这也要网上找,都是老一套,一看就知道…………
这是让别人帮我分析的
1.建议使用XDelBox删除以下文件:(
XDelBox1.7下载)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
c:\windows\system32\svchst1.exe
c:\windows\system32\winlib .dll
c:\windows\system32\ywg32.dll
c:\y.exe
i:\msdos.pif
d:\msdos.pif
c:\windows\system32\c0n1me.exe
c:\windows\system32\vmvreg32.dll
c:\windows\system32\ywtlgfl.dll
c:\program files\internet explorer\plugins\winsys16.sys
c:\documents and settings\all users\「开始」菜单\程序\启动\sys2.pif
c:\windows\system32\wuauc1t.exe
c:\docume~1\lenovo\locals~1\temp\~78.tmp
c:\windows\system32\drivers\acpidisk.sys
c:\autorun.inf
d:\autorun.inf
e:\autorun.inf
f:\autorun.inf
h:\autorun.inf
i:\autorun.inf
c:\MSDOS.PIF
d:\MSDOS.PIF
e:\MSDOS.PIF
f:\MSDOS.PIF
h:\MSDOS.PIF
i:\MSDOS.PIF
2.删除重启后使用SREng修复下面各项:
启动项目 -- 注册表之如下项删除:
[{1AB1F65A-964F-4AE7-B254-05146A0E602E}] <C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys>
注意该项[AppInit_DLLs]修改:把<ghjdtry.dll,dgxsrr.dll,fdght.dll,rgghjj.dll,sefawe.dll,frntrn.dll,qrhhb.dll,drghszd.dll,fngn.dll,gjjte.dll,xgnfn.dll,xfgnhcgfm.dll,serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,xfgnfx.dll,serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,xdndn.dll,xdfntt.dll,hgfhk.dll,dnteh.dll,xfng.dll,njritc.dll,chmfcmh.dll,jwlah.dll,gmnait.dll,hfjg.dll,thurh.dll,mgmgmm.dll,oqrthc.dll,hktrre.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll,zdbdb.dll,ydgn.dll,dbfb.dll,fjnbv.dll,fghshj.dll,setrhes.dll,cdxbfxdb.dll,xfgnxfn.dll,gjkhj.dll,xdhdg.dll,rhs.dll,mrjhtjd.dll,zdbfbd.dll,fjyjy.dll,fxnfnh.dll,bjrvm.dll,ektvm.dll,rdthr.dll,rgfjj.dll,dscef.dll,crugd.dll,lariytrz.dll,hjaiq.dll,kduy.dll,hkfgh.dll,awef.dll,dfhsh.dll,ethsh.dll,stehs.dll,sthth.dll,wfhyt.dll,sperls.dll,>修改为<>即清空
[explorer] <`.vbe>
[IFEO[360rpt.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[360safe.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[360tray.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[ANTIARP.exe]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[Ast.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[AutoRunKiller.exe]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[AvMonitor.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[AVP.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[CCenter.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[Frameworkservice.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[GFUpd.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[GuardField.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[IceSword.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[Iparmor.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[KASARP.exe]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[KRegEx.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[KVMonxp.kxp]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[KVSrvXP.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[KVWSC.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[Mmsk.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[Navapsvc.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[Nod32kui.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[QQDOCTOR.EXE]] <C:\WINDOWS\system32\wuauc1t.exe>
[IFEO[RAS.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[Regedit.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[Runiep.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[VPC32.exe]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[VPTRAY.exe]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[WOPTILITIES.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[Wuauclt.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
[IFEO[~.EXE]] <C:\WINDOWS\system32\c0n1me.exe>
启动项目 -- 启动文件夹之如下项删除:
[sys2] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\sys2.pif>
启动项目 -- 服务-- 驱动程序之如下项禁用:
[sys_hen / sys_hen] <\??\C:\DOCUME~1\lenovo\LOCALS~1\Temp\~78.tmp>
[acpidisk / acpidisk] <\??\C:\WINDOWS\system32\drivers\acpidisk.sys>
系统修复-- 浏览器加载项之如下项删除:
[] <C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys>
[] <C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys>
系统修复--高级修复--重置winsock
下载临时文件清理工具清理一下临时文件
http://www.dodudou.com/down/ATF-Cleaner-cn.exe
下载windows清理助手V2.7清理恶意软件
http://www.arswp.com/download/arswp2/arswp2.zip
删除磁盘中的APPINIT_DLL中所对应的DLL文件和 `.vbe
补充个专杀
[
本帖最后由 无尽藏海 于 2008-5-8 09:26 编辑 ]