1.这里官网下载费尔木马强力清除助手,勾选“清除,并抑制文件再次生成”后删除以下文件:(不管文件是否存在,删一次没坏处,如果提示文件不存在,不管他,直接继续下面的修复)。
http://dl.filseclab.com/down/powerrmv.zipc:\windows\temp\wmsetup.dll
c:\windows\system32\wzcfsw.dll
c:\windows\system32\rfdswc.dll
c:\windows\system32\mndsfsrv.dll
c:\windows\system32\jfrwdh.dll
c:\windows\system32\wyrsdj.dll
c:\windows\system32\wrqszl.dll
c:\windows\system32\tdggrz.dll
c:\windows\system32\mnmhgsrv.dll
c:\windows\system32\rijxbkin.dll
c:\windows\system32\tisqatyu.dll
c:\windows\system32\yzztjmsn.dll
c:\windows\system32\ozfyebyt.dll
c:\windows\system32\apsgfjba.dll
c:\windows\system32\ypdjgbmp.dll
c:\windows\system32\arjrcler.dll
c:\windows\system32\nhmxcjkl.dll
c:\windows\system32\skqncbib.dll
c:\windows\system32\mndhfdwd.dll
c:\windows\system32\mpmyhapi.dll
c:\windows\system32\pjjxedwd.dll
c:\windows\system32\lassaplo.dll
c:\windows\system32\mndsgsrv.dll
c:\windows\system32\akjsckaq.dll
c:\windows\system32\lijzclit.dll
c:\windows\system32\mpwddapi.dll
c:\windows\system32\mfdesy.dll
c:\windows\system32\oswxdttb.dll
c:\windows\system32\jfdses.dll
c:\windows\system32\pedadt.dll
c:\windows\system32\yzztkmsn.dll
c:\windows\system32\arjreler.dll
c:\windows\system32\pqzfajke.dll
c:\windows\system32\s2da2f323.dll
c:\windows\system32\tfsdmz.dll
c:\windows\system32\mstimewd.dll
c:\windows\system32\erxybloe.dll
c:\windows\apppatch\jview.dll
c:\windows\system32\zgfdet.dll
c:\windows\system32\xyvsqq
c:\windows\system32\sppnkg
c:\windows\system32\qolmjf
c:\windows\system32\drivers\eth8023.sys
c:\windows\system32\ietool.dll
2.删除重启后使用sreng修复下面各项: 启动项目 -- 注册表之如下项删除:
[{6a041f13-a111-12a3-b0cf-f99818aa68a6}]
[{528df602-9541-a985-210a-984a698c6f25}]
[{83ba45af-faaa-cddd-beee-bcde1234ab38}]
[{50940f85-f015-14f1-a05f-f69858ac6d05}]
[{22596546-2036-9451-6058-658402589722}]
[{45aadfaa-dd36-42ab-83ad-0521bbf58c24}]
[{91698482-6555-3666-1222-954784129019}]
[{17ac9076-c898-b098-d098-a18319080971}]
[{81954fac-1023-154f-895a-1458258ad818}]
[{6e6ca8a1-81bc-4707-a54c-f4903dd70bad}]
[{2d698451-2015-6358-9871-2015987452d2}]
[{35671234-7890-abcd-cdef-567801237653}]
[{17dfd111-bf3a-4cb4-adb0-88fcbfe69821}]
注意该项[appinit_dlls]修改:把<hmsdvf.dll,asfjthj.dll,asefry.dll,sdvj.dll,asfhjy.dll,hjukrt.dll,dhdhvv.dll,fgjderg.dll,swegfuj.dll,mhgdfg.dll,sdvfrr.dll,vhsdfg.dll,dger.dll,hjdrg.dll,kergt.dll,gfcfg.dll,reger.dll,hrergh.dll,frntrn.dll,qrhhb.dll,drghszd.dll,fngn.dll,gnfctt.dll,xgnfn.dll,xfgnhcgfm.dll,serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,xfgnfx.dll,serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,xdndn.dll,xdfntt.dll,hgfhk.dll,dnteh.dll,xfng.dll,njritc.dll,chmfcmh.dll,jwlah.dll,gmnait.dll,hfjg.dll,thurh.dll,mgmgmm.dll,oqrthc.dll,sdrfh.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll,zdbdb.dll,ydgn.dll,dbfb.dll,fjnbv.dll,jrhhh.dll,setrhes.dll,cdxbfxdb.dll,xfgnxfn.dll,gjkhj.dll,xdhdg.dll,rhs.dll,mrjhtjd.dll,zdbfbd.dll,fjyjy.dll,fxnfnh.dll,bjrvm.dll,ektvm.dll,ghthhh.dll,yjrfe.dll,dscef.dll,crugd.dll,lariytrz.dll,hjaiq.dll,kduy.dll,hkfgh.dll,awef.dll,dfhsh.dll,ethsh.dll,stehs.dll,sthth.dll,wfhyt.dll,rgghjj.dll,ghjkdr.dll,hfther.dll,ieprot.dll>修改为<>即清空
[{28766e1c-74b0-4417-8c75-f12ae309ef35}]
[{461d2ab4-29a5-45c2-9134-d52272d3de38}]
[{67fd640a-158f-48ac-fd14-1597f14a9776}]
[{841529cb-7f77-4b99-a895-b5441e0d302f}]
[{1e51c0fd-ee36-434b-ad2a-fd1ff3731c38}]
[{f99defdd-200b-4410-b572-e90883d527d2}]
[{4d165a2a-4bc1-4ca8-8299-08e05aaab5a4}]
[{7c8d1401-a58d-a81c-cd24-a5915c4517c7}]
[{25fd6584-698f-bcd2-602c-698745210352}]
[{18093456-9012-4568-9076-908765467181}]
[{a490415f-65f8-b5c5-d8ba-9405fb12054a}]
[{5a069845-2036-6084-9054-6087502480a5}]
[{6fd45a54-9875-698f-e56e-65102358fdf6}]
[{91954fac-1023-154f-895a-1458258ad819}]
[{5c69034a-f45f-d34d-a33a-c33c4d324fc5}]
[{37ac9076-c898-b098-d098-a18319080973}]
[{32023698-6984-8541-9654-698745012523}]
[{6c648541-1025-9650-9057-6541258720c6}]
[{8629ff4f-acdb-5c90-a098-facb3456a268}]
[{54fae856-ad58-20cb-a025-cd4895fa6e45}]
[{2b69874a-c58c-458d-69f0-698f874e41b2}]
[{77fd640a-158f-48ac-fd14-1597f14a9777}]
[{3a908760-8000-4000-a000-9000322145a3}]
[{3c954872-1230-6541-9548-6541025884c3}]
[{45694105-5108-9405-3695-954187462154}]
[{dc3d30ae-0380-4151-8934-ee98a34b0370}]
[{43512378-9874-5641-1025-985420368734}]
[{81af1cf6-d1c9-4c6a-ac01-ede54e71945b}]
[{5e907a48-400e-4ea8-9792-ffae052d59e9}]
[{b490415f-65f8-b5c5-d8ba-9405fb12054b}]
[{7c69034a-f45f-d34d-a33a-c33c4d324fc7}]
[{60a345cd-abcd-efab-cdef-abcd01020306}]
[{a629ff4f-acdb-5c90-a098-facb3456a26a}]
[{875e07b1-0614-43d9-a76e-d76a28ab3d7b}]
[{00180018-0018-0018-0018-00180018bb15}]
[{20909876-4567-3908-4056-909834565102}]
[javaview]
[mstimewd]
[ifeo[360safebox.exe]]
[ifeo[kppmain.exe]]
[ifeo[safeboxtray.exe]]
[{28eb3777-3e23-4e72-8449-a992d09d24c3}]
启动项目 -- 服务-- 驱动程序之如下项删除:
[xyvsqq / xyvsqq]
[sppnkg / sppnkg]
[qolmjf / qolmjf]
[eth8023 / eth8023]
系统修复-- 浏览器加载项之如下项删除:
[快捷工具条3.2] <c:\windows\system32\ietool.dll>
[] <c:\windows\system32\yzztkmsn.dll>
[] <c:\windows\system32\s2da2f323.dll>
[] <c:\windows\system32\yzztjmsn.dll>
[] <c:\windows\system32\ypdjgbmp.dll>
[] <c:\windows\system32\mpmyhapi.dll>
[] <c:\windows\system32\mnmhgsrv.dll>
[] <c:\windows\system32\arjreler.dll>
[] <c:\windows\system32\mndsgsrv.dll>
[] <c:\windows\system32\apsgfjba.dll>
[] <c:\windows\system32\mndhfdwd.dll>
[] <c:\windows\system32\mndsfsrv.dll>
[] <c:\windows\system32\pqzfajke.dll>
[] <c:\windows\system32\arjrcler.dll>
[] <c:\windows\system32\ozfyebyt.dll>
[] <c:\windows\system32\pjjxedwd.dll>
[] <c:\windows\system32\mpwddapi.dll>
[] <c:\windows\system32\oswxdttb.dll>
[] <c:\windows\system32\lijzclit.dll>
[] <c:\windows\system32\akjsckaq.dll>
[] <c:\windows\system32\nhmxcjkl.dll>
[] <c:\windows\system32\skqncbib.dll>
[] <c:\windows\system32\lassaplo.dll>
[] <c:\windows\system32\rijxbkin.dll>
[] <c:\windows\system32\erxybloe.dll>
[] <c:\windows\system32\tisqatyu.dll>
[快捷工具条3.2] <c:\windows\system32\ietool.dll>
[] <c:\windows\system32\s2da2f323.dll>
[] <c:\windows\system32\yzztjmsn.dll>
[] <c:\windows\system32\ypdjgbmp.dll>
[] <c:\windows\system32\mpmyhapi.dll>
[] <c:\windows\system32\mnmhgsrv.dll>
[] <c:\windows\system32\arjreler.dll>
[] <c:\windows\system32\mndsgsrv.dll>
[] <c:\windows\system32\apsgfjba.dll>
[] <c:\windows\system32\mndhfdwd.dll>
[] <c:\windows\system32\mndsfsrv.dll>
[] <c:\windows\system32\pqzfajke.dll>
[] <c:\windows\system32\arjrcler.dll>
[] <c:\windows\system32\ozfyebyt.dll>
[] <c:\windows\system32\pjjxedwd.dll>
[] <c:\windows\system32\mpwddapi.dll>
[] <c:\windows\system32\oswxdttb.dll>
[] <c:\windows\system32\lijzclit.dll>
[] <c:\windows\system32\akjsckaq.dll>
[] <c:\windows\system32\nhmxcjkl.dll>
[] <c:\windows\system32\skqncbib.dll>
[] <c:\windows\system32\lassaplo.dll>
[] <c:\windows\system32\rijxbkin.dll>
[] <c:\windows\system32\erxybloe.dll>
[] <c:\windows\system32\tisqatyu.dll>
做完下载以下软件清理一次并更新杀毒软件至最新进行全盘杀毒一次
清理系统临时文件和ie临时文件夹
http://www.atribune.org/public-beta/atf-cleaner.exe 用金山清理专家清理恶意软件
http://www.duba.net/zt/ksc/down.shtml 下载 windows清理助手清理一遍
http://www.arswp.com/download/arswp2/arswp2.zip大部分文件已经不存在 不过就当清理下吧
c:\windows\temp\wmsetup.dll 这个文件一定要删除