1.建议使用XDelBox删除以下文件:(
XDelBox1.3下载)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
c:\windows\system32\1pkti2vz.exe
c:\windows\system32\29p9p59f1yc.exe
c:\windows\344un8lteuqw.exe
c:\windows\system32\3w0zfgtbz.exe
c:\windows\6327wufc.exe
c:\windows\7ab4yw75ze2z.exe
c:\windows\system32\8y4n7sr965.exe
c:\windows\system32\a1rncx2.exe
c:\windows\system32\b3aiv9dbo.exe
c:\windows\system32\blur4crc.exe
c:\windows\dfg3q43hd.exe
c:\windows\dsuw7.exe
c:\windows\exg0ygz6.exe
c:\windows\f80bbmkkf.exe
c:\windows\gb2umn735.exe
c:\windows\hf1xve.exe
c:\windows\system32\intx8st27zl.exe
c:\windows\system32\jgk1ccz.exe
c:\windows\system32\jmneoip1czs.exe
c:\windows\jvjgplump3.exe
c:\windows\lf61iwrsyy5.exe
c:\windows\system32\mpacqxo3yi.exe
c:\windows\system32\ntsvc.ocx
c:\windows\mxn0oq.exe
c:\windows\system32\qkzgg.exe
c:\windows\qrz12u.exe
c:\windows\qw02y2n054.exe
c:\windows\usnsvc.exe
c:\windows\system32\so1o34ii5.exe
c:\windows\system32\sq1rc02cxkw1.exe
c:\windows\syd67ouef6a.exe
c:\windows\system32\u39eecy.exe
c:\windows\xctu887mc.exe
c:\windows\system32\inf\rundll33.exe
c:\documents and settings\all users\「开始」菜单\程序\启动\k9xa8pnkqv2.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\t6j232.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\uiwaw.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\nbg9643omf7c.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\f93sbkor.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\20axkcqt.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\hbwsypue73xi.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\j54w6wu.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\p8lsdozuej8.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\l091ar7.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\gzwlh523z2d5.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\lrl26l02x.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\usqbjq.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\wxmcdm6.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\peggkihz4.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\7g84p4fdad3a.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\pij061l.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\hv5zz1qal.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\gi1k5k7.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\wafz5zx4i771.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\i0kvzh572h.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\c3ax4vchdv.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\15jh1.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\rdh53d9nek1s.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\k9g8vsc40.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\2cxmvyzv.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\4vub0chnw4o5.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\gqa6qkxcxz6.lnk
c:\documents and settings\all users\「开始」菜单\程序\启动\xccstart.lnk
c:\windows\dsuw7.exe -4v6wtnh
c:\windows\exg0ygz6.exe -onlu1i0m5o5b
c:\windows\f80bbmkkf.exe -ehr38mxb1mr7
c:\windows\344un8lteuqw.exe -3q6j56
c:\windows\gb2umn735.exe -nsa2y
c:\windows\hf1xve.exe -sq2gtid
c:\windows\system32\3w0zfgtbz.exe -6uiydpjw7wp
c:\windows\system32\intx8st27zl.exe -7w4qt22xlfz
c:\windows\system32\jgk1ccz.exe -oywtinayv
c:\windows\system32\jmneoip1czs.exe -y7eiw
c:\windows\jvjgplump3.exe -hym5f
c:\windows\lf61iwrsyy5.exe -4i5vo95cd
c:\windows\6327wufc.exe -87tr7vh87
c:\windows\7ab4yw75ze2z.exe -clohk7e3
c:\windows\system32\mpacqxo3yi.exe -fnwdn42xla
c:\windows\system32\8y4n7sr965.exe -cy18zof3xkli
c:\windows\system32\a1rncx2.exe -4mb4t4ci56f
c:\windows\mxn0oq.exe -wxdqsg8
c:\windows\system32\qkzgg.exe -r86rh0
c:\windows\qrz12u.exe -ddy75ixd
c:\windows\qw02y2n054.exe -fy2bh5fk1k2m
c:\windows\system32\so1o34ii5.exe -6fr1y2s4ql
c:\windows\system32\sq1rc02cxkw1.exe -szatv
c:\windows\system32\1pkti2vz.exe -4c9ujp0
c:\windows\syd67ouef6a.exe -0ydqrxzv0
c:\windows\system32\29p9p59f1yc.exe -8umx8a
c:\windows\system32\u39eecy.exe -nuimanjmgx4q
c:\windows\system32\b3aiv9dbo.exe -zs6wq6a65
c:\windows\xctu887mc.exe -2bj8btblw
c:\windows\system32\blur4crc.exe -g6qzber8
c:\windows\vnyrb4p1.exe -ctdj3
c:\windows\system32\rw6db.exe -xar2tzl
c:\windows\82d053udwpm.txt
c:\windows\es6hyvtvt4pd.txt
c:\docume~1\owner\locals~1\temp\tmp54.tmp
c:\windows\ogk5kaoptyti.txt
c:\windows\zlzk4es.txt
c:\windows\system32\drivers\tcpsr.sys
c:\docume~1\owner\locals~1\temp\tmp62.tmp
c:\windows\system32\drivers\nsx73.sys
c:\windows\3m7b5q2r65.txt
c:\docume~1\owner\locals~1\temp\tmp5a.tmp
c:\docume~1\owner\locals~1\temp\~wxp2ins.109.tmp
c:\windows\system32\drivers\rspp.sys
2.删除重启后使用SREng修复下面各项: 启动项目 -- 启动文件夹之如下项删除:
[K9XA8PNKQV2] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\K9XA8PNKQV2.lnk>
[T6J232] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\T6J232.lnk>
[UIWAW] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\UIWAW.lnk>
[NBG9643OMF7C] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\NBG9643OMF7C.lnk>
[F93SBKOR] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\F93SBKOR.lnk>
[20AXKCQT] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\20AXKCQT.lnk>
[HBWSYPUE73XI] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\HBWSYPUE73XI.lnk>
[J54W6WU] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\J54W6WU.lnk>
[P8LSDOZUEJ8] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\P8LSDOZUEJ8.lnk>
[L091AR7] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\L091AR7.lnk>
[GZWLH523Z2D5] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\GZWLH523Z2D5.lnk>
[LRL26L02X] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\LRL26L02X.lnk>
[USQBJQ] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\USQBJQ.lnk>
[WXMCDM6] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\WXMCDM6.lnk>
[PEGGKIHZ4] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\PEGGKIHZ4.lnk>
[7G84P4FDAD3A] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\7G84P4FDAD3A.lnk>
[PIJ061L] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\PIJ061L.lnk>
[HV5ZZ1QAL] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\HV5ZZ1QAL.lnk>
[GI1K5K7] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\GI1K5K7.lnk>
[WAFZ5ZX4I771] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\WAFZ5ZX4I771.lnk>
[I0KVZH572H] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\I0KVZH572H.lnk>
[C3AX4VCHDV] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\C3AX4VCHDV.lnk>
[15JH1] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\15JH1.lnk>
[RDH53D9NEK1S] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\RDH53D9NEK1S.lnk>
[K9G8VSC40] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\K9G8VSC40.lnk>
[2CXMVYZV] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\2CXMVYZV.lnk>
[4VUB0CHNW4O5] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\4VUB0CHNW4O5.lnk>
[GQA6QKXCXZ6] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\GQA6QKXCXZ6.lnk>
[xccstart] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\xccstart.lnk>
启动项目 -- 服务 -- Win32服务应用程序之如下项删除:
[APGV2Q / DSUW7] <C:\WINDOWS\DSUW7.exe -4V6WTNH>
[QBLFZFVV / EXG0YGZ6] <C:\WINDOWS\EXG0YGZ6.exe -ONLU1I0M5O5B>
[QBLFZFVV / EXG0YGZ6] <C:\WINDOWS\EXG0YGZ6.exe -ONLU1I0M5O5B>
[4SDK28ITDDH / F80BBMKKF] <C:\WINDOWS\F80BBMKKF.exe -EHR38MXB1MR7>
[946B8FA9N / 344UN8LTEUQW] <C:\WINDOWS\344UN8LTEUQW.exe -3Q6J56>
[73C5ZCHWFAD7 / GB2UMN735] <C:\WINDOWS\GB2UMN735.exe -NSA2Y>
[PZKAUGY / HF1XVE] <C:\WINDOWS\HF1XVE.exe -SQ2GTID>
[2WFSGS4H9W1 / 3W0ZFGTBZ] <C:\WINDOWS\system32\3W0ZFGTBZ.exe -6UIYDPJW7WP>
[5M6P1V / INTX8ST27ZL] <C:\WINDOWS\system32\INTX8ST27ZL.exe -7W4QT22XLFZ>
[B3K6FUT8 / JGK1CCZ] <C:\WINDOWS\system32\JGK1CCZ.exe -OYWTINAYV>
[Q5UYTX0 / JMNEOIP1CZS] <C:\WINDOWS\system32\JMNEOIP1CZS.exe -Y7EIW>
[DSP9GVZU / JVJGPLUMP3] <C:\WINDOWS\JVJGPLUMP3.exe -HYM5F>
[ZCW3N / LF61IWRSYY5] <C:\WINDOWS\LF61IWRSYY5.exe -4I5VO95CD>
[FVH5S66AXGU / 6327WUFC] <C:\WINDOWS\6327WUFC.exe -87TR7VH87>
[21JJNHJNQ850 / 7AB4YW75ZE2Z] <C:\WINDOWS\7AB4YW75ZE2Z.exe -CLOHK7E3>
[EU968 / MPACQXO3YI] <C:\WINDOWS\system32\MPACQXO3YI.exe -FNWDN42XLA>
[CL2UUF78JY6L / 8Y4N7SR965] <C:\WINDOWS\system32\8Y4N7SR965.exe -CY18ZOF3XKLI>
[84KW52W2 / A1RNCX2] <C:\WINDOWS\system32\A1RNCX2.exe -4MB4T4CI56F>
[3NZV372 / MXN0OQ] <C:\WINDOWS\MXN0OQ.exe -WXDQSG8>
[UPX6CR4NGCO3 / QKZGG] <C:\WINDOWS\system32\QKZGG.exe -R86RH0>
[4KEVOJWPCU / QRZ12U] <C:\WINDOWS\QRZ12U.exe -DDY75IXD>
[CNVW1WJN6 / QW02Y2N054] <C:\WINDOWS\QW02Y2N054.exe -FY2BH5FK1K2M>
[XAHTD9CY0LKN / SO1O34II5] <C:\WINDOWS\system32\SO1O34II5.exe -6FR1Y2S4QL>
[BEQS5N6WZW / SQ1RC02CXKW1] <C:\WINDOWS\system32\SQ1RC02CXKW1.exe -SZATV>
[0ON5M0CADKDG / 1PKTI2VZ] <C:\WINDOWS\system32\1PKTI2VZ.exe -4C9UJP0>
[TYJCIDQBUW / SYD67OUEF6A] <C:\WINDOWS\SYD67OUEF6A.exe -0YDQRXZV0>
[QG0A72M4JMBN / 29P9P59F1YC] <C:\WINDOWS\system32\29P9P59F1YC.exe -8UMX8A>
[68K3F2H / U39EECY] <C:\WINDOWS\system32\U39EECY.exe -NUIMANJMGX4Q>
[IJCQC0 / B3AIV9DBO] <C:\WINDOWS\system32\B3AIV9DBO.exe -ZS6WQ6A65>
[C1YZD / XCTU887MC] <C:\WINDOWS\XCTU887MC.exe -2BJ8BTBLW>
[PREA7CDS / BLUR4CRC] <C:\WINDOWS\system32\BLUR4CRC.exe -G6QZBER8>
[0X549CTWM8 / VNYRB4P1] <C:\WINDOWS\VNYRB4P1.exe -CTDJ3>
[AXVJ4QYJ2O / RW6DB] <C:\WINDOWS\system32\RW6DB.exe -XAR2TZL>
启动项目 -- 服务-- 驱动程序之如下项删除:
[JSQ7AS / 8QP4YC4NNDE] <\??\C:\WINDOWS\82D053UDWPM.txt>
[6VLYFD0SJ / BMBJG] <\??\C:\WINDOWS\ES6HYVTVT4PD.txt>
[zftp / zftp] <\??\C:\DOCUME~1\Owner\LOCALS~1\Temp\tmp54.tmp>
[7TT1P2FA70 / YROAQYC0L] <\??\C:\WINDOWS\OGK5KAOPTYTI.txt>
[5S5V5GBD1YV / WUM0EQ] <\??\C:\WINDOWS\ZLZK4ES.txt>
[tcpsr / tcpsr] <\??\C:\WINDOWS\System32\drivers\tcpsr.sys>
[ptfs / ptfs] <\??\C:\DOCUME~1\Owner\LOCALS~1\Temp\tmp62.tmp>
[Nsx73 / Nsx73] <\SystemRoot\System32\Drivers\Nsx73.sys>
[4C04IA / N6AWL9JAJDA0] <\??\C:\WINDOWS\3M7B5Q2R65.txt>
[fmsq / fmsq] <\??\C:\DOCUME~1\Owner\LOCALS~1\Temp\tmp5A.tmp>
[Atixeve27296 / Atixeve27296] <\??\C:\DOCUME~1\Owner\LOCALS~1\Temp\~wxp2ins.109.tmp>
[rspp / rspp] <\??\C:\WINDOWS\system32\Drivers\Rspp.sys>
**************以上分析报告由SREngLog分析助手提供******************分析:草莽书生
时间:2008-9-6
SREngLog分析助手 1.3 (20070808 更新 BY 草莽书生)自动清理方案操作步骤:1。下载通用病毒杀灭机正式版(
点击下载),请先参考软件帮助说明。
2。复制符号区域的修复指令或者下载附件中的修复指令文件*.dat 。
========指令正文,复制以下内容========
复制指令区
========指令结束,复制以上内容========3。打开通用病毒杀灭机(打不开的建议改名,如abc.exe,abc.bat等),复制修复指令者使用剪贴板导入;下载修复指令文件的使用文件导入
重启即可删除病毒,并帮助你删除自启动项和禁用服务。
(注:第一次重启有时候会弹出文件夹,那是由于自启动项目还没有删除,而文件已经被XDELBOX删除并用文件夹替代的结果)