以下操作在下载所需要软件后重起按F8进入安全模式进行
这里官网下载费尔木马强力清除助手,勾选“清除,并抑制文件再次生成”后删除以下文件(一些文件已经不存在,不过不要管,抑制再生删除一次没害处):
http://dl.filseclab.com/down/powerrmv.zipc:\windows\system32\davuqe.dll
c:\windows\system32\nzcbhs.dll
c:\windows\hefcndy.exe
c:\windows\ticisms.exe
c:\windows\cinfonmc.exe
c:\windows\isndntio.exe
c:\windows\fmsiocps.exe
c:\windows\anistio.exe
c:\windows\dionpis.exe
c:\windows\mfchlp64.exe
c:\windows\suqepzru.exe
c:\windows\fmsjhif.exe
c:\windows\fmsbbqi.exe
c:\windows\dbhlp32.exe
c:\windows\tciocp64.exe
c:\windows\ptshell.exe
c:\windows\huifitc.exe
c:\windows\bincdwsa.exe
c:\windows\fmbiost.exe
c:\windows\dndsioc.exe
c:\windows\yuiabct.exe
c:\windows\wipicdec.exe
c:\windows\temp\~wxp2ins.468.tmp
c:\windows\system32\cafesvr
c:\windows\system32\zzxurs
c:\docume~1\admini~1\locals~1\temp\tmp9.tmp
c:\docume~1\admini~1\locals~1\temp\tmp17.tmp
c:\windows\system32\pmkkge
c:\docume~1\admini~1\locals~1\temp\tmp19.tmp
c:\windows\system32\drivers\msosmsp2p32.sys
c:\windows\system32\drivers\msosmsfpfis64.sys
c:\docume~1\admini~1\locals~1\temp\tmp13.tmp
c:\windows\temp\tmp1.tmp
c:\windows\system32\drivers\k9xv.sys
c:\docume~1\admini~1\locals~1\temp\tmp15.tmp
c:\windows\system32\drivers\ilgta9.sys
c:\docume~1\admini~1\locals~1\temp\tmpf.tmp
c:\docume~1\admini~1\locals~1\temp\tmp11.tmp
c:\docume~1\admini~1\locals~1\temp\tmpd.tmp
c:\windows\system32\drivers\npf.sys
c:\program files\internet explorer\plugins\dossys16.sys
c:\documents and settings\all users\application data\microsoft\pctools\pctools.dll
c:\program files\common files\cpush\cpush1.dll
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[hefcndy]
[ticisms]
[cinfonmc]
[isndntio]
[fmsiocps]
[anistio]
[dionpis]
[mfchlp64]
[jscuwqve]
[fmsjhif]
[fmsbbqi]
[dbhlp32]
[tciocp64]
[ptshell]
[huifitc]
[bincdwsa]
[fmbiost]
[dndsioc]
[yuiabct]
[wipicdec]
注意该项[AppInit_DLLs]修改:把<SysDaJHv.dll,fmsiocps.dll,davuqe.dll,msosmhfp01.dll,nzcbhs.dll,msoscqit00.dll,nicozftp01.dll,msosdohs02.dll,msosfmsq01.dll,msosmnsf00.dll,msosjtio01.dll,msosptfs00.dll,wipicdec.dll>修改为<>即清空
[IFEO[360rpt.exe]]
[IFEO[360safe.exe]]
[IFEO[360safebox.exe]]
[IFEO[360tray.exe]]
[IFEO[CCenter.exe]]
[IFEO[KPPMain.exe]]
[IFEO[KWatch.exe]]
[IFEO[QQDoctor.exe]]
[IFEO[QQKav.exe]]
[IFEO[RavMon.exe]]
[IFEO[RavMonD.exe]]
[IFEO[safeboxTray.exe]]
[IFEO[tqat.exe]]
启动项目 -- 服务-- 驱动程序之如下项删除:
[Atixeve23750 / Atixeve23750]
[cafesvr / cafesvr]
[zzxurs / zzxurs]
[zftp / zftp]
[ptfs / ptfs]
[pmkkge / pmkkge]
[ping / ping]
[msp2p32 / msp2p32]
[msfpfis64 / msfpfis64]
[mnsf / mnsf]
[mhfp / mhfp]
[k9xv / k9xv]
[jtio / jtio]
[ilgta / ilgta9]
[fmsq / fmsq]
[dohs / dohs]
[cqit / cqit]
[Netgroup Packet Filter / NPF]
系统修复-- 浏览器加载项之如下项删除:
[] <C:\Program Files\Internet Explorer\PLUGINS\DosSys16.Sys>
[] <C:\Program Files\Internet Explorer\PLUGINS\DosSys16.Sys>
[Info cache] <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll>
[CAdLogic Object] <C:\Program Files\Common Files\CPUSH\cpush1.dll>
做完下载以下软件清理一次并更新杀毒软件至最新进行全盘杀毒一次
清理系统临时文件和IE临时文件夹
http://www.atribune.org/public-beta/ATF-Cleaner.exe 用金山清理专家清理恶意软件
http://www.duba.net/zt/ksc/down.shtml 下载 windows清理助手清理一遍
http://www.arswp.com/download/arswp2/arswp2.zip