1.这里官网下载费尔木马强力清除助手,勾选“清除,并抑制文件再次生成”后删除以下文件:(不管文件是否存在,删一次没坏处,如果提示文件不存在,不管他,直接继续下面的修复)。
http://dl.filseclab.com/down/powerrmv.zipc:\windows\system32\winlib .dll
c:\windows\system32\sofie.dll
c:\windows\system32\internat.exe
c:\windows\system32\dpvvoxmh.dll
c:\windows\system32\msobjstl.dll
c:\windows\system32\mstimewd.dll
c:\windows\system32\adsntzt.dll
c:\windows\system32\apsghjba.dll
c:\windows\system32\wmpuiqhx.dll
c:\windows\system32\rasdlgcq.dll
c:\windows\system32\cliconfgzx.dll
c:\windows\system32\zxmsewin.dll
c:\windows\system32\mndhfdwd.dll
c:\windows\system32\dispexcb.dll
c:\windows\system32\wloxygir.dll
c:\windows\system32\catsrvwl.dll
c:\windows\system32\kbdswjr.dll
c:\windows\system32\tscfgwmijxsj.dll
c:\windows\system32\slbiopfs2.dll
c:\windows\system32\imgutilhx2.dll
c:\03ac44d422a4ff12.dat
c:\1046e7cc3d301c8a.dat
c:\250f0b38b1cf4f03.dat
c:\26fd49585b37e1b3.dat
c:\windows\system32\drivers\2c05p.sys
c:\30fb8f608edd110f.dat
c:\3367b4e4219fb856.dat
c:\3555f304c757cf85.dat
c:\3a07661029682c3a.dat
c:\3c435428b114a5bb.dat
c:\47e22858f2663695.dat
c:\5df3ca84d035c526.dat
c:\60ddd76cb98ec134.dat
c:\67267930b07e568a.dat
c:\726e3df8a2212726.dat
c:\8f9d78b4fd21284a.dat
c:\9df62260014572b5.dat
c:\windows\system32\drivers\comint32.sys
c:\b315553490be6574.dat
c:\docume~1\admini~1\locals~1\temp\tmpc.tmp
c:\windows\\systemroot\system32\drivers\lhpgojqb.sys
c:\f9adfeccad4cd342.dat
c:\ee663a04b4f6aa6e.dat
c:\e75200e47a4a4478.dat
c:\d636224cad612860.dat
c:\d0e94f50a97ba9c0.dat
c:\windows\system32\drivers\cibjurs82.sys
c:\cc37dc4415424bec.dat
c:\windows\system32\drivers\bgcdjceg.sys
c:\bf7fc0c0eb470a07.dat
c:\documents and settings\all users\application data\microsoft\office\userdata\g73hmfep2o.dll
c:\program files\yok\adblock.dll
c:\windows\system32\macromed\download\download.dll
c:\windows\downloaded program files\downloader.dll
c:\windows\downloaded program files\safeinput4jh.dll
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[internat.exe] <internat.exe>
[{00070007-0007-0007-0007-00070007BB15}]
[{00170017-0017-0017-0017-00170017BB15}]
[{00180018-0018-0018-0018-00180018BB15}]
[{00010001-0001-0001-0001-00010001BB15}]
[{8FD45A54-9875-698F-E56E-65102358FDF8}]
[{00270027-0027-0027-0027-00270027BB15}]
[{00230023-0023-0023-0023-00230023BB15}]
[{00050005-0005-0005-0005-00050005BB15}]
[{8A041F13-A111-12A3-B0CF-F99818AA68A8}]
[{6C648541-1025-9650-9057-6541258720C6}]
[{00060006-0006-0006-0006-00060006BB15}]
[{00150015-0015-0015-0015-00150015BB15}]
[{00040004-0004-0004-0004-00040004BB15}]
[{00120012-0012-0012-0012-00120012BB15}]
[{00330033-0033-0033-0033-00330033BB15}]
[{00250025-0025-0025-0025-00250025BB15}]
[{00300030-0030-0030-0030-00300030BB15}]
[dpvvoxmh.dll]
[msobjstl.dll]
[mstimewd.dll]
[adsntzt.dll]
[wmpuiqhx.dll]
[rasdlgcq.dll]
[cliconfgzx.dll]
[dispexcb.dll]
[wloxygir.dll]
[catsrvwl.dll]
[kbdswjr.dll]
[tscfgwmijxsj.dll]
[slbiopfs2.dll]
[imgutilhx2.dll]
启动项目 -- 服务-- 驱动程序之如下项删除:
[03ac44d422a4ff12 / 03ac44d422a4ff12]
[1046e7cc3d301c8a / 1046e7cc3d301c8a]
[250f0b38b1cf4f03 / 250f0b38b1cf4f03]
[26fd49585b37e1b3 / 26fd49585b37e1b3]
[2c05 / 2c05p]
[30fb8f608edd110f / 30fb8f608edd110f]
[3367b4e4219fb856 / 3367b4e4219fb856]
[3555f304c757cf85 / 3555f304c757cf85]
[3a07661029682c3a / 3a07661029682c3a]
[3c435428b114a5bb / 3c435428b114a5bb]
[47e22858f2663695 / 47e22858f2663695]
[5df3ca84d035c526 / 5df3ca84d035c526]
[60ddd76cb98ec134 / 60ddd76cb98ec134]
[67267930b07e568a / 67267930b07e568a]
[726e3df8a2212726 / 726e3df8a2212726]
[8f9d78b4fd21284a / 8f9d78b4fd21284a]
[9df62260014572b5 / 9df62260014572b5]
[RAS Asynchronous Media Driver / AsyncMac]
[b315553490be6574 / b315553490be6574]
[acpidisk / acpidisk]
[acpidisk / acpidisk]
[PciHardDisk / PciHardDisk]
[PciHardDisk / PciHardDisk]
[ntptdb / ntptdb]
[ntptdb / ntptdb]
[MS / MS]
[lhpgojqb / lhpgojqb]
[f9adfeccad4cd342 / f9adfeccad4cd342]
[ee663a04b4f6aa6e / ee663a04b4f6aa6e]
[e75200e47a4a4478 / e75200e47a4a4478]
[d636224cad612860 / d636224cad612860]
[d0e94f50a97ba9c0 / d0e94f50a97ba9c0]
[cibjurs82 / cibjurs82]
[cc37dc4415424bec / cc37dc4415424bec]
[bgcdjceg / bgcdjceg]
[bf7fc0c0eb470a07 / bf7fc0c0eb470a07]
系统修复-- 浏览器加载项之如下项删除:
[] <C:\WINDOWS\system32\mndhfdwd.dll>
[BHO5] <C:\WINDOWS\system32\sofie.dll>
[InceHelper Class] <C:\Documents and Settings\All Users\Application Data\Microsoft\Office\USERDATA\g73hmfeP2O.dll>
[YOKHttpFilter Class] <C:\Program Files\yok\adblock.dll>
[BHO5] <C:\WINDOWS\system32\sofie.dll>
[InceHelper Class] <C:\Documents and Settings\All Users\Application Data\Microsoft\Office\USERDATA\g73hmfeP2O.dll>
[] <C:\WINDOWS\system32\mndhfdwd.dll>
[] <C:\WINDOWS\system32\macromed\download\Download.dll>
[DLoader Class] <C:\WINDOWS\Downloaded Program Files\downloader.dll>
[Submit Class] <C:\WINDOWS\Downloaded Program Files\safeInput4jh.dll>
做完下载以下软件清理一次并更新杀毒软件至最新进行全盘杀毒一次
清理系统临时文件和IE临时文件夹
http://www.atribune.org/public-beta/ATF-Cleaner.exe 用金山清理专家清理恶意软件
http://www.duba.net/zt/ksc/down.shtml 下载 windows清理助手清理一遍
http://www.arswp.com/download/arswp2/arswp2.zip