引用: |
【梦想成为高手的贴子】猫叔,看下我的日志啊,超级难搞的病毒啊.. http://forum.ikaka.com/topic.asp?board=28&artid=8402724 ……………… |
1、用XDELBOX删除下列文件:
C:\WINDOWS\system32\249C9D0F.DLL
C:\WINDOWS\system32\LYMANGR.DLL
C:\WINDOWS\system32\LotusHlp.dll
C:\WINDOWS\system32\qzjyrd.dll
C:\WINDOWS\system32\szpilt.dll
C:\WINDOWS\system32\nykqlp.dll
C:\WINDOWS\system32\aarlqc.dll
C:\WINDOWS\system32\vgszrh.dll
C:\WINDOWS\system32\axyzyu.dll
C:\WINDOWS\system32\qfwics.dll
C:\WINDOWS\system32\msccrt.dll
C:\WINDOWS\system32\kiitnd.dll
C:\WINDOWS\system32\aqtbum.dll
C:\WINDOWS\338448WL.DLL
C:\WINDOWS\system32\kyetre.dll
C:\WINDOWS\system32\MsIMMs32.dll
C:\WINDOWS\system32\SHQMANGR.DLL
C:\Autorun.inf
C:\auto.exe
D:\Autorun.inf
D:\auto.exe
E:\Autorun.inf
E:\auto.exe
F:\Autorun.inf
F:\auto.exe
2、重启后,用SRENG删除下列注册表内容:
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<GenProtect><C:\WINDOWS\GenProtect.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<NVDispDrv><C:\WINDOWS\NVDispDRV.EXE> []
<MsPrint32D><C:\WINDOWS\MsPrint32D.exe> []
<AVPSrv><C:\WINDOWS\AVPSrv.exE> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<upxdnd><C:\WINDOWS\upxdnd.exe> []
<WinSysM><C:\WINDOWS\338448M.exe> [N/A]
<LotusHlp><C:\WINDOWS\LotusHlp.exe> []
<DbgHlp32><C:\WINDOWS\DbgHlp32.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<WinSysW><C:\WINDOWS\338448L.exe> [N/A]
<PTSShell><C:\WINDOWS\PTSShell.exe> []
<MsIMMs32><C:\WINDOWS\MsIMMs32.exE> []
<360Tray><c:\windows\services.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<MSDEG32><LYLoader.exe> []
<MSDWG32><LYLoadbr.exe> [N/A]
<MSDCG32 ><LYLeador.exe> [N/A]
<MSDOG32><LYLoador.exe> [N/A]
<MSDSG32><LYLoadar.exe> [N/A]
<MSDMG32><LYLoadmr.exe> []
<MSDHG32><LYLoadhr.exe> [N/A]
<MSDQG32><LYLoadqr.exe> [N/A]
启动文件夹
[腾讯QQ]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\WINDOWS\system32\mypc.exe [Microsoft Corporation]><N>
服务
[FD715B3 / FD715B3][Stopped/Auto Start]
<C:\WINDOWS\system32\72C448D6.EXE -k><>
[WindowsDeamonSSL_ALU / WindowsDeamonSSL_ALU][Running/Auto Start]
<C:\WINDOWS\csrssddv.exe><N/A>
[winsslilyday / winsslilyday][Running/Auto Start]
<C:\WINDOWS\winfbsd.exe><N/A>