12   1  /  2  页   跳转

[求助] (已解决)wo zai 我在等待!

(已解决)wo zai 我在等待!

急求解答!
今日电脑中毒,使用瑞星杀N多次!可越杀越多!每次都是如此报告清除病毒种类列表:
病毒: Trojan.PSW.Win32.GameOL.nvl
病毒: Win32.ExplorerDL.i     
病毒: Trojan.Win32.AvKiller.co
病毒: Trojan.PSW.Win32.GameOL.oqb
病毒: Packer.Win32.Upack.a   
病毒: Trojan.PSW.Win32.GameOL.oof
病毒: Trojan.PSW.Win32.GameOL.org
病毒: Trojan.PSW.Win32.GameOL.osi
病毒: Trojan.PSW.Win32.GameOL.oek
MAC 地址:00:1F:C6:31:64:E9
用户来源:互联网
软件版本:20.52.62
  每次杀了都不起作用!还有下面
C:\WINDOWS\system32\wklsdd.dll
C:\WINDOWS\system32\ddserh.dll
C:\WINDOWS\system32\wcomipek.exe>>upx_c
C:\WINDOWS\system32\zycdex.dll
C:\WINDOWS\system32\sgdewg.dll
C:\WINDOWS\system32\wrqszl.dll
C:\WINDOWS\system32\fghdd.dll>>6a
C:\WINDOWS\system32\dfxh.dll
C:\WINDOWS\system32\vfdh.dll
C:\WINDOWS\system32\cvnghk.dll>>6a
C:\System Volume Information\_restore{824A4BF4-E434-4939-BA01-F5B357A73190}\RP14\A0014853.DLL>>6a
C:\System Volume Information\_restore{824A4BF4-E434-4939-BA01-F5B357A73190}\RP14\A0014854.DLL>>6a
说清除失败!
  急求高手!该怎么办?难道一定要重装系统!???在线等!谢谢!

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)

附件附件:

文件名:SREngLOG.log
下载次数:126
文件类型:application/octet-stream
文件大小:
上传时间:2008-7-13 22:44:49
描述:log

附件附件:

文件名:SREng2LOG.log
下载次数:134
文件类型:application/octet-stream
文件大小:
上传时间:2008-7-14 0:14:45
描述:log

最后编辑rfds 最后编辑于 2008-07-18 11:32:47
分享到:
gototop
 

回复: wo zai 我在等待!

1.建议使用XDelBox删除以下文件
XDelBox下载见附件
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。

c:\windows\system32\hrafh.dll
c:\windows\system32\nmsdjh.dll
c:\windows\system32\xdhuk.dll
c:\windows\system32\zdfgf.dll
c:\windows\system32\tdggrz.dll
c:\windows\system32\tdfhex.dll
c:\windows\system32\rfdswc.dll
c:\windows\system32\mtewdh.dll
c:\windows\system32\dndsaf.dll
c:\windows\system32\wklsdd.dll
c:\windows\system32\jfrwdh.dll
c:\windows\system32\fmcvxy.dll
c:\windows\system32\ddserh.dll
c:\windows\system32\wrqszl.dll
c:\windows\system32\sgdewg.dll
c:\windows\system32\ravext.dll
c:\windows\system32\shlhook.dll
c:\windows\system32\mfdesy.dll

2.删除重启后使用SREng修复下面各项:

    启动项目 -- 注册表之如下项删除:
[{EB71E0B3-E97D-4D30-8733-E28266467617}]    <>
[{189F087F-4378-405F-85FA-37D955AD7A8C}]    <C:\WINDOWS\system32\mtewdh.dll>
[{461D2AB4-29A5-45C2-9134-D52272D3DE38}]    <C:\WINDOWS\system32\rfdswc.dll>
[{0B846B26-BFE6-4E8E-A948-1DB17B77B483}]    <C:\WINDOWS\system32\tdfhex.dll>
[{4D165A2A-4BC1-4CA8-8299-08E05AAAB5A4}]    <C:\WINDOWS\system32\tdggrz.dll>
[{45AADFAA-DD36-42AB-83AD-0521BBF58C24}]    <>
[{259BF3CF-194D-4FE6-9ADB-DE6544B098B6}]    <C:\WINDOWS\system32\dndsaf.dll>
[{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}]    <>
注意该项[AppInit_DLLs]修改:把<nmsdjh.dll,hrafh.dll,bsnfhs.dll,gaffg.dll,snszh.dll,zdhere.dll,klsf.dll,jsdfa.dll,hjsz.dll,cgfhr.dll,aghmxd.dll,sdfrbt.dll,jkzsgf.dll,dghagc.dll,dfgwag.dll,fgjd.dll,xfnh.dll,bgyu.dll,xdrhcj.dll,zsrdygx.dll,dfhvk.dll,xdfthjh.dll,cvbtfs.dll,cgydj.dll,zsdgrgh.dll,fghdd.dll,bgcjty.dll,dbgj.dll,xcfgh.dll,cvnghk.dll,vgxdcg.dll,chjg.dll,vnfxd.dll,nbmfu.dll,xdbjy.dll,vbjxbnm.dll,xgngj.dll,cxvbh.dll,fgjt.dll,cnbv.dll,cvnhk.dll,vgjzrg.dll,cvjdfh.dll,sdfhk.dll,gmnait.dll,xdbnm.dll,xbnft.dll,myuf.dll,hkxddrh.dll,aserg.dll,zdfgf.dll,bnmdgh.dll,bxdfh.dll,cncft.dll,cfjzsxn.dll,dfbghj.dll,dgbzd.dll,nhjsd.dll,hjmasd.dll,xbfhxd.dll,bngyjuf.dll,xdgxr.dll,bnmft.dll,xcvgu.dll,szggfj.dll,zsggixd.dll,bnhugk.dll,xdhuk.dll,dxgjgfy.dll,fgjderg.dll,asfhjy.dll,swegfuj.dll,cxfhf.dll,hjukrt.dll,dhdhvv.dll,vdfthjk.dll,xdfrg.dll,zsgjfh.dll,cvbyj.dll,nmxdt.dll,bhdryn.dll,nbkfy.dll,xsdjd.dll,xuxdg.dll,nmdgkn.dll,xdhts.dll,vcnyd.dll,zsdth.dll,>修改为<>即清空
[{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}]    <C:\WINDOWS\system32\wklsdd.dll>
[{841529CB-7F77-4B99-A895-B5441E0D302F}]    <C:\WINDOWS\system32\jfrwdh.dll>
[{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7}]    <C:\WINDOWS\system32\fmcvxy.dll>
[{A9895933-6636-4281-BC58-EE6DE2AF96E3}]    <C:\WINDOWS\system32\ddserh.dll>
[{F99DEFDD-200B-4410-B572-E90883D527D2}]    <C:\WINDOWS\system32\wrqszl.dll>
[{F99DEFDD-200B-4410-B572-E90883D527D2}]    <C:\WINDOWS\system32\wrqszl.dll>
[{8C41B7F7-3168-400D-A702-0E7EFE0BA304}]    <C:\WINDOWS\system32\sgdewg.dll>
[{32CD708B-60A7-4C00-9377-D73EAA495F0F}]    <C:\WINDOWS\system32\RavExt.dll>
[{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}]    <C:\WINDOWS\system32\shlhook.dll>
[{DC3D30AE-0380-4151-8934-EE98A34B0370}]    <C:\WINDOWS\system32\mfdesy.dll>

附件附件:

下载次数:134
文件类型:application/octet-stream
文件大小:
上传时间:2008-7-13 22:52:57
描述:rar

gototop
 

回复: wo zai 我在等待!

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><nmsdjh.dll,hrafh.dll,bsnfhs.dll,gaffg.dll,snszh.dll,zdhere.dll,klsf.dll,jsdfa.dll,hjsz.dll,cgfhr.dll,aghmxd.dll,sdfrbt.dll,jkzsgf.dll,dghagc.dll,dfgwag.dll,fgjd.dll,xfnh.dll,bgyu.dll,xdrhcj.dll,zsrdygx.dll,dfhvk.dll,xdfthjh.dll,cvbtfs.dll,cgydj.dll,zsdgrgh.dll,fghdd.dll,bgcjty.dll,dbgj.dll,xcfgh.dll,cvnghk.dll,vgxdcg.dll,chjg.dll,vnfxd.dll,nbmfu.dll,xdbjy.dll,vbjxbnm.dll,xgngj.dll,cxvbh.dll,fgjt.dll,cnbv.dll,cvnhk.dll,vgjzrg.dll,cvjdfh.dll,sdfhk.dll,gmnait.dll,xdbnm.dll,xbnft.dll,myuf.dll,hkxddrh.dll,aserg.dll,zdfgf.dll,bnmdgh.dll,bxdfh.dll,cncft.dll,cfjzsxn.dll,dfbghj.dll,dgbzd.dll,nhjsd.dll,hjmasd.dll,xbfhxd.dll,bngyjuf.dll,xdgxr.dll,bnmft.dll,xcvgu.dll,szggfj.dll,zsggixd.dll,bnhugk.dll,xdhuk.dll,dxgjgfy.dll,fgjderg.dll,asfhjy.dll,swegfuj.dll,cxfhf.dll,hjukrt.dll,dhdhvv.dll,vdfthjk.dll,xdfrg.dll,zsgjfh.dll,cvbyj.dll,nmxdt.dll,bhdryn.dll,nbkfy.dll,xsdjd.dll,xuxdg.dll,nmdgkn.dll,xdhts.dll,vcnyd.dll,zsdth.dll,>  []
改为
<AppInit_DLLs><>

删除启动项
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
下的注册表项目及文件
    <{DC3D30AE-0380-4151-8934-EE98A34B0370}><C:\WINDOWS\system32\mfdesy.dll>  [File is missing]
    <{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}><C:\WINDOWS\system32\wklsdd.dll>  [File is missing]
    <{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}><>  [N/A]
    <{259BF3CF-194D-4FE6-9ADB-DE6544B098B6}><C:\WINDOWS\system32\dndsaf.dll>  []
    <{45AADFAA-DD36-42AB-83AD-0521BBF58C24}><>  [N/A]
    <{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll>  [File is missing]
    <{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7}><C:\WINDOWS\system32\fmcvxy.dll>  [File is missing]
    <{4D165A2A-4BC1-4CA8-8299-08E05AAAB5A4}><C:\WINDOWS\system32\tdggrz.dll>  []
    <{A9895933-6636-4281-BC58-EE6DE2AF96E3}><C:\WINDOWS\system32\ddserh.dll>  [File is missing]
    <{0B846B26-BFE6-4E8E-A948-1DB17B77B483}><C:\WINDOWS\system32\tdfhex.dll>  []
    <{F99DEFDD-200B-4410-B572-E90883D527D2}><C:\WINDOWS\system32\wrqszl.dll>  [File is missing]
    <{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgdewg.dll>  [File is missing]
    <{461D2AB4-29A5-45C2-9134-D52272D3DE38}><C:\WINDOWS\system32\rfdswc.dll>  []
    <{189F087F-4378-405F-85FA-37D955AD7A8C}><C:\WINDOWS\system32\mtewdh.dll>  []
    <{EB71E0B3-E97D-4D30-8733-E28266467617}><>  [N/A]
gototop
 

回复 2F 没有眼泪 的帖子

请问是把[{189F087F-4378-405F-85FA-37D955AD7A8C}]  改写成  <C:\WINDOWS\system32\mtewdh.dll>???还是把[{189F087F-4378-405F-85FA-37D955AD7A8C}]  直接删除?我菜鸟,不懂!谢谢!
gototop
 

回复:wo zai 我在等待!

直接删除掉。。如果改写的我会说改写。。嘿嘿
清除成功后请再上SRENG日志
gototop
 

回复 5F 没有眼泪 的帖子

ha哈哈!谢谢你们拉!我上了你看看!整遭了!花了我一天时间!啥子瑞星嘛!杀杀毒越杀越多!想换杀毒软件了!
gototop
 

回复:wo zai 我在等待!

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><nmsdjh.dll,hrafh.dll,bsnfhs.dll,gaffg.dll,snszh.dll,zdhere.dll,klsf.dll,jsdfa.dll,hjsz.dll,cgfhr.dll,aghmxd.dll,sdfrbt.dll,jkzsgf.dll,dghagc.dll,dfgwag.dll,fgjd.dll,xfnh.dll,bgyu.dll,xdrhcj.dll,zsrdygx.dll,dfhvk.dll,xdfthjh.dll,cvbtfs.dll,cgydj.dll,zsdgrgh.dll,fghdd.dll,bgcjty.dll,dbgj.dll,xcfgh.dll,cvnghk.dll,vgxdcg.dll,chjg.dll,vnfxd.dll,nbmfu.dll,xdbjy.dll,vbjxbnm.dll,xgngj.dll,cxvbh.dll,fgjt.dll,cnbv.dll,cvnhk.dll,vgjzrg.dll,cvjdfh.dll,sdfhk.dll,gmnait.dll,xdbnm.dll,xbnft.dll,myuf.dll,hkxddrh.dll,aserg.dll,zdfgf.dll,bnmdgh.dll,bxdfh.dll,cncft.dll,cfjzsxn.dll,dfbghj.dll,dgbzd.dll,nhjsd.dll,hjmasd.dll,xbfhxd.dll,bngyjuf.dll,xdgxr.dll,bnmft.dll,xcvgu.dll,szggfj.dll,zsggixd.dll,bnhugk.dll,xdhuk.dll,dxgjgfy.dll,fgjderg.dll,asfhjy.dll,swegfuj.dll,cxfhf.dll,hjukrt.dll,dhdhvv.dll,vdfthjk.dll,xdfrg.dll,zsgjfh.dll,cvbyj.dll,nmxdt.dll,bhdryn.dll,nbkfy.dll,xsdjd.dll,xuxdg.dll,nmdgkn.dll,xdhts.dll,vcnyd.dll,zsdth.dll,>  [N/A]
改为<AppInit_DLLs><>!!!!!!!!不听话。。。。。。。。。。。。。。
gototop
 

回复: wo zai 我在等待!

启动项目 -- 注册表之如下项删除:
注意该项[AppInit_DLLs]修改:把<nmsdjh.dll,hrafh.dll,bsnfhs.dll,gaffg.dll,snszh.dll,zdhere.dll,klsf.dll,jsdfa.dll,hjsz.dll,cgfhr.dll,aghmxd.dll,sdfrbt.dll,jkzsgf.dll,dghagc.dll,dfgwag.dll,fgjd.dll,xfnh.dll,bgyu.dll,xdrhcj.dll,zsrdygx.dll,dfhvk.dll,xdfthjh.dll,cvbtfs.dll,cgydj.dll,zsdgrgh.dll,fghdd.dll,bgcjty.dll,dbgj.dll,xcfgh.dll,cvnghk.dll,vgxdcg.dll,chjg.dll,vnfxd.dll,nbmfu.dll,xdbjy.dll,vbjxbnm.dll,xgngj.dll,cxvbh.dll,fgjt.dll,cnbv.dll,cvnhk.dll,vgjzrg.dll,cvjdfh.dll,sdfhk.dll,gmnait.dll,xdbnm.dll,xbnft.dll,myuf.dll,hkxddrh.dll,aserg.dll,zdfgf.dll,bnmdgh.dll,bxdfh.dll,cncft.dll,cfjzsxn.dll,dfbghj.dll,dgbzd.dll,nhjsd.dll,hjmasd.dll,xbfhxd.dll,bngyjuf.dll,xdgxr.dll,bnmft.dll,xcvgu.dll,szggfj.dll,zsggixd.dll,bnhugk.dll,xdhuk.dll,dxgjgfy.dll,fgjderg.dll,asfhjy.dll,swegfuj.dll,cxfhf.dll,hjukrt.dll,dhdhvv.dll,vdfthjk.dll,xdfrg.dll,zsgjfh.dll,cvbyj.dll,nmxdt.dll,bhdryn.dll,nbkfy.dll,xsdjd.dll,xuxdg.dll,nmdgkn.dll,xdhts.dll,vcnyd.dll,zsdth.dll,>修改为<>即清空

这个你没清理。。
后来扫的日志就放在后面的回帖中哦,不要放在一楼
gototop
 

回复:wo zai 我在等待!

yun 晕!我一不小心删除了!怎么办?????
gototop
 

回复 8F 没有眼泪 的帖子

惨不?热哦!给删掉了!后果严重不?有没有啥挽救方法?谢谢啊!!!!!!111
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT