发布时间:2012-04-15 01:31:28作者:知识屋
1、用Unlocker 1.8.5(可到down.45it.com下载)删除以下文件,若有些文件没有则跳过:
C:WINDOWSsystem32zxmsewin.dll
C:WINDOWSsystem32mnmhhsrv.dll
C:WINDOWSsystem32zptldsys.dll
C:WINDOWSsystem32nhmxejkl.dll
C:WINDOWSsystem32lofsdjbo.dll
C:WINDOWSsystem32ozfyfbyt.dll
C:WINDOWSsystem32ijdybpaw.dll
C:WINDOWSsystem32yzztnmsn.dll
C:WINDOWSsystem32tisqdtyu.dll
C:WINDOWSsystem32fd233ds4f4.dll
C:WINDOWSsystem32kgfghd.dll
C:WINDOWSsystem32jfdses.dll
C:WINDOWSsystem32mttwfh.dll
C:WINDOWSsystem32hhrdxd.dll
C:WINDOWSsystem32ydggsx.dll
C:WINDOWSsystem32tdfhex.dll
C:WINDOWSsystem32wrqszl.dll
C:WINDOWSsystem32ddserh.dll
C:WINDOWSsystem32sgdewg.dll
C:WINDOWSsystem32rfdswc.dll
C:WINDOWSsystem32jfrwdh.dll
C:WINDOWSsystem32cedafb.dll
C:WINDOWSsystem32zsdgff.dll
C:WINDOWSsystem32wyhesm.dll
C:WINDOWSsystem32pedadt.dll
C:WINDOWSsystem32zycdex.dll
C:Program FilesInternet ExplorerPLUGINSWindows64.Sys
C:WINDOWSsystem32 BCC4.exe
system32drivers5cqt3ta.sys
C:WINDOWSsystem32mfc40u.dll
C:WINDOWSsystem32Com1.1.7WndHook.dll
c:zzz.sys
C:autorun.inf
C:MSDOS.bat
D:autorun.inf
D:MSDOS.bat
E:autorun.inf
E:MSDOS.bat
F:autorun.inf
F:MSDOS.bat
2、用SREng(可到down.45it.com下载)删除以下启动的【注册表】项:
{8C8D1401-A58D-A81C-CD24-A5915C4517C8}
{60940F85-F015-14F1-A05F-F69858AC6D06}
{57AC9076-C898-B098-D098-A18319080975}
{470165F1-9F65-569F-F895-F14F58F41074}
{6A069845-2036-6084-9054-6087502480A6}
{2A698452-C5D8-C584-C256-C264C987C5A2}
{E490415F-65F8-B5C5-D8BA-9405FB12054E}
{48093456-9012-4568-9076-908765467184}
{8C954872-1230-6541-9548-6541025884C8}
{50A8A8C4-EDC9-4ABD-A0A2-2E2418982189}
{81AF1CF6-D1C9-4C6A-AC01-EDE54E71945B}
{000F087F-4378-545F-74FA-37D345AD7A8C}
{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}
{0086DD39-EB8E-4504-A085-AC8A433E34D0}
{0B846B26-BFE6-4E8E-A948-1DB17B77B483}
{F99DEFDD-200B-4410-B572-E90883D527D2}
{A9895933-6636-4281-BC58-EE6DE2AF96E3}
{8C41B7F7-3168-400D-A702-0E7EFE0BA304}
{461D2AB4-29A5-45C2-9134-D52272D3DE38}
{841529CB-7F77-4B99-A895-B5441E0D302F}
{84143967-B645-4BFF-B873-DA1DC886E9A7}
{53D44DB6-E22B-4B17-97D3-572C96CCA6E1}
{EB71E0B3-E97D-4D30-8733-E28266467617}
{5E907A48-400E-4EA8-9792-FFAE052D59E9}
{45AADFAA-DD36-42AB-83AD-0521BBF58C24}
{D47A61B8-0EAB-417F-8DF4-5C949982A2AF}
{8A041F13-A111-12A3-B0CF-F99818AA68A8}
3.恢复IFEO映像挟持.
IFEO映像挟持修复程序((可到down.45it.com下载))
也可以第7点中的AUTORUN软件进行IFEO修复.
4.用SREng删除以下【服务】项(启动项目,服务,WIN32服务应用程序):
[0BCC4 / 0BCC4]
5.用SREng删除以下【驱动程序】项(启动项目,服务,驱动程序):
[5cqt3ta / 5cqt3ta]
[zzz / zzz]
6.用SREng删除以下【浏览器加载项】项:
{D47A61B8-0EAB-417F-8DF4-5C949982A2AF}
{06926B30-424E-4f1c-8EE3-543CD96573DC}
7.使用Autorun病毒防御者全盘杀毒.可清除磁盘每个区的AUTO病毒(可到down.45it.com下载).
最后,重启系统。
2013-07-17
SiZhu.exe、HBKernel32.sys、HBTL.dll、HBmhly.dll、llwzjy08092
如何彻底删除木马小技巧
安全上网软硬兼施 带你走近安全路由的世界
36Otray.exe、sysave.exe、LotusHlp.exe、338448M.exe、GDQQHXI3
关于病毒感染文件的问答
木马“肉鸡控制者”最新变种主要特点
ntfis.exe,qfpUt.exe,WCsQZ.exe,syschunk.dll,BandRes.dll,TaskS
Windows64.Sys、zzz.sys、MSDOS.bat、WndHook.dll、tisqdtyu.dll
走近病毒的世界-SysAnti.exe病毒变种浅析