12   2  /  2  页   跳转

版主帮忙````

回复:版主帮忙````

按顺序操作,先去删文件!

另外删除服务或驱动的时候会弹出提示让你选是、否、取消,这时候先别忙着操作,注意看一下提示内容,应该不难发现如果确定要删除的话这里应该是点“否”的!
gototop
 

回复: 版主帮忙````



引用:
原帖由 zouyanglin 于 2008-4-30 21:09:00 发表
c:\windows\system32\drivers\2f90.sys
c:\windows\system32\drivers\xt2bw5x30h.sys
c:\documents and settings\all users\application data\microsoft\office\system\ntptdb.sys
c:\windows\system32\drivers\1......

你按照我上面给你那个流程去做,不是让你手动找到文件删除,要用XDelBox
gototop
 

回复:版主帮忙````

对不起啊``是我没看清楚 那些Win32服务应用程序 驱动程序已经删了 那些文件我是用XDelBox删的 没有手动去删
现在就只有那些注册表删用sreng不掉 要不要浏览的方式 找到文件后手动删除?
gototop
 

回复: 版主帮忙````



引用:
原帖由 zouyanglin 于 2008-4-30 21:29:00 发表
对不起啊``是我没看清楚 那些Win32服务应用程序 驱动程序已经删了 那些文件我是用XDelBox删的 没有手动去删
现在就只有那些注册表删用sreng不掉 要不要浏览的方式 找到文件后手动删除?

附件附件:

文件名:SREngLOG3.log
下载次数:95
文件类型:application/octet-stream
文件大小:
上传时间:2008-4-30 21:31:42
描述:最新扫描

gototop
 

回复:版主帮忙````

利用SRE 
打开启动项目——服务——Win32服务,删除以下服务:
[Google Updater Service / gusvc][Stopped/Manual Start]
  <><N/A>
打开启动项目——注册表项目 删除以下项目:
最下面所有IFEO相关:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\60e41.exe]
    <IFEO[60e41.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\an006.exe]
    <IFEO[an006.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AtiSrv.exe]
    <IFEO[AtiSrv.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\d03.exe]
    <IFEO[d03.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dbghlp32.exe]
    <IFEO[dbghlp32.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dotnetfc1.exe]
    <IFEO[dotnetfc1.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dxdiags.exe]
    <IFEO[dxdiags.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\frhhusyk.exe]
    <IFEO[frhhusyk.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\haZl0oh.exe]
    <IFEO[haZl0oh.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kbfz.exe]
    <IFEO[kbfz.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Kvsc3.exE]
    <IFEO[Kvsc3.exE]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kzdh@webbrowser-lyrics_2012.exe]
    <IFEO[kzdh@webbrowser-lyrics_2012.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msyaxk.exe]
    <IFEO[msyaxk.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\peer.exe]
    <IFEO[peer.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Performance.exe]
    <IFEO[Performance.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rpcs.exe]
    <IFEO[Rpcs.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll.exe]
    <IFEO[rundll.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sashost.exe]
    <IFEO[sashost.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scvhost.exe]
    <IFEO[scvhost.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\servciesa.exe]
    <IFEO[servciesa.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\servciesb.exe]
    <IFEO[servciesb.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\servciesc.exe]
    <IFEO[servciesc.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\servciesd.exe]
    <IFEO[servciesd.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\server1.exe]
    <IFEO[server1.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\servet.exe]
    <IFEO[servet.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SSDPDiscovv.exe]
    <IFEO[SSDPDiscovv.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svch0st.exe]
    <IFEO[svch0st.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchosts.exe]
    <IFEO[svchosts.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svsh0st.exe]
    <IFEO[svsh0st.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sysloader.exe]
    <IFEO[sysloader.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\temp3.exe]
    <IFEO[temp3.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wiasoisao.exe]
    <IFEO[wiasoisao.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wincom.exe]
    <IFEO[wincom.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winnir.exe]
    <IFEO[winnir.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WinserviceExten.exe]
    <IFEO[WinserviceExten.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WSockDrv32.exe]
    <IFEO[WSockDrv32.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xin.exe]
    <IFEO[xin.exe]><C:\windows\system32\svchost.exe>  [(Verified)Microsoft Windows Publisher]
删除后 再利用冰刃 查看上面删除的文件 是否还有痕迹
冰刃下载地址:http://www.skycn.com/soft/37828.html
在下面的文件中查看 确认是否删除
如果有病毒问题,请大家与我联系邮箱是1987noodle0158@sina.com
我的博客是http://blog.sina.com.cn/ufovirus
gototop
 

回复:版主帮忙````

那些注册表已经删了 只剩Google Updater Service / gusvc重起后又有
最后还有两个请求要麻烦
再帮我看看日志 看哪些是没用的 多余的 可以删掉
还有 桌面上的文件名称的背景总有颜色 如何设为透明?见下图(黑色的)
gototop
 

回复: 版主帮忙````



引用:
原帖由 zouyanglin 于 2008-4-30 22:20:00 发表
那些注册表已经删了 只剩Google Updater Service / gusvc重起后又有
最后还有两个请求要麻烦
再帮我看看日志 看哪些是没用的 多余的 可以删掉
还有 桌面上的文件名称的背景总有颜色 如何设为透明?见下图(黑色的......

附件附件:

文件名:SREngLOG4.log
下载次数:72
文件类型:application/octet-stream
文件大小:
上传时间:2008-4-30 22:20:57
描述:log

gototop
 

回复:版主帮忙````

最后谢谢各位的帮忙 lqqk7 UFO不幸外人 tjcum210210
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT