EndurerOriginal
1Version
Yesterday, shortly after a netizen reinstalled Windows XP, he found that it would take half a minute to start the operation after the desktop was started. It was not normal! Let me check it.
Pe_xscan is used to scan logs and the following suspicious items are found:
/------------
Pe_xscan by Purple endurer
Windows XP Service Pack 1 (5.1.2600)
Administrator user group
O2-BHO wmpdrm-{0e674588-66b7-4e19-9d0e-2053b800f69f}-C:/Windows/system32/wmpdrm. dll
O2-BHO bandie class-{77fef28e-eb96-44ff-b511-3185dea48697}-C:/progra ~ 1/Baidu/BAR/baidubar. dll
O3-IE Toolbar:-{B580CF65-E151-49C3-B73F-70B13FCA8E86}-C:/progra ~ 1/Baidu/BAR/baidubar. dll
O4-HKLM/../run: [spoolsv] C:/Windows/system32/spoolsv/spoolsv.exe-printer
------------/
Two rogue software programs were originally at fault:
File Description: C:/Windows/system32/spoolsv/spoolsv.exe
Attribute: ---
Language: Chinese (China)
File version: 2, 0, 0, 3
Note: The auxiliary tool of maxcompute Browser
Copyright: Copyright (c) 2006
Remarks: auxiliary tool of maxcompute Browser
Product Version: 2, 0, 0, 3
Product Name: axun browser auxiliary tool
Company: Guangzhou aoxun Information Technology Co., Ltd.
Legal trademark: maxcompute (TM)
Internal name: spoolsv.exe
Source File Name: spoolsv.exe
Creation Time: 16:15:26
Modification time: 16:15:26
Access time:
Size: 45056 bytes, 44.0 KB
MD5: ca0e9f2948604660bd94d012d65d24a8
File Description: C:/Windows/system32/wmpdrm. dll
Attribute: ---
Language: Chinese (China)
File version: 2, 2, 0, 2
Note: The auxiliary tool of maxcompute Browser
Copyright: Copyright (c) 2006
Remarks: auxiliary tool of maxcompute Browser
Product Version: 2, 2, 0, 2
Product Name: axun browser auxiliary tool
Company Name: allsum info. Tech. Ltd.
Legal trademark: maxcompute (TM)
Internal name: wmpdrm. dll
Source File Name: wmpdrm. dll
Creation Time: 15:46:28
Modification time: 15:46:28
Access time:
Size: 172032 bytes, 168.0 KB
MD5: 20e6b0e65c694d3765b2c8dedb9d0c6f
All of them are notorious ......
Fix:
(For the following operations, refer to [System Restoration series] basic operation indexes.
Http://endurer.bokee.com/2591241.html)
Uninstall Baidu souba
Restart your computer to safe Mode
Use WinRAR to delete the following files and folders:
C:/Windows/system32/wmpdrm. dll
C:/Windows/system32/1116
C:/Windows/system32/bakcfs
C:/Windows/system32/mscache
C:/Windows/system32/msibm
C:/Windows/system32/msicn
C:/Windows/system32/spoolsv
Use hijackthis to scan and fix suspicious items in the pe_xscanlog column.
Clear temporary ie folders and C:/Windows/prefetch folders