/kb400982.html)
The o6 items should be obtained by 360 guardian.