原帖由 hui4190 于 2008-7-31 8:25:00 发表
请看附件
能告诉我中了什么吗?杀毒杀不出来。可是明显中毒,的
用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
1.建议使用XDelBox删除以下文件:
XDelBox1.7]http://www.dodudou.com/down/]XDelBox1.7下载
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
c:\windows\system32\oobe\7754\svchost.exe
c:\windows\system32\rtmbufdx.exe
c:\windows\gwmapereshid3002.dll
c:\windows\player.exe
c:\windows\system32\dpvvoxmh.dll
c:\windows\system32\msobjstl.dll
c:\windows\system32\vknscgpg.dll
c:\windows\system32\mstimewd.dll
c:\windows\system32\adsntzt.dll
c:\windows\system32\apsghjba.dll
c:\windows\system32\wmpuiqhx.dll
c:\windows\system32\scrruncqsj.dll
c:\windows\system32\rasdlgcq.dll
c:\windows\system32\cliconfgzx.dll
c:\windows\system32\dispexcb.dll
c:\windows\system32\dndsaf.dll
c:\windows\system32\catsrvwl.dll
c:\windows\system32\kbdswjr.dll
c:\windows\system32\bootvidgj.dll
c:\windows\system32\tscfgwmijxsj.dll
c:\windows\system32\ksuserfy.dll
c:\windows\system32\slbiopfs2.dll
c:\windows\system32\sooirewlqx.dll
c:\windows\system32\ddserh.dll
c:\windows\system32\wzcfsw.dll
c:\windows\system32\jfrwdh.dll
c:\windows\system32\zgtwfx.dll
c:\windows\system32\fmcvxy.dll
c:\windows\system32\jfdses.dll
c:\windows\system32\fsrgeb.dll
c:\windows\system32\tdfhex.dll
c:\0026d7fce86704a0.dat
c:\03dc7c404def249f.dat
c:\0efd690c719dacaa.dat
c:\24e8333caaa45662.dat
c:\windows\system32\drivers\2wiloj.sys
c:\383fffec6c9cde9b.dat
c:\a495d38c1a47d961.dat
c:\windows\system32\drivers\msiffei.sys
c:\windows\system32\drivers\sfafix.sys
c:\windows\system32\drivers\qrxabzp.sys
c:\windows\system32\drivers\phfc.sys
c:\docume~1\admini~1\locals~1\temp\_tmp.bat
c:\documents and settings\all users\application data\microsoft\office\system\ntptdb.sys
c:\windows\system32\nessery.sys
c:\docume~1\admini~1\locals~1\temp\1.tmp
c:\windows\system32\d32dx9.sys
c:\fb27b4f8baef9d5f.dat
c:\faa9cd94beb65860.dat
c:\d789007ca16984b4.dat
c:\ce2f79d438016be0.dat
c:\windows\system32\10ca.dll
c:\documents and settings\all users\application data\microsoft\office\userdata\webbrowser_2005.dll
c:\windows\downlo~1\submit~1.dll
c:\windows\downlo~1\inputc~1.dll
c:\program files\zztoolbar\toolbar_bho.dll
c:\program files\zztoolbar\toolband.dll
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[N/A] <C:\WINDOWS\Player.exe>
[N/A] <C:\WINDOWS\Player.exe>
[{00070007-0007-0007-0007-00070007BB15}] <C:\WINDOWS\system32\dpvvoxmh.dll>
[{00170017-0017-0017-0017-00170017BB15}] <C:\WINDOWS\system32\msobjstl.dll>
[{00150015-0015-0015-0015-00150015BB15}] <C:\WINDOWS\system32\vknscgpg.dll>
[{00180018-0018-0018-0018-00180018BB15}] <C:\WINDOWS\system32\mstimewd.dll>
[{00010001-0001-0001-0001-00010001BB15}] <C:\WINDOWS\system32\adsntzt.dll>
[{8FD45A54-9875-698F-E56E-65102358FDF8}] <C:\WINDOWS\system32\apsghjba.dll>
[{00270027-0027-0027-0027-00270027BB15}] <C:\WINDOWS\system32\wmpuiqhx.dll>
[{00240024-0024-0024-0024-00240024BB15}] <C:\WINDOWS\system32\scrruncqsj.dll>
[{00230023-0023-0023-0023-00230023BB15}] <C:\WINDOWS\system32\rasdlgcq.dll>
[{00050005-0005-0005-0005-00050005BB15}] <C:\WINDOWS\system32\cliconfgzx.dll>
[{00060006-0006-0006-0006-00060006BB15}] <C:\WINDOWS\system32\dispexcb.dll>
[{259BF3CF-194D-4FE6-9ADB-DE6544B098B6}] <C:\WINDOWS\system32\dndsaf.dll>
[{00040004-0004-0004-0004-00040004BB15}] <C:\WINDOWS\system32\catsrvwl.dll>
[{00120012-0012-0012-0012-00120012BB15}] <C:\WINDOWS\system32\kbdswjr.dll>
[{00030003-0003-0003-0003-00030003BB15}] <C:\WINDOWS\system32\bootvidgj.dll>
[{00330033-0033-0033-0033-00330033BB15}] <C:\WINDOWS\system32\tscfgwmijxsj.dll>
[{00130013-0013-0013-0013-00130013BB15}] <C:\WINDOWS\system32\ksuserfy.dll>
[{00250025-0025-0025-0025-00250025BB15}] <C:\WINDOWS\system32\slbiopfs2.dll>
[{00310031-0031-0031-0031-00310031BB15}] <C:\WINDOWS\system32\sooirewlqx.dll>
[{A9895933-6636-4281-BC58-EE6DE2AF96E3}] <C:\WINDOWS\system32\ddserh.dll>
[{28766E1C-74B0-4417-8C75-F12AE309EF35}] <C:\WINDOWS\system32\wzcfsw.dll>
[{841529CB-7F77-4B99-A895-B5441E0D302F}] <C:\WINDOWS\system32\jfrwdh.dll>
[{006CA8A1-61BC-4774-A54C-F49034270BAD}] <C:\WINDOWS\system32\zgtwfx.dll>
[{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7}] <C:\WINDOWS\system32\fmcvxy.dll>
[{81AF1CF6-D1C9-4C6A-AC01-EDE54E71945B}] <C:\WINDOWS\system32\jfdses.dll>
[{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6}] <C:\WINDOWS\system32\fsrgeb.dll>
[{0B846B26-BFE6-4E8E-A948-1DB17B77B483}] <C:\WINDOWS\system32\tdfhex.dll>
[{E0F3526A-4165-4589-80CD-50B6FBAC3BDA}] <C:\WINDOWS\system32\adsntzt.dll>
[{432BDC7C-DE5B-43f4-AA81-E7F8AFB0182D}] <C:\WINDOWS\system32\kbdswjr.dll>
[dpvvoxmh.dll] <C:\WINDOWS\system32\dpvvoxmh.dll>
[msobjstl.dll] <C:\WINDOWS\system32\msobjstl.dll>
[vknscgpg.dll] <C:\WINDOWS\system32\vknscgpg.dll>
[mstimewd.dll] <C:\WINDOWS\system32\mstimewd.dll>
[adsntzt.dll] <C:\WINDOWS\system32\adsntzt.dll>
[wmpuiqhx.dll] <C:\WINDOWS\system32\wmpuiqhx.dll>
[scrruncqsj.dll] <C:\WINDOWS\system32\scrruncqsj.dll>
[rasdlgcq.dll] <C:\WINDOWS\system32\rasdlgcq.dll>
[cliconfgzx.dll] <C:\WINDOWS\system32\cliconfgzx.dll>
[dispexcb.dll] <C:\WINDOWS\system32\dispexcb.dll>
[catsrvwl.dll] <C:\WINDOWS\system32\catsrvwl.dll>
[kbdswjr.dll] <C:\WINDOWS\system32\kbdswjr.dll>
[bootvidgj.dll] <C:\WINDOWS\system32\bootvidgj.dll>
[tscfgwmijxsj.dll] <C:\WINDOWS\system32\tscfgwmijxsj.dll>
[ksuserfy.dll] <C:\WINDOWS\system32\ksuserfy.dll>
[slbiopfs2.dll] <C:\WINDOWS\system32\slbiopfs2.dll>
[sooirewlqx.dll] <C:\WINDOWS\system32\sooirewlqx.dll>
[IFEO[AntiArp.exe]] <ntsd -d>
[IFEO[DrvAnti.exe]] <ntsd -d>
[IFEO[drwadins.exe]] <ntsd -d>
[IFEO[drwebscd.exe]] <ntsd -d>
[IFEO[drwebupw.exe]] <ntsd -d>
[IFEO[filemon.exe]] <ntsd -d>
[IFEO[GFRing3.exe]] <ntsd -d>
[IFEO[GFUpd.exe]] <ntsd -d>
[IFEO[OllyDBG.EXE]] <ntsd -d>
[IFEO[OllyICE.EXE]] <ntsd -d>
[IFEO[procexp.exe]] <ntsd -d>
[IFEO[RavCopy.exe]] <ntsd -d>
[IFEO[RavXP.exe]] <ntsd -d>
[IFEO[RawCopy.exe]] <ntsd -d>
[IFEO[regmon.exe]] <ntsd -d>
[IFEO[RegTool.exe]] <ntsd -d>
[IFEO[rfwProxy.exe]] <ntsd -d>
[IFEO[rfwstub.exe]] <ntsd -d>
[IFEO[spiderml.exe]] <ntsd -d>
[IFEO[spidernt.exe]] <ntsd -d>
[IFEO[spiderui.exe]] <ntsd -d>
[IFEO[spml_set.exe]] <ntsd -d>
[IFEO[taskmgar.exe]] <ntsd -d>
启动项目 -- 服务-- 驱动程序之如下项禁用:
[0026d7fce86704a0 / 0026d7fce86704a0] <\??\C:\0026d7fce86704a0.dat>
[03dc7c404def249f / 03dc7c404def249f] <\??\C:\03dc7c404def249f.dat>
[0efd690c719dacaa / 0efd690c719dacaa] <\??\C:\0efd690c719dacaa.dat>
[24e8333caaa45662 / 24e8333caaa45662] <\??\C:\24e8333caaa45662.dat>
[2wilo / 2wiloj] <\SystemRoot\System32\DRIVERS\2wiloj.sys>
[383fffec6c9cde9b / 383fffec6c9cde9b] <\??\C:\383fffec6c9cde9b.dat>
[a495d38c1a47d961 / a495d38c1a47d961] <\??\C:\a495d38c1a47d961.dat>
[msiffei / msiffei] <System32\Drivers\msiffei.sys>
[sfafix / sfafix] <\SystemRoot\system32\drivers\sfafix.sys>
[qrxabzp / qrxabzp] <\??\C:\WINDOWS\system32\drivers\qrxabzp.sys>
[phfc / phfc] <\SystemRoot\system32\drivers\phfc.sys>
[olhjf / olhjf] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_tmp.bat>
[ntptdb / ntptdb] <\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys>
[Nessery / Nessery] <\??\C:\WINDOWS\system32\Nessery.sys>
[IIS Manager / IIS Manager ] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1.tmp>
[HiddFldy / HiddFldy] <\??\C:\WINDOWS\system32\d32dx9.sys>
[fb27b4f8baef9d5f / fb27b4f8baef9d5f] <\??\C:\fb27b4f8baef9d5f.dat>
[faa9cd94beb65860 / faa9cd94beb65860] <\??\C:\faa9cd94beb65860.dat>
[d789007ca16984b4 / d789007ca16984b4] <\??\C:\d789007ca16984b4.dat>
[ce2f79d438016be0 / ce2f79d438016be0] <\??\C:\ce2f79d438016be0.dat>
系统修复-- 浏览器加载项之如下项删除:
[Invoke Class] <C:\WINDOWS\system32\10ca.dll>
[InceHelper Class] <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2005.dll>
[AxSubmitControl Class] <C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL>
[AxInputControl Class] <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL>
[Invoke Class] <C:\WINDOWS\system32\10ca.dll>
[AxSubmitControl Class] <C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL>
[InceHelper Class] <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2005.dll>
[网站排名工具条BHO] <C:\Program Files\zzToolBar\Toolbar_bho.dll>
[网站排名工具条] <C:\Program Files\zzToolBar\ToolBand.dll>
[网站排名工具条BHO] <C:\Program Files\zzToolBar\Toolbar_bho.dll>
[Invoke Class] <C:\WINDOWS\system32\10ca.dll>
[InceHelper Class] <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2005.dll>
[AxSubmitControl Class] <C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL>
[AxInputControl Class] <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL>
[Invoke Class] <C:\WINDOWS\system32\10ca.dll>
[AxSubmitControl Class] <C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL>
[InceHelper Class] <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2005.dll>
[网站排名工具条BHO] <C:\Program Files\zzToolBar\Toolbar_bho.dll>
[网站排名工具条] <C:\Program Files\zzToolBar\ToolBand.dll>
[网站排名工具条BHO] <C:\Program Files\zzToolBar\Toolbar_bho.dll>
[网站排名工具条] <C:\Program Files\zzToolBar\ToolBand.dll>
清理完以后重启电脑用下面工具
建议用以下工具对系统进行清理。
1:下载临时文件清理工具.
下载地址:
http://www.atribune.org/2:下载windows清理助手清理残余病毒和木马
下载地址:
http://www.arswp.com/download.html