——————————————————————————————————————————
这里下载手工清理木马群工具包,并解压至C盘文件夹里。(全部工具内附操作说明):
http://bbs.ikaka.com/attachment.aspx?attachmentid=480689———————————————————————
下载usp10.dll扫描清理工具。
http://bbs.ikaka.com/attachment.aspx?attachmentid=481869然后作好下面操作需要的所有准备,彻底断网处理。不断网无法解决问题。
———————————————————————
用工具包内的“XDELBOX删除文件工具”去删除病毒文件。工具包必须全部解压至C盘后应用。
如果XDELBOX工具操作中提示出错,不能操作,可以继续使用工具包内其他SmtDel工具、费尔工具、超级巡警、EasyDelete工具删除病毒文件。(全部内附操作说明图)
启动XDELBOX程序。复制粘贴下面文件操作删除:
C:\WINDOWS\system32\anymie360.dll
C:\Program Files\Internet Explorer\PowerNeNt.Onz
C:\WINDOWS\TEMP\64036
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\100376
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat
C:\WINDOWS\system32\kfmpilhj.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\138613
C:\WINDOWS\system32\ihdfmcbc.dll
C:\Program Files\Internet Explorer\PontDwn.Dot
C:\WINDOWS\system32\hblllfcc.dll
C:\WINDOWS\system32\ehdagege.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\322955
C:\WINDOWS\fonts\CtmRes.dll
C:\WINDOWS\system32\nbacaifg.dll
C:\WINDOWS\system32\ecmipgbb.dll
C:\WINDOWS\system32\iipffhje.dll
C:\WINDOWS\system32\cealpalp.dll
C:\WINDOWS\system32\nfccoiof.dll
C:\WINDOWS\system32\biaekcmm.dll
C:\WINDOWS\system32\kbjicidg.dll
C:\WINDOWS\system32\gapadkel.dll
C:\WINDOWS\system32\hnjfelch.dll
C:\WINDOWS\system32\lddlkmel.dll
C:\WINDOWS\system32\onglejhh.dll
C:\WINDOWS\fonts\ctm01025.ttf
C:\WINDOWS\fonts\ctm04004.ttf
C:\WINDOWS\fonts\ctm09003.ttf
C:\WINDOWS\fonts\ctm11008.ttf
C:\WINDOWS\fonts\ctm12004.ttf
C:\WINDOWS\system32\ctm11008.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\390414
C:\WINDOWS\system32\ctm12004.exe
C:\WINDOWS\fonts\ComRes.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\401040
C:\WINDOWS\system32\ctm09003.exe
C:\WINDOWS\TEMP\410896
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\462949
C:\WINDOWS\TEMP\493619
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\914239
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\914379
C:\WINDOWS\System32\Drivers\msiffei.sys
C:\WINDOWS\system32\BF01E0B5.dat
C:\WINDOWS\system32\anymie360.exe
C:\WINDOWS\anymie360.exe
重启电脑自动运行完毕进入系统后,不论删除结果如何立即继续下面操作。
运行usp10.dll扫描清理工具扫描电脑,并继续下面操作。
———————————————————————
用工具包内的“映像劫持清除工具”(有操作说明),清除检测到的所有映像劫持项。没有就不管它了。
———————————————————————
可以这贴里找相同系统里的ctfmon.exe文件下载:
http://bbs.ikaka.com/showtopic-8417665.aspx用工具包内的“SmtRpl替换文件工具”(有使用说明)
将C:\WINDOWS\system32\ctfmon.exe替换回正常的系统文件.
————————————————————————————————————
在扫日志的SRENG工具》启动项目》注册表》里将<AppInit_DLLs>项目置空(就是选择“编辑”)这必须关闭杀毒软件的监控,否则改不了可能。
就是将 <AppInit_DLLs> 的“值”项编辑置空
你可以选择其中一个红色项,然后编辑时你可能看不到什么,只需要在值项里输入任意一个字母或数字即可。
————————————————————————————————————
在扫日志的SRENG工具》启动项目》注册表》里面找下面项目删除:
<Alcmtr><anymie360.exe> []
<{4F5A2DCC-E236-45FB-80E0-D6DD2FAF5DD2}><C:\WINDOWS\system32\kflaidcc.dll> [File is missing]
<{005EE83D-0340-4AE0-BD83-C15E7E72242A}><C:\WINDOWS\system32\ggleeojd.dll> [File is missing]
<{55158976-1421-440E-B3FE-C7CF47BD2FC2}><C:\WINDOWS\system32\llhlopnm.dll> [File is missing]
<{11D2126F-2637-435E-BDA1-A57EDD4FDAAE}><C:\WINDOWS\system32\hhdihimf.dll> [File is missing]
<{A53B2874-F84A-47A2-BBA1-CFC4C41DD237}><C:\WINDOWS\system32\aljbionk.dll> [File is missing]
<{B2B55210-AF2A-4299-A505-19B7C8466E31}><C:\WINDOWS\system32\bibllihg.dll> [File is missing]
<{BBB72187-E70A-4AE9-AC73-CB0F812700E6}><C:\WINDOWS\system32\bbbnihon.dll> [File is missing]
<{DA4C0583-90D7-44BC-A7E5-2B0A344451D6}><C:\WINDOWS\system32\dakcgloj.dll> [File is missing]
<{B07DC262-743B-4FF3-BCB6-238D3D473A0D}><C:\WINDOWS\system32\bgndcimi.dll> [File is missing]
<{E3321EBC-6C05-4460-BA11-D29571BEEEB3}><C:\WINDOWS\system32\ejjihebc.dll> [File is missing]
<{33791851-F9FD-4719-AB62-5952F09D2AEB}><C:\WINDOWS\system32\jjnpholh.dll> [File is missing]
<{71C4EB49-21E1-4FE6-9348-B1ECEBBC2AFE}><C:\WINDOWS\system32\nhckebkp.dll> [File is missing]
<{B612ECEB-2F98-4B86-B7D3-368347396A8C}><C:\WINDOWS\system32\bmhieceb.dll> [File is missing]
<{6A8D34D7-08D7-421F-AFF6-956A0BD6F0BF}><C:\Program Files\Internet Explorer\PowerNeNt.Onz> []
<{4021B3B8-8749-48B3-AB6B-33F1D60CBA24}><C:\WINDOWS\system32\kgihbjbo.dll> [File is missing]
<{E06AA4CF-637E-4094-A651-151A7C16100A}><C:\WINDOWS\system32\egmaakcf.dll> [File is missing]
<{2C51AE5E-4C9B-499A-829B-173F7CB06BBE}><C:\WINDOWS\system32\iclhaele.dll> [File is missing]
<{8B85DE68-D5DC-4895-9E9B-9DD2E4A3150A}><C:\WINDOWS\system32\oboldemo.dll> [File is missing]
<{081AB32D-61AB-41D1-9894-85E6BE833BF1}><C:\WINDOWS\system32\gohabjid.dll> [File is missing]
<{80A3B5D6-48FE-4E76-8005-EBE00866C578}><C:\WINDOWS\system32\ogajbldm.dll> [File is missing]
<{44E71C77-A72F-404E-BED8-CC9191785B57}><C:\WINDOWS\system32\kkenhcnn.dll> [File is missing]
<{2C567250-B1EC-42BC-8F3E-BE4861972C15}><C:\WINDOWS\system32\iclmnilg.dll> [File is missing]
<{94A141CF-B87F-4772-8C48-6A6641CA8ED0}><C:\WINDOWS\system32\pkahkhcf.dll> [File is missing]
<{1985A3FA-241E-4436-B81B-5B02139F16A9}><C:\WINDOWS\system32\hpolajfa.dll> [File is missing]
<{CE56A22D-CA3D-4E85-A6AB-22F71C92790E}><C:\WINDOWS\system32\celmaiid.dll> [File is missing]
<{B1B4DFCF-ACF3-4578-ABEC-5C5D405910BE}><C:\WINDOWS\system32\bhbkdfcf.dll> [File is missing]
<{604BC299-360A-4B62-8E87-5685030D6E84}><C:\WINDOWS\system32\mgkbcipp.dll> [File is missing]
<{DE424090-CF40-49A6-83EA-3950FEDB4464}><C:\WINDOWS\system32\dekikgpg.dll> [File is missing]
<{DC5F2D80-F906-44CA-A4DF-FF471F4786E0}><C:\WINDOWS\system32\dclfidog.dll> [File is missing]
<{384142AF-D7BD-48A8-A4AF-193927A75F6F}><C:\WINDOWS\system32\jokhkiaf.dll> [File is missing]
<{F6504E2F-8586-4DFC-881B-D058107D9F1A}><C:\WINDOWS\system32\fmlgkeif.dll> [File is missing]
<{908D910E-8397-4249-AEC1-AC0498915FF8}><C:\WINDOWS\system32\pgodphge.dll> [File is missing]
<{F7A30C31-277D-4003-AA13-6972ECA362F2}><C:\WINDOWS\system32\fnajgcjh.dll> [File is missing]
<{0D2FE1D0-C705-46D1-865C-7506B9F07923}><C:\WINDOWS\system32\gdifehdg.dll> [File is missing]
<{F4A8F1FE-E34E-49E9-B707-E6B3F5C92D49}><C:\WINDOWS\system32\fkaofhfe.dll> [File is missing]
<{322870B3-45FB-44EF-8141-7E3FBD9049ED}><C:\WINDOWS\system32\jiiongbj.dll> [File is missing]
<{C82B3EE3-B073-438A-9B6F-00ED3A0B3A7C}><C:\WINDOWS\system32\coibjeej.dll> [File is missing]
<{D8F0534A-B62A-462B-8582-D25257DDB64E}><C:\WINDOWS\system32\dofgljka.dll> [File is missing]
<{4D2BBAB1-A828-45D5-925E-AEBA148114B8}><C:\WINDOWS\system32\kdibbabh.dll> [File is missing]
<{6904EB09-0382-41CB-BA97-6EA882FCF203}><C:\WINDOWS\system32\mpgkebgp.dll> [File is missing]
<{4953A4DB-2B35-4EF4-8660-2C0565F38B3F}><C:\WINDOWS\system32\kpljakdb.dll> [File is missing]
<{F49EA650-076B-4E67-AB4F-BF953A29BB56}><C:\WINDOWS\system32\fkpeamlg.dll> [File is missing]
<{6F311925-7917-4252-882F-A198B24EF0F6}><C:\WINDOWS\system32\mfjhhpil.dll> [File is missing]
<{7A79395D-A547-419C-9E9B-589BA645C00D}><C:\WINDOWS\system32\nanpjpld.dll> [File is missing]
<{5DBEEF41-B2F9-428C-A57A-99C263569E05}><C:\WINDOWS\system32\ldbeefkh.dll> [File is missing]
<{B714B15B-22B1-48EE-BF4C-F7450C0D485D}><C:\WINDOWS\system32\bnhkbhlb.dll> [File is missing]
<{4598C803-C432-4118-AC43-4E822832C44A}><C:\WINDOWS\system32\klpocogj.dll> [File is missing]
<{B75C08DB-9199-460C-855E-21E8140DBCA6}><C:\WINDOWS\system32\bnlcgodb.dll> [File is missing]
<{4F692513-97EC-46EC-8C66-1AE27ABB197F}><C:\WINDOWS\system32\kfmpilhj.dll> []
<{21DF6CBC-D2B5-467F-8289-70F97747C1CA}><C:\WINDOWS\system32\ihdfmcbc.dll> []
<{DBF082E3-0872-4E6B-A0E8-DC4FDA6CCB36}><C:\WINDOWS\system32\dbfgoiej.dll> [File is missing]
<{1B555FCC-9705-464D-ACDC-3C93C67B9839}><C:\WINDOWS\system32\hblllfcc.dll> []
<{E1DA0E0E-C413-42B9-B188-2AC5056B6F4C}><C:\WINDOWS\system32\ehdagege.dll> []
<{C34ADCA2-772C-4147-B380-74584491BDF1}><C:\WINDOWS\system32\cjkadcai.dll> [File is missing]
<{AD5BDCAD-4AA6-4431-993D-04F1CCC6B70D}><C:\WINDOWS\system32\adlbdcad.dll> [File is missing]
<{4FCD7745-A42C-4B9C-A575-E5DBB3863058}><C:\WINDOWS\system32\kfcdnnkl.dll> [File is missing]
<{7BACA2F0-5801-468A-9429-AB5AE873F23A}><C:\WINDOWS\system32\nbacaifg.dll> []
<{EC6290BB-4D99-40BB-9098-C19F9CFC2598}><C:\WINDOWS\system32\ecmipgbb.dll> []
<{229FF13E-3361-4E61-9423-6A3AAB8189DE}><C:\WINDOWS\system32\iipffhje.dll> []
<{CEA59A59-C013-4036-9D35-9A4C580A27E6}><C:\WINDOWS\system32\cealpalp.dll> []
<{7FCC828F-C300-4D06-957E-DD49CF387573}><C:\WINDOWS\system32\nfccoiof.dll> []
<{B2AE4C66-A807-47FD-A08E-2984F87A9ACF}><C:\WINDOWS\system32\biaekcmm.dll> []
<{4B32C2D0-7D24-4261-977B-56AF3AEA26AC}><C:\WINDOWS\system32\kbjicidg.dll> []
<{0A9AD4E5-0B04-4C3D-BFDB-B54BD59A012D}><C:\WINDOWS\system32\gapadkel.dll> []
<{173FE5C1-4270-4C18-A125-29EF2672CAC4}><C:\WINDOWS\system32\hnjfelch.dll> []
<{5DD546E5-8877-45E6-86B9-4664BF57DC90}><C:\WINDOWS\system32\lddlkmel.dll> []
<{8705E311-EE2B-4E5E-B75A-6C66126B14F6}><C:\WINDOWS\system32\onglejhh.dll> []
<{99622060-709D-48FB-AB87-FB98ECBB5115}><C:\WINDOWS\system32\ppmiigmg.dll> []
<{22F536BD-3113-4E36-BFBD-8C368432DC85}><C:\WINDOWS\system32\iifljmbd.dll> []
<{2ACC2C22-4E3A-4AD1-8FBF-56EAE282B3D0}><C:\WINDOWS\system32\iaccicii.dll> []
<{B01602BA-58CF-44E5-9FB9-B886929EA7A8}><C:\WINDOWS\system32\bghmgiba.dll> []
<{BF956C8F-D8F2-4545-AB7C-7C11106E2FD9}><C:\WINDOWS\system32\bfplmcof.dll> []
<{33F92E96-A5A1-4B61-870E-12B2552AFF05}><C:\WINDOWS\system32\jjfpiepm.dll> []
<{45044782-BB4B-4C0D-90FB-6A50E06922BB}><C:\WINDOWS\system32\klgkknoi.dll> []
<4F5A2DCC><C:\WINDOWS\system32\kflaidcc.dll> [File is missing]
<005EE83D><C:\WINDOWS\system32\ggleeojd.dll> [File is missing]
<55158976><C:\WINDOWS\system32\llhlopnm.dll> [File is missing]
<11D2126F><C:\WINDOWS\system32\hhdihimf.dll> [File is missing]
<A53B2874><C:\WINDOWS\system32\aljbionk.dll> [File is missing]
<B2B55210><C:\WINDOWS\system32\bibllihg.dll> [File is missing]
<BBB72187><C:\WINDOWS\system32\bbbnihon.dll> [File is missing]
<DA4C0583><C:\WINDOWS\system32\dakcgloj.dll> [File is missing]
<B07DC262><C:\WINDOWS\system32\bgndcimi.dll> [File is missing]
<E3321EBC><C:\WINDOWS\system32\ejjihebc.dll> [File is missing]
<33791851><C:\WINDOWS\system32\jjnpholh.dll> [File is missing]
<71C4EB49><C:\WINDOWS\system32\nhckebkp.dll> [File is missing]
<B612ECEB><C:\WINDOWS\system32\bmhieceb.dll> [File is missing]
<4021B3B8><C:\WINDOWS\system32\kgihbjbo.dll> [File is missing]
<E06AA4CF><C:\WINDOWS\system32\egmaakcf.dll> [File is missing]
<2C51AE5E><C:\WINDOWS\system32\iclhaele.dll> [File is missing]
<8B85DE68><C:\WINDOWS\system32\oboldemo.dll> [File is missing]
<081AB32D><C:\WINDOWS\system32\gohabjid.dll> [File is missing]
<80A3B5D6><C:\WINDOWS\system32\ogajbldm.dll> [File is missing]
<44E71C77><C:\WINDOWS\system32\kkenhcnn.dll> [File is missing]
<2C567250><C:\WINDOWS\system32\iclmnilg.dll> [File is missing]
<94A141CF><C:\WINDOWS\system32\pkahkhcf.dll> [File is missing]
<1985A3FA><C:\WINDOWS\system32\hpolajfa.dll> [File is missing]
<CE56A22D><C:\WINDOWS\system32\celmaiid.dll> [File is missing]
<B1B4DFCF><C:\WINDOWS\system32\bhbkdfcf.dll> [File is missing]
<604BC299><C:\WINDOWS\system32\mgkbcipp.dll> [File is missing]
<DE424090><C:\WINDOWS\system32\dekikgpg.dll> [File is missing]
<DC5F2D80><C:\WINDOWS\system32\dclfidog.dll> [File is missing]
<384142AF><C:\WINDOWS\system32\jokhkiaf.dll> [File is missing]
<F6504E2F><C:\WINDOWS\system32\fmlgkeif.dll> [File is missing]
<908D910E><C:\WINDOWS\system32\pgodphge.dll> [File is missing]
<F7A30C31><C:\WINDOWS\system32\fnajgcjh.dll> [File is missing]
<0D2FE1D0><C:\WINDOWS\system32\gdifehdg.dll> [File is missing]
<F4A8F1FE><C:\WINDOWS\system32\fkaofhfe.dll> [File is missing]
<322870B3><C:\WINDOWS\system32\jiiongbj.dll> [File is missing]
<C82B3EE3><C:\WINDOWS\system32\coibjeej.dll> [File is missing]
<D8F0534A><C:\WINDOWS\system32\dofgljka.dll> [File is missing]
<4D2BBAB1><C:\WINDOWS\system32\kdibbabh.dll> [File is missing]
<6904EB09><C:\WINDOWS\system32\mpgkebgp.dll> [File is missing]
<4953A4DB><C:\WINDOWS\system32\kpljakdb.dll> [File is missing]
<F49EA650><C:\WINDOWS\system32\fkpeamlg.dll> [File is missing]
<6F311925><C:\WINDOWS\system32\mfjhhpil.dll> [File is missing]
<7A79395D><C:\WINDOWS\system32\nanpjpld.dll> [File is missing]
<5DBEEF41><C:\WINDOWS\system32\ldbeefkh.dll> [File is missing]
<B714B15B><C:\WINDOWS\system32\bnhkbhlb.dll> [File is missing]
<4598C803><C:\WINDOWS\system32\klpocogj.dll> [File is missing]
<B75C08DB><C:\WINDOWS\system32\bnlcgodb.dll> [File is missing]
<4F692513><C:\WINDOWS\system32\kfmpilhj.dll> []
<21DF6CBC><C:\WINDOWS\system32\ihdfmcbc.dll> []
<DBF082E3><C:\WINDOWS\system32\dbfgoiej.dll> [File is missing]
<1B555FCC><C:\WINDOWS\system32\hblllfcc.dll> []
<E1DA0E0E><C:\WINDOWS\system32\ehdagege.dll> []
<C34ADCA2><C:\WINDOWS\system32\cjkadcai.dll> [File is missing]
<AD5BDCAD><C:\WINDOWS\system32\adlbdcad.dll> [File is missing]
<4FCD7745><C:\WINDOWS\system32\kfcdnnkl.dll> [File is missing]
<7BACA2F0><C:\WINDOWS\system32\nbacaifg.dll> []
<EC6290BB><C:\WINDOWS\system32\ecmipgbb.dll> []
<229FF13E><C:\WINDOWS\system32\iipffhje.dll> []
<CEA59A59><C:\WINDOWS\system32\cealpalp.dll> []
<7FCC828F><C:\WINDOWS\system32\nfccoiof.dll> []
<B2AE4C66><C:\WINDOWS\system32\biaekcmm.dll> []
<4B32C2D0><C:\WINDOWS\system32\kbjicidg.dll> []
<0A9AD4E5><C:\WINDOWS\system32\gapadkel.dll> []
<173FE5C1><C:\WINDOWS\system32\hnjfelch.dll> []
<5DD546E5><C:\WINDOWS\system32\lddlkmel.dll> []
<8705E311><C:\WINDOWS\system32\onglejhh.dll> []
<99622060><C:\WINDOWS\system32\ppmiigmg.dll> []
<22F536BD><C:\WINDOWS\system32\iifljmbd.dll> []
<2ACC2C22><C:\WINDOWS\system32\iaccicii.dll> []
<B01602BA><C:\WINDOWS\system32\bghmgiba.dll> []
<BF956C8F><C:\WINDOWS\system32\bfplmcof.dll> []
<33F92E96><C:\WINDOWS\system32\jjfpiepm.dll> []
<45044782><C:\WINDOWS\system32\klgkknoi.dll> []
————————————————————————————————————
在扫日志的SRENG工具》启动项目》服务》驱动程序》里面找下面项删除,
==================================
驱动程序
[msiffei / msiffei][Stopped/Manual Start]
<System32\Drivers\msiffei.sys><N/A>
[Safe Mon 360 / SafeMon0][Running/System Start]
<\??\C:\WINDOWS\system32\BF01E0B5.dat><N/A>
—————————————————————————————
在扫日志的SRENG工具》系统修复》浏览器加载项》里面找下面删除
==================================
浏览器加载项
[]
{6A8D34D7-08D7-421F-AFF6-956A0BD6F0BF} <C:\Program Files\Internet Explorer\PowerNeNt.Onz, N/A>
[]
{6A8D34D7-08D7-421F-AFF6-956A0BD6F0BF} <C:\Program Files\Internet Explorer\PowerNeNt.Onz, N/A>
——————————————————————————————————————
手工直接去IE浏览器的菜单里找“工具”项里选择“internet选项”点击“删除文件”勾选“删除脱机文件”再点“确定”清空IE缓存。
用工具包内的“系统垃圾文件清理工具”清空能清空的垃圾文件,不能清空的不管它
————————————————————————————————————
当扫描usp10.dll扫描清理工具提示重启电脑时
再重启电脑,反复检查,操作的结果,
连网用W i n d o w s 清理助手 ,清理你那系统。
W i n d o w s 清理助手 下载:
http://www.arswp.com/杀毒软件升级至最新版本全盘杀。
记得打全系统漏洞补丁
SRENG工具的各项操作看这里:
http://bbs.ikaka.com/showtopic-8545446.aspx