1   1  /  1  页   跳转

[求助] 又中招了,瑞星被屏蔽

又中招了,瑞星被屏蔽

请高手帮忙解决啊,谢谢!!!!!!

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; WPS; TencentTraveler )

附件附件:

文件名:SREngLOG.log
下载次数:82
文件类型:application/octet-stream
文件大小:
上传时间:2008-6-24 13:57:51
描述:log

分享到:
gototop
 

回复: 又中招了,瑞星被屏蔽

1.建议使用XDelBox删除以下文件:(XDelBox1.6下载)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。

c:\windows\system32\ietzbpaq.dll
c:\windows\system32\yzztkmsn.dll
c:\windows\conime.exe
c:\program files\internet explorer\iexplore32.dat
c:\program files\internet explorer\iexplore32.sys
c:\program files\internet explorer\plugins\windows64.sys
c:\windows\system32\cedafb.dll
c:\windows\system32\cliconfgzx.dll
c:\windows\system32\ddserh.dll
c:\windows\system32\fd233ds4f3.dll
c:\windows\system32\fmcvxy.dll
c:\windows\system32\hhrdxd.dll
c:\windows\system32\jfrwdh.dll
c:\windows\system32\mndhfdwd.dll
c:\windows\system32\mnmhgsrv.dll
c:\windows\system32\mpwdeapi.dll
c:\windows\system32\oohxdbyt.dll
c:\windows\system32\ozfyebyt.dll
c:\windows\system32\ptjhehlp.dll
c:\windows\system32\rfdswc.dll
c:\windows\system32\s2da2f323.dll
c:\windows\system32\sgrefg.dll
c:\windows\system32\tdffdl.dll
c:\windows\system32\wyhesm.dll
c:\windows\system32\ypcqghlp.dll
c:\windows\system32\yxcschlp.dll
c:\windows\system32\zgrjdx.dll
c:\windows\system32\zptlcsys.dll
c:\windows\system32\zycbdime.dll
c:\windows\system32\zywlcime.dll
c:\windows\system32\zyzxjime.dll
c:\program files\common files\microsoft shared\msinfo\system76.ins
c:\program files\internet explorer\iexplore32.win
c:\windows\system32\oswxdttb.dll
c:\windows\system32\jfdses.dll
c:\windows\system32\ypcqfhlp.dll
c:\windows\system32\apzhctde.dll
c:\windows\system32\zxmsdwin.dll
c:\windows\system32\apsgfjba.dll
yzztkmsn.dll,ietzbpaq.dll mpackl.dll woasick.dll welldon.dll verptw.dll wpuplder.dll jordspa.dll
"c:\program files\rising\rav\ravmond.exe"
c:\docume~1\admini~1\locals~1\temp\1.tmp

2.删除重启后使用SREng修复下面各项:

    启动项目 -- 注册表之如下项删除:
[cliconfgzx]    <C:\WINDOWS\system32\cliconfgzx.dll>
[{4372FE4D-E2C2-45FE-A893-E2B1691A7DD0}]    <C:\Program Files\Internet Explorer\PLUGINS\Windows64.Sys>
[{4A698102-5904-AFD0-20DF-CD1A65829CA4}]    <C:\WINDOWS\system32\zycbdime.dll>
[{5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5}]    <C:\WINDOWS\system32\oohxdbyt.dll>
[{37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73}]    <C:\WINDOWS\system32\zywlcime.dll>
[{80AF1289-F140-A140-D012-C1458759FC08}]    <C:\WINDOWS\system32\ypcqghlp.dll>
[{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7}]    <C:\WINDOWS\system32\fmcvxy.dll>
[{461D2AB4-29A5-45C2-9134-D52272D3DE38}]    <C:\WINDOWS\system32\rfdswc.dll>
[{841529CB-7F77-4B99-A895-B5441E0D302F}]    <C:\WINDOWS\system32\jfrwdh.dll>
[{8C41B7F7-3168-400D-A702-0E7EFE0BA304}]    <C:\WINDOWS\system32\sgrefg.dll>
[{45AADFAA-DD36-42AB-83AD-0521BBF58C24}]    <C:\WINDOWS\system32\zgrjdx.dll>
[{00050005-0005-0005-0005-00050005BB15}]    <C:\WINDOWS\system32\cliconfgzx.dll>
[{C0595A7E-2E2F-4B34-A83A-019270A0A464}]    <C:\WINDOWS\system32\tdffdl.dll>
[{A9895933-6636-4281-BC58-EE6DE2AF96E3}]    <C:\WINDOWS\system32\ddserh.dll>
[{1FD4696C-E95A-44E2-A03A-FDBDF4CCC305}]    <C:\Program Files\Internet Explorer\IEXPLORE32.win>
[{0B497AE8-3F6C-440C-AB87-52ED0182464A}]    <C:\Program Files\Internet Explorer\IEXPLORE32.Dat>
[{E6C0D0E3-9E9A-489D-AE19-BBCFC7047A59}]    <C:\Program Files\Internet Explorer\IEXPLORE32.Sys>
[{6C648541-1025-9650-9057-6541258720C6}]    <C:\WINDOWS\system32\mndhfdwd.dll>
[{A693A5AB-BDBA-4AE7-A1C8-E41FEE1C020B}]    <C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins>
[{29109876-7619-9101-7012-901938475192}]    <C:\WINDOWS\system32\ietzbpaq.dll>
[{43512378-9874-5641-1025-985420368734}]    <C:\WINDOWS\system32\oswxdttb.dll>
[{5A069845-2036-6084-9054-6087502480A5}]    <C:\WINDOWS\system32\ozfyebyt.dll>
[{81AF1CF6-D1C9-4C6A-AC01-EDE54E71945B}]    <C:\WINDOWS\system32\jfdses.dll>
[{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}]    <C:\WINDOWS\system32\hhrdxd.dll>
[{7C954872-1230-6541-9548-6541025884C7}]    <C:\WINDOWS\system32\fd233ds4f3.dll>
[{84143967-B645-4BFF-B873-DA1DC886E9A7}]    <C:\WINDOWS\system32\cedafb.dll>
[{528DF602-9541-A985-210A-984A698C6F25}]    <C:\WINDOWS\system32\ptjhehlp.dll>
[{70AF1289-F140-A140-D012-C1458759FC07}]    <C:\WINDOWS\system32\ypcqfhlp.dll>
[{3D698451-2015-6358-9871-2015987452D3}]    <C:\WINDOWS\system32\apzhctde.dll>
[{EB71E0B3-E97D-4D30-8733-E28266467617}]    <C:\WINDOWS\system32\wyhesm.dll>
[{B490415F-65F8-B5C5-D8BA-9405FB12054B}]    <C:\WINDOWS\system32\yzztkmsn.dll>
[{35671234-7890-ABCD-CDEF-567801237653}]    <C:\WINDOWS\system32\yxcschlp.dll>
[{A629FF4F-ACDB-5C90-A098-FACB3456A26A}]    <C:\WINDOWS\system32\s2da2f323.dll>
[{7A041F13-A111-12A3-B0CF-F99818AA68A7}]    <C:\WINDOWS\system32\zxmsdwin.dll>
[{AA59145F-315D-BC23-AC1F-145DF81A34AA}]    <C:\WINDOWS\system32\zyzxjime.dll>
[{7C8D1401-A58D-A81C-CD24-A5915C4517C7}]    <C:\WINDOWS\system32\mnmhgsrv.dll>
[{6FD45A54-9875-698F-E56E-65102358FDF6}]    <C:\WINDOWS\system32\apsgfjba.dll>
[{55694105-5108-9405-3695-954187462155}]    <C:\WINDOWS\system32\mpwdeapi.dll>
[{50940F85-F015-14F1-A05F-F69858AC6D05}]    <C:\WINDOWS\system32\zptlcsys.dll>
注意该项[AppInit_DLLs]修改:把<yzztkmsn.dll,ietzbpaq.dll mpackl.dll woasick.dll welldon.dll verptw.dll wpuplder.dll jordspa.dll>修改为<>即清空

    启动项目 -- 服务 -- Win32服务应用程序之如下项禁用:
[Rising RealTime Monitor / RsRavMon]    <"C:\PROGRAM FILES\RISING\RAV\Ravmond.exe">

    启动项目 -- 服务-- 驱动程序之如下项禁用:
[IIS Manager  / IIS Manager ]    <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1.tmp>

    系统修复-- 浏览器加载项之如下项删除:
[]    <C:\Program Files\Internet Explorer\IEXPLORE32.Sys>
[]    <C:\WINDOWS\system32\yzztkmsn.dll>
[]    <C:\WINDOWS\system32\zyzxjime.dll>
[]    <C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins>
[]    <C:\WINDOWS\system32\s2da2f323.dll>
[]    <C:\WINDOWS\system32\ypcqghlp.dll>
[]    <C:\WINDOWS\system32\fd233ds4f3.dll>
[]    <C:\WINDOWS\system32\mnmhgsrv.dll>
[]    <C:\WINDOWS\system32\zxmsdwin.dll>
[]    <C:\WINDOWS\system32\ypcqfhlp.dll>
[]    <C:\WINDOWS\system32\apsgfjba.dll>
[]    <C:\WINDOWS\system32\mndhfdwd.dll>
[]    <C:\WINDOWS\system32\oohxdbyt.dll>
[]    <C:\WINDOWS\system32\ozfyebyt.dll>
[]    <C:\WINDOWS\system32\mpwdeapi.dll>
[]    <C:\WINDOWS\system32\ptjhehlp.dll>
[]    <C:\WINDOWS\system32\zptlcsys.dll>
[]    <C:\WINDOWS\system32\zycbdime.dll>
[]    <C:\Program Files\Internet Explorer\PLUGINS\Windows64.Sys>
[]    <C:\WINDOWS\system32\oswxdttb.dll>
[]    <C:\WINDOWS\system32\apzhctde.dll>
[]    <C:\WINDOWS\system32\zywlcime.dll>
[]    <C:\WINDOWS\system32\yxcschlp.dll>
[]    <C:\WINDOWS\system32\ietzbpaq.dll>
[]    <C:\Program Files\Internet Explorer\IEXPLORE32.win>
[]    <C:\Program Files\Internet Explorer\IEXPLORE32.Dat>
[]    <C:\Program Files\Internet Explorer\IEXPLORE32.Sys>
[]    <C:\WINDOWS\system32\yzztkmsn.dll>
[]    <C:\WINDOWS\system32\zyzxjime.dll>
[]    <C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins>
[]    <C:\WINDOWS\system32\s2da2f323.dll>
[]    <C:\WINDOWS\system32\ypcqghlp.dll>
[]    <C:\WINDOWS\system32\fd233ds4f3.dll>
[]    <C:\WINDOWS\system32\mnmhgsrv.dll>
[]    <C:\WINDOWS\system32\zxmsdwin.dll>
[]    <C:\WINDOWS\system32\ypcqfhlp.dll>
[]    <C:\WINDOWS\system32\apsgfjba.dll>
[]    <C:\WINDOWS\system32\mndhfdwd.dll>
[]    <C:\WINDOWS\system32\oohxdbyt.dll>
[]    <C:\WINDOWS\system32\ozfyebyt.dll>
[]    <C:\WINDOWS\system32\mpwdeapi.dll>
[]    <C:\WINDOWS\system32\ptjhehlp.dll>
[]    <C:\WINDOWS\system32\zptlcsys.dll>
[]    <C:\WINDOWS\system32\zycbdime.dll>
[]    <C:\Program Files\Internet Explorer\PLUGINS\Windows64.Sys>
[]    <C:\WINDOWS\system32\oswxdttb.dll>
[]    <C:\WINDOWS\system32\apzhctde.dll>
[]    <C:\WINDOWS\system32\zywlcime.dll>
[]    <C:\WINDOWS\system32\yxcschlp.dll>
[]    <C:\WINDOWS\system32\ietzbpaq.dll>
[]    <C:\Program Files\Internet Explorer\IEXPLORE32.win>
[]    <C:\Program Files\Internet Explorer\IEXPLORE32.Dat>

杀毒软件程序文件被破坏,建议卸载重装.
gototop
 

回复:又中招了,瑞星被屏蔽

这一步很重要:复制c:\windows\system32\dllcache\explorer.exe文件粘贴到c:\windows\文件夹内,提示替换时选“是”。

1.用XDelBox勾选抑制再生后删除以下文件:(XDelBox1.7支持奥运版下载)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入不检查路径,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。

c:\windows\system32\ietzbpaq.dll
c:\windows\system32\yzztkmsn.dll
c:\windows\conime.exe
c:\program files\internet explorer\iexplore32.dat
c:\program files\internet explorer\iexplore32.sys
c:\program files\internet explorer\plugins\windows64.sys
c:\windows\system32\cedafb.dll
c:\windows\system32\cliconfgzx.dll
c:\windows\system32\ddserh.dll
c:\windows\system32\fd233ds4f3.dll
c:\windows\system32\fmcvxy.dll
c:\windows\system32\hhrdxd.dll
c:\windows\system32\jfrwdh.dll
c:\windows\system32\mndhfdwd.dll
c:\windows\system32\mnmhgsrv.dll
c:\windows\system32\mpwdeapi.dll
c:\windows\system32\oohxdbyt.dll
c:\windows\system32\ozfyebyt.dll
c:\windows\system32\ptjhehlp.dll
c:\windows\system32\rfdswc.dll
c:\windows\system32\s2da2f323.dll
c:\windows\system32\sgrefg.dll
c:\windows\system32\tdffdl.dll
c:\windows\system32\wyhesm.dll
c:\windows\system32\ypcqghlp.dll
c:\windows\system32\yxcschlp.dll
c:\windows\system32\zgrjdx.dll
c:\windows\system32\zptlcsys.dll
c:\windows\system32\zycbdime.dll
c:\windows\system32\zywlcime.dll
c:\windows\system32\zyzxjime.dll
c:\program files\internet explorer\iexplore32.win
c:\program files\common files\microsoft shared\msinfo\system76.ins
c:\windows\system32\explorer.exe
c:\windows\system32\oswxdttb.dll
c:\windows\system32\jfdses.dll
c:\windows\system32\ypcqfhlp.dll
c:\windows\system32\apzhctde.dll
c:\windows\system32\zxmsdwin.dll
c:\windows\system32\apsgfjba.dll
c:\docume~1\admini~1\locals~1\temp\1.tmp

2.删除重启后使用SREng修复下面各项:

    启动项目 -- 注册表之如下项删除:
[cliconfgzx]   
[{4372FE4D-E2C2-45FE-A893-E2B1691A7DD0}]   
[{4A698102-5904-AFD0-20DF-CD1A65829CA4}]   
[{5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5}]   
[{37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73}]   
[{80AF1289-F140-A140-D012-C1458759FC08}]   
[{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7}]   
[{461D2AB4-29A5-45C2-9134-D52272D3DE38}]   
[{841529CB-7F77-4B99-A895-B5441E0D302F}]   
[{8C41B7F7-3168-400D-A702-0E7EFE0BA304}]   
[{45AADFAA-DD36-42AB-83AD-0521BBF58C24}]   
[{00050005-0005-0005-0005-00050005BB15}]   
[{C0595A7E-2E2F-4B34-A83A-019270A0A464}]   
[{A9895933-6636-4281-BC58-EE6DE2AF96E3}]   
[{1FD4696C-E95A-44E2-A03A-FDBDF4CCC305}]   
[{0B497AE8-3F6C-440C-AB87-52ED0182464A}]   
[{E6C0D0E3-9E9A-489D-AE19-BBCFC7047A59}]   
[{6C648541-1025-9650-9057-6541258720C6}]   
[{A693A5AB-BDBA-4AE7-A1C8-E41FEE1C020B}]   
[{29109876-7619-9101-7012-901938475192}]   
[{43512378-9874-5641-1025-985420368734}]   
[{5A069845-2036-6084-9054-6087502480A5}]   
[{81AF1CF6-D1C9-4C6A-AC01-EDE54E71945B}]   
[{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}]   
[{7C954872-1230-6541-9548-6541025884C7}]   
[{84143967-B645-4BFF-B873-DA1DC886E9A7}]   
[{528DF602-9541-A985-210A-984A698C6F25}]   
[{70AF1289-F140-A140-D012-C1458759FC07}]   
[{3D698451-2015-6358-9871-2015987452D3}]   
[{EB71E0B3-E97D-4D30-8733-E28266467617}]   
[{B490415F-65F8-B5C5-D8BA-9405FB12054B}]   
[{35671234-7890-ABCD-CDEF-567801237653}]   
[{A629FF4F-ACDB-5C90-A098-FACB3456A26A}]   
[{7A041F13-A111-12A3-B0CF-F99818AA68A7}]   
[{AA59145F-315D-BC23-AC1F-145DF81A34AA}]   
[{7C8D1401-A58D-A81C-CD24-A5915C4517C7}]   
[{6FD45A54-9875-698F-E56E-65102358FDF6}]   
[{55694105-5108-9405-3695-954187462155}]   
[{50940F85-F015-14F1-A05F-F69858AC6D05}]   
注意该项[AppInit_DLLs]修改:把<yzztkmsn.dll,ietzbpaq.dll mpackl.dll woasick.dll welldon.dll verptw.dll wpuplder.dll jordspa.dll>修改为<>即清空

    启动项目 -- 服务-- 驱动程序之如下项删除:
[IIS Manager  / IIS Manager ]

    系统修复-- 浏览器加载项之如下项删除:
[]    <C:\Program Files\Internet Explorer\IEXPLORE32.Sys>
[]    <C:\WINDOWS\system32\yzztkmsn.dll>
[]    <C:\WINDOWS\system32\zyzxjime.dll>
[]    <C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins>
[]    <C:\WINDOWS\system32\s2da2f323.dll>
[]    <C:\WINDOWS\system32\ypcqghlp.dll>
[]    <C:\WINDOWS\system32\fd233ds4f3.dll>
[]    <C:\WINDOWS\system32\mnmhgsrv.dll>
[]    <C:\WINDOWS\system32\zxmsdwin.dll>
[]    <C:\WINDOWS\system32\ypcqfhlp.dll>
[]    <C:\WINDOWS\system32\apsgfjba.dll>
[]    <C:\WINDOWS\system32\mndhfdwd.dll>
[]    <C:\WINDOWS\system32\oohxdbyt.dll>
[]    <C:\WINDOWS\system32\ozfyebyt.dll>
[]    <C:\WINDOWS\system32\mpwdeapi.dll>
[]    <C:\WINDOWS\system32\ptjhehlp.dll>
[]    <C:\WINDOWS\system32\zptlcsys.dll>
[]    <C:\WINDOWS\system32\zycbdime.dll>
[]    <C:\Program Files\Internet Explorer\PLUGINS\Windows64.Sys>
[]    <C:\WINDOWS\system32\oswxdttb.dll>
[]    <C:\WINDOWS\system32\apzhctde.dll>
[]    <C:\WINDOWS\system32\zywlcime.dll>
[]    <C:\WINDOWS\system32\yxcschlp.dll>
[]    <C:\WINDOWS\system32\ietzbpaq.dll>
[]    <C:\Program Files\Internet Explorer\IEXPLORE32.win>
[]    <C:\Program Files\Internet Explorer\IEXPLORE32.Dat>
[]    <C:\Program Files\Internet Explorer\IEXPLORE32.Sys>
[]    <C:\WINDOWS\system32\yzztkmsn.dll>
[]    <C:\WINDOWS\system32\zyzxjime.dll>
[]    <C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins>
[]    <C:\WINDOWS\system32\s2da2f323.dll>
[]    <C:\WINDOWS\system32\ypcqghlp.dll>
[]    <C:\WINDOWS\system32\fd233ds4f3.dll>
[]    <C:\WINDOWS\system32\mnmhgsrv.dll>
[]    <C:\WINDOWS\system32\zxmsdwin.dll>
[]    <C:\WINDOWS\system32\ypcqfhlp.dll>
[]    <C:\WINDOWS\system32\apsgfjba.dll>
[]    <C:\WINDOWS\system32\mndhfdwd.dll>
[]    <C:\WINDOWS\system32\oohxdbyt.dll>
[]    <C:\WINDOWS\system32\ozfyebyt.dll>
[]    <C:\WINDOWS\system32\mpwdeapi.dll>
[]    <C:\WINDOWS\system32\ptjhehlp.dll>
[]    <C:\WINDOWS\system32\zptlcsys.dll>
[]    <C:\WINDOWS\system32\zycbdime.dll>
[]    <C:\Program Files\Internet Explorer\PLUGINS\Windows64.Sys>
[]    <C:\WINDOWS\system32\oswxdttb.dll>
[]    <C:\WINDOWS\system32\apzhctde.dll>
[]    <C:\WINDOWS\system32\zywlcime.dll>
[]    <C:\WINDOWS\system32\yxcschlp.dll>
[]    <C:\WINDOWS\system32\ietzbpaq.dll>
[]    <C:\Program Files\Internet Explorer\IEXPLORE32.win>
[]    <C:\Program Files\Internet Explorer\IEXPLORE32.Dat>

做完下载以下软件清理一次并修复安装杀毒软件,更新杀毒软件至最新进行全盘杀毒一次

清理系统临时文件和IE临时文件夹
http://www.atribune.org/public-beta/ATF-Cleaner.exe
用金山清理专家清理恶意软件
http://www.duba.net/zt/ksc/down.shtml
下载 windows清理助手清理一遍
http://www.arswp.com/download/arswp2/arswp2.zip
不认识我没关系,因为我也不认识你。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT