原帖由 永远的小雨 于 2008-6-16 23:35:00 发表
我升级瑞星杀毒过程中扫描的.
D:\System Volume Information\_restore{C12758D0-1287-42FC-B587-8675CE191B0E}\RP1\A0000052.exe病毒名称Worm.Magistr.g
D:\System Volume Information\_restore{C12758D0-1287-42FC-B587-8675CE191B
1.建议使用XDelBox删除以下文件(XDelBox1.7支持奥运版下载) 下载地址:www.dodudou.com)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。

c:\windows\system32\mndhedwd.dll
c:\windows\apppatch\jview.dll
c:\windows\system32\oswxdttb.dll
c:\windows\system32\lijzclit.dll
c:\windows\system32\pjjxedwd.dll
c:\windows\system32\lassaplo.dll
c:\windows\system32\tfsdmz.dll
c:\windows\system32\fsrgeb.dll
c:\windows\system32\ddserh.dll
c:\windows\system32\wyrsdj.dll
c:\windows\system32\pedadt.dll
c:\windows\system32\apsgejba.dll
c:\windows\system32\drivers\eth8023.sys
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[{5C648541-1025-9650-9057-6541258720C5}] <C:\WINDOWS\system32\mndhedwd.dll>
[JavaView] <C:\WINDOWS\AppPatch\Jview.dll>
[{43512378-9874-5641-1025-985420368734}] <C:\WINDOWS\system32\oswxdttb.dll>
[{3C954872-1230-6541-9548-6541025884C3}] <C:\WINDOWS\system32\lijzclit.dll>
[{54FAE856-AD58-20CB-A025-CD4895FA6E45}] <C:\WINDOWS\system32\pjjxedwd.dll>
[{2B69874A-C58C-458D-69F0-698F874E41B2}] <C:\WINDOWS\system32\lassaplo.dll>
[{875E07B1-0614-43D9-A76E-D76A28AB3D7B}] <C:\WINDOWS\system32\tfsdmz.dll>
[{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6}] <C:\WINDOWS\system32\fsrgeb.dll>
[{A9895933-6636-4281-BC58-EE6DE2AF96E3}] <C:\WINDOWS\system32\ddserh.dll>
[{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}] <C:\WINDOWS\system32\wyrsdj.dll>
[{5E907A48-400E-4EA8-9792-FFAE052D59E9}] <C:\WINDOWS\system32\pedadt.dll>
[{5FD45A54-9875-698F-E56E-65102358FDF5}] <C:\WINDOWS\system32\apsgejba.dll>
注意该项[AppInit_DLLs]修改:把<tuker.dll,ujkwet.dll,asefry.dll,sdvj.dll,asfhjy.dll,hjukrt.dll,dhdhvv.dll,asfjthj.dll,hmsdvf.dll,jrhhh.dll,sdrfh.dll,vhsdfg.dll,dger.dll,hjdrg.dll,kergt.dll,gfcfg.dll,reger.dll,hrergh.dll,frntrn.dll,qrhhb.dll,drghszd.dll,fngn.dll,gnfctt.dll,xgnfn.dll,xfgnhcgfm.dll,serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,xfgnfx.dll,serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,xdndn.dll,xdfntt.dll,hgfhk.dll,dnteh.dll,xfng.dll,njritc.dll,chmfcmh.dll,jwlah.dll,gmnait.dll,hfjg.dll,thurh.dll,mgmgmm.dll,oqrthc.dll,ghkrg.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll,zdbdb.dll,ydgn.dll,dbfb.dll,fjnbv.dll,yukevg.dll,setrhes.dll,cdxbfxdb.dll,xfgnxfn.dll,gjkhj.dll,xdhdg.dll,rhs.dll,mrjhtjd.dll,zdbfbd.dll,fjyjy.dll,fxnfnh.dll,bjrvm.dll,ektvm.dll,ghthhh.dll,yjrfe.dll,dscef.dll,crugd.dll,lariytrz.dll,hjaiq.dll,kduy.dll,hkfgh.dll,awef.dll,dfhsh.dll,ethsh.dll,stehs.dll,sthth.dll,wfhyt.dll,rgghjj.dll,ghjkdr.dll,hfther.dll,ieprot.dll>修改为<>即清空
启动项目 -- 服务-- 驱动程序之如下项删除:
[eth8023 / eth8023] <\SystemRoot\system32\drivers\eth8023.sys>
系统修复-- 浏览器加载项之如下项删除:
[] <C:\WINDOWS\system32\apsgejba.dll>
[] <C:\WINDOWS\system32\mndhedwd.dll>
[] <C:\WINDOWS\system32\pjjxedwd.dll>
[] <C:\WINDOWS\system32\oswxdttb.dll>
[] <C:\WINDOWS\system32\lijzclit.dll>
[] <C:\WINDOWS\system32\lassaplo.dll>
[] <C:\WINDOWS\system32\apsgejba.dll>
[] <C:\WINDOWS\system32\mndhedwd.dll>
[] <C:\WINDOWS\system32\pjjxedwd.dll>
[] <C:\WINDOWS\system32\oswxdttb.dll>
[] <C:\WINDOWS\system32\lijzclit.dll>
[] <C:\WINDOWS\system32\lassaplo.dll>
系统修复-- HOSTS文件--重置host文件
1:修复以上重启电脑之后用一:清理系统临时文件和IE临时文件夹
http://www.atribune.org/public-beta/ATF-Cleaner.exe 2:建议用windows清理助手清理一下系统。
windows清理助手下载页面:
http://www.arswp.com/download.html