删除
c:\docume~1\admini~1\locals~1\temp\dat2c.tmp
c:\docume~1\admini~1\locals~1\temp\dat68.tmp
c:\program files\internet explorer\plugins\ns_sys55.sys
c:\program files\winrar\rarext.dll
c:\windows\system32\cmdbcs.dll
c:\windows\system32\dbghlp32.dll
c:\windows\system32\dscef.dll
c:\windows\system32\eohsom.dll
c:\windows\system32\fifeei.dll
c:\windows\system32\gnolnait.dll
c:\windows\system32\gsfnbr.dll
c:\windows\system32\ijougiemnaw.dll
c:\windows\system32\kvsc3.dll
c:\windows\system32\lotushlp.dll
c:\windows\system32\mnauygniqaixnaij.dll
c:\windows\system32\msccrt.dll
c:\windows\system32\msosiocp.dll
c:\windows\system32\pahzij.dll
c:\windows\system32\pedadt.dll
c:\windows\system32\ptsshell.dll
c:\windows\system32\rzysdhbx.dll
c:\windows\system32\setup\en_1072.bin
c:\windows\system32\taijoad.dll
c:\windows\system32\tsqc.dll
c:\windows\system32\upxdnd.dll
c:\windows\system32\wsockdrv32.dll
c:\windows\system32\xbcvxb.dll
c:\windows\system32\xfgnxfn.dll
d:\handwrite\hsengine.dll
mrjhtjd.dll,qrhhb.dll,xdfntt.dll,hgfhk.dll,hjaiq.dll,kduy.dll,frntrn.dll,dnteh.dll,chmfcmh.dll,jwlah.dll,crugd.dll,lariytrz.dll,thurh.dll,mgmgmm.dll,oqrthc.dll,ydgn.dll,dbfb.dll,fjnbv.dll,wmsat.dll,gmnait.dll,hfjg.dll,xdndn.dll,rgfjj.dll,dscef.dll,xfng.dll,njritc.dll,setrhes.dll,cdxbfxdb.dll,xfgnxfn.dll,gjkhj.dll,fxnfnh.dll,bjrvm.dll,ektvm.dll,fehom.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll,zdbdb.dll,rhs.dll,atehhz.dll,gjjte.dll,xgnfn.dll,xfgnhcgfm.dll,serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,xfgnfx.dll,serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,hkfgh.dll,drghszd.dll,fngn.dll,xdhdg.dll,zdbfbd.dll,fjyjy.dll,,msosdrop00.dll,msosdohs00.dll,msosmhfp00.dll
c:\windows\ptsshell.exe
c:\windows\lotushlp.exe
c:\windows\dbghlp32.exe
c:\windows\wsockdrv32.exe
c:\windows\cmdbcs.exe
c:\windows\msccrt.exe
c:\windows\kvsc3.exe
c:\windows\gwsmhxuq.exe
c:\windows\upxdnd.exe
c:\windows\shaproc.exe
"c:\windows\system32\rundll32.exe" "c:\windows\system32\shell32.dll",control_rundll "c:\docume~1\admini~1\locals~1\temp\dat2c.tmp"
c:\windows\system32\75d23be4.exe -d
c:\docume~1\admini~1\locals~1\temp\tmp3a.tmp
c:\docume~1\admini~1\locals~1\temp\tmp25.tmp
c:\docume~1\admini~1\locals~1\temp\tmp16.tmp
http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg
2.删除重启后使用SREng修复下面各项:
启动项目 -- 注册表之如下项删除:
[{7FA4A83B-F99A-4bfc-A8E2-6A62B05D2C82}] <C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dat2C.tmp>
注意该项[AppInit_DLLs]修改:把<mrjhtjd.dll,qrhhb.dll,xdfntt.dll,hgfhk.dll,hjaiq.dll,kduy.dll,frntrn.dll,dnteh.dll,chmfcmh.dll,jwlah.dll,crugd.dll,lariytrz.dll,thurh.dll,mgmgmm.dll,oqrthc.dll,ydgn.dll,dbfb.dll,fjnbv.dll,wmsat.dll,gmnait.dll,hfjg.dll,xdndn.dll,rgfjj.dll,dscef.dll,xfng.dll,njritc.dll,setrhes.dll,cdxbfxdb.dll,xfgnxfn.dll,gjkhj.dll,fxnfnh.dll,bjrvm.dll,ektvm.dll,fehom.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll,zdbdb.dll,rhs.dll,atehhz.dll,gjjte.dll,xgnfn.dll,xfgnhcgfm.dll,serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,xfgnfx.dll,serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,hkfgh.dll,drghszd.dll,fngn.dll,xdhdg.dll,zdbfbd.dll,fjyjy.dll,,msosdrop00.dll,msosdohs00.dll,msosmhfp00.dll>修改为<>即清空
[PTSShell] <C:\WINDOWS\PTSShell.exe>
[LotusHlp] <C:\WINDOWS\LotusHlp.exe>
[DbgHlp32] <C:\WINDOWS\DbgHlp32.exe>
[WSockDrv32] <C:\WINDOWS\WSockDrv32.exe>
[cmdbcs] <C:\WINDOWS\cmdbcs.exe>
[msccrt] <C:\WINDOWS\msccrt.exe>
[Kvsc3] <C:\WINDOWS\Kvsc3.exE>
[igzwzslm] <C:\WINDOWS\gwsmhxuq.exe>
[upxdnd] <C:\WINDOWS\upxdnd.exe>
[SHAProc] <C:\WINDOWS\SHAProc.exe>
[WinShell] <"C:\WINDOWS\system32\Rundll32.exe" "C:\WINDOWS\system32\shell32.dll",Control_RunDLL "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dat2C.tmp">
启动项目 -- 服务 -- Win32服务应用程序之如下项删除:
[Error Reporting Service / ERSvc] <>
[Error Reporting Service / ERSvc] <>
[B302EC43 / B302EC43] <C:\WINDOWS\system32\75D23BE4.EXE -d>
启动项目 -- 服务-- 驱动程序之如下项删除:
[drop / drop] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp3A.tmp>
[dohs / dohs] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp25.tmp>
[mhfp / mhfp] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp16.tmp>
系统修复-- 浏览器加载项之如下项删除:
[情景聊天] <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg>
[] <C:\Program Files\Internet Explorer\PLUGINS\Ns_Sys55.Sys>
[] <C:\Program Files\Internet Explorer\PLUGINS\Ns_Sys55.Sys>