建议格式化C盘重装操作系统。
手工杀毒的方法很麻烦,所花的时间不比重装系统短,而且不容易清理干净,过程口述起来也比较麻烦。
给你讲一下什么地方出了问题,你就明白了:
病毒添加的注册表项目,要修改(红色项目)或删除:
==================================
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ravmsmon><C:\Program Files\NetMeeting\ravmsmon.exe> []
<ravwlmon><C:\Program Files\NetMeeting\ravwlmon.exe> []
<ravzxmon><C:\Program Files\NetMeeting\ravzxmon.exe> []
<ravytmon><C:\Program Files\NetMeeting\ravytmon.exe> []
<ravmymon><C:\Program Files\NetMeeting\ravmymon.exe> []
<ravtlmon><C:\Program Files\NetMeeting\ravtlmon.exe> []
<ravcqmon><C:\Program Files\NetMeeting\ravcqmon.exe> []
<ravfymon><C:\Program Files\NetMeeting\ravfymon.exe> []
<ravchdmon><C:\Program Files\NetMeeting\ravchdmon.exe> []
<DbgHlp32><C:\WINDOWS\DbgHlp32.exe> []
<avpdj><C:\Program Files\NetMeeting\avpdj.exe> [N/A]
<MsIMMs32><C:\WINDOWS\MsIMMs32.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><raqjapi.dll> [][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{3D47B341-43DF-4563-753F-345FFA3157D3}><C:\WINDOWS\system32\kvmxcma.dll> []
<{14783410-4F90-34A0-7820-3230ACD05F41}><C:\WINDOWS\system32\raqjapi.dll> []
<{2C87A354-ABC3-DEDE-FF33-3213FD7447C2}><C:\WINDOWS\system32\kvdxbma.dll> [N/A]
<{5D83AD9C-3BFC-43F5-979D-2904DBC54A8E}><C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys> []
<{22FAACDE-34DA-CCD4-AB4D-DA34485A3422}><C:\WINDOWS\system32\rsjzbpm.dll> []
<{C5E87A05-F463-4841-B19E-DD3EC3862368}><C:\Program Files\Internet Explorer\IEXPLORE32.Sys> []
<{EE12D60D-AD9A-4095-B839-3BE6862679FD}><C:\Program Files\Internet Explorer\IEXPLORE32.Dat> []
<{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}><C:\Program Files\Internet Explorer\IEXPLORE32.win> []
<{3C87A354-ABC3-DEDE-FF33-3213FD7447C3}><C:\WINDOWS\system32\kvdxcma.dll> []
==================================
流氓软件和病毒添加的服务项目,要删除:
[84D63D20 / 84D63D20][Stopped/Auto Start]
<C:\WINDOWS\system32\63BEAE00.EXE -d><Microsoft Corporation>
[Windows qlsn RunThem / qlsn][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\lgni\vqxs.dll><N/A>
[Distributed Console Manager / SmallCenter][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\spted.dll><N/A>
==================================
流氓软件和病毒添加的驱动程序,要删除:
[agfheege / agfheege][Stopped/System Start]
<\??\C:\WINDOWS\system32\drivers\agfheege.sys><N/A>
[cdnprot / cdnprot][Running/Boot Start]
<\SystemRoot\system32\drivers\cdnprot.sys><中国互联网络信息中心(CNNIC)>
[hsqwcjqw / hsqwcjqw][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\hsqwcjqw.sys><Yahoo! China Corporation>
[iefaachg / iefaachg][Stopped/System Start]
<\??\C:\WINDOWS\system32\drivers\iefaachg.sys><N/A>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\DRIVERS\npf.sys><CACE Technologies>
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\C:\Program Files\Tencent\QQ\npkycryp.sys><N/A>
[SVKP / SVKP][Running/Auto Start]
<\??\C:\WINDOWS\system32\SVKP.sys><AntiCracking>
[yaskp / yaskp][Running/Boot Start]
<\SystemRoot\system32\drivers\yaskp.sys><Copyright (C) yahoo Corporation.>
==================================
流氓软件添加的浏览器加载项,要删除:
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[雅虎助手]
{5D73EE86-05F1-49ed-B850-E423120EC338} <http://cn.zs.yahoo.com/start.htm?source=yzs_icon&btn=yassistnew, N/A>
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, yahoo! china>
[雅虎助手]
{406F94F0-504F-4A40-8DFD-58B0666ABEBD} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, yahoo! china>
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll,
[添加到雅虎订阅(&Y)]
<res://C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll/YRSSMENUEXT, N/A>
[雅虎搜索]
<res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/203, N/A>
==================================
要删除下面这些病毒和流氓软件添加的文件:
[C:\WINDOWS\system32\rsjzbpm.dll] [N/A, ]
[C:\Program Files\NetMeeting\ravfymon.dat] [N/A, ]
[C:\Program Files\NetMeeting\ravcqmon.dat] [N/A, ]
[C:\Program Files\NetMeeting\ravtlmon.dat] [N/A, ]
[C:\Program Files\NetMeeting\ravmymon.dat] [N/A, ]
[C:\Program Files\NetMeeting\ravytmon.dat] [N/A, ]
[C:\Program Files\NetMeeting\ravzxmon.dat] [N/A, ]
[C:\Program Files\NetMeeting\ravwlmon.dat] [N/A, ]
[C:\Program Files\NetMeeting\ravmsmon.dat] [N/A, ]
[C:\Program Files\CNNIC\Cdn\cdnforie.dll] [CNNIC, 2, 0, 0, 2]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
[C:\WINDOWS\system32\kvmxcma.dll] [N/A, ]
[C:\WINDOWS\system32\raqjapi.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\kvdxcma.dll] [N/A, ]
[C:\Program Files\Internet Explorer\IEXPLORE32.Dat] [N/A, ]
[C:\Program Files\Internet Explorer\IEXPLORE32.Sys] [N/A, ]
除了上面的文件外,前面注册表、服务、驱动、浏览器加载项目对应的所有映像文件,都要删除。
==================================
文件关联出现异常,要修复:
.TXT Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.CHM Error. [C:\WINDOWS\hh.exe %1]
.HLP Error. [C:\WINDOWS\winhlp32.exe %1]
.INI Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF Error. [C:\WINDOWS\NOTEPAD.EXE %1]
==================================
Winsock出现异常,C:\WINDOWS\system32\mssql.dll这个文件也要删除,而且要用SRENG扫描工具修复:
Winsock 提供商
MSSQL Tcpip [TCP/IP]
C:\WINDOWS\system32\mssql.dll(, N/A)
MSSQL Tcpip [UDP/IP]
C:\WINDOWS\system32\mssql.dll(, N/A)
==================================
真要手工杀非折腾一天不可,所以建议格式化C盘重装系统。