【回复“0神龙0”的帖子】
汗!!还是昨天哪些啊!
1、病毒文件(用XDELBOX删除):
C:\WINDOWS\system32\msplrct.dll
C:\WINDOWS\system32\qdshm.dll
C:\WINDOWS\system32\opx7zv02q.dll
C:\WINDOWS\system32\sqmapi32.dll
C:\WINDOWS\system32\addrzthelp.dll
C:\WINDOWS\system32\addrmshelp.dll
C:\WINDOWS\system32\addrgjhelp.dll
C:\WINDOWS\system32\addrzxhelp.dll
C:\WINDOWS\system32\rarjbpi.dll
C:\WINDOWS\system32\GenProtect.dll
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\kvdxcma.dll
C:\WINDOWS\system32\kaqhfzy.dll
C:\WINDOWS\system32\AVPSrv.dll
C:\WINDOWS\system32\addrwdhelp.dll
C:\WINDOWS\system32\kvdxsbma.dll
C:\WINDOWS\system32\dllMergeDict.dll
C:\WINDOWS\System32\DRIVERS\rfvevcn7.sys
C:\WINDOWS\system32\playasp.exe
C:\WINDOWS\IEnet.exe
C:\WINDOWS\system32\drivers\mxdispdr.sys
2、病毒添加的注册表内容(重启后用SRENG删除):
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><kvdxsbma.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{3C87A354-ABC3-DEDE-FF33-3213FD7447C3}><C:\WINDOWS\system32\kvdxcma.dll> []
<{2598FF45-DA60-F48A-BC43-10AC47853D52}><C:\WINDOWS\system32\rarjbpi.dll> []
<{2D561258-45F3-A451-F908-A258458226D2}><C:\WINDOWS\system32\kvdxsbma.dll> []
<{67D81718-1314-5200-2597-587901018076}><C:\WINDOWS\system32\kaqhfzy.dll> []
服务
[IENET / IENEY][Stopped/Disabled]
<C:\WINDOWS\IEnet.exe><N/A>
[ServiceJsHelp / ServiceJsHelp][Stopped/Auto Start]
<C:\WINDOWS\system32\playasp.exe><N/A>
驱动程序
[mxdispdr / mxdispdr][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\mxdispdr.sys><N/A>
[rfvevcn / rfvevcn7][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\rfvevcn7.sys><N/A>