就这些:
要删除的文件:
c:\windows\system32\bjrvm.dll
c:\windows\system32\fghshj.dll
c:\windows\system32\fjnbv.dll
c:\windows\system32\frntrn.dll
c:\windows\system32\gjjte.dll
c:\windows\system32\hfjg.dll
c:\windows\system32\ijatnaw.dll
c:\windows\system32\jwlah.dll
c:\windows\system32\jyjlt.dll
c:\windows\system32\lariytrz.dll
c:\windows\system32\mgmgmm.dll
c:\windows\system32\rgfjj.dll
c:\windows\system32\sehhter.dll
c:\windows\system32\sperls.dll
c:\windows\system32\xgnfn.dll
c:\windows\system32\uresdqjknzxbrtyq.dll
c:\windows\system32\ayfkkfkk1055.dll
c:\windows\system32\msepbe.dll
c:\windows\system32\ttezzezz1046.dll
c:\windows\system32\ttnnbnnb1047.dll
c:\windows\system32\ttqacqac1038.dll
c:\windows\system32\ttvufvuf1011.dll
c:\windows\system32\lwias16_080427.dll
c:\windows\system32\inf\svchosts.exe
c:\windows\system32\qxxxxx.dll
c:\windows\system32\dld.exe
c:\windows\system32\lwias16_080427.dll
c:\windows\system32\uresdqjknzxbrtyq.dll
c:\windows\system32\kernel32.exe
c:\windows\system32\qwer.exe
c:\windows\system32\netsyssem.exe
c:\windows\system32\asdf.exe
c:\windows\ime\winupgrade.exe
c:\windows\system32\drivers\bd63.sys
c:\windows\system32\drivers\msosmsfpfis64.sys
c:\windows\system32\nessery.sys
c:\windows\system32\drivers\obj2.sys
c:\windows\system32\figsel.dll
c:\windows\system32\ietool.dll
D:\Autorun.inf
D:\MSDOS.PIF
E:\Autorun.inf
E:\MSDOS.PIF
启动项目
注册表
<LUOM><C:\WINDOWS\system32\DLD.exe> []
<nyuserinit><C:\WINDOWS\system32\inf\svchosts.exe C:\WINDOWS\system32\lwias16_080427.dll tanlt88> [N/A]
<{05922c2d-da84-48e8-a3e4-e797c58c39cf}><C:\WINDOWS\system32\ttEZZEZZ1046.dll> []
<{dc546cb1-0be7-4957-98c5-469b55a6923d}><C:\WINDOWS\system32\ttQACQAC1038.dll> []
<{29fab913-d0cd-477b-a3f0-3d7c3a90379b}><C:\WINDOWS\system32\ttVUFVUF1011.dll> []
<{c4bf46a2-1c05-427d-992f-4e24f7d57f68}><C:\WINDOWS\system32\ttNNBNNB1047.dll> []
<{6ce08af1-5f70-4c1a-8d1a-8aba11619e87}><C:\WINDOWS\system32\ayFKKFKK1055.dll> []
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <AppInit_DLLs><ghjdtry.dll,dgxsrr.dll,fdght.dll,rgghjj.dll,sefawe.dll,frntrn.dll,qrhhb.dll,drghszd.dll,fngn.dll,gjjte.dll,xgnfn.dll,xfgnhcgfm.dll,serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,xfgnfx.dll,serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,xdndn.dll,xdfntt.dll,hgfhk.dll,dnteh.dll,xfng.dll,njritc.dll,chmfcmh.dll,jwlah.dll,gmnait.dll,hfjg.dll,thurh.dll,mgmgmm.dll,oqrthc.dll,hktrre.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll,zdbdb.dll,ydgn.dll,dbfb.dll,fjnbv.dll,fghshj.dll,setrhes.dll,cdxbfxdb.dll,xfgnxfn.dll,gjkhj.dll,xdhdg.dll,rhs.dll,mrjhtjd.dll,zdbfbd.dll,fjyjy.dll,fxnfnh.dll,bjrvm.dll,ektvm.dll,rdthr.dll,rgfjj.dll,dscef.dll,crugd.dll,lariytrz.dll,hjaiq.dll,kduy.dll,hkfgh.dll,awef.dll,dfhsh.dll,ethsh.dll,stehs.dll,sthth.dll,wfhyt.dll,sperls.dll,> [N/A]
==================================
服务
[Windows Presentation Foundation (WPF) / applications][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k applications-->C:\WINDOWS\system32\UrEsdqJKNzxBrTYq.dll><N/A>
[kernel32 / kernel32][Running/Auto Start]
<c:\windows\system32\KERNEL32.exe><N/A>
[Distributed Link Tracking Client Service / LinkServic][Stopped/Auto Start]
<C:\WINDOWS\system32\qwer.exe><N/A>
[Networj System / NetSzstem][Stopped/Auto Start]
<C:\WINDOWS\system32\NetSyssem.exe><N/A>
[服务名 / svcname][Running/Auto Start]
<C:\WINDOWS\system32\asdf.exe><N/A>
[winfirewall / winfirewall][Running/Auto Start]
<C:\WINDOWS\ime\winupgrade.exe><N/A>
==================================
驱动程序
[bd6 / bd63][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\bd63.sys><N/A>
[msfpfis64 / msfpfis64][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosmsfpfis64.sys><N/A>
[Nessery / Nessery][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Nessery.sys><N/A>
[obj2 / obj2][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\DRIVERS\obj2.sys><N/A>
下面这个就不知道了
==================================
驱动程序
[RESSDT / RESSDT][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\ssdtti.sys><N/A>
==================================
浏览器加载项
[HTML Doucment]
{1B0A105E-5FB9-4507-835D-68794062C367} <C:\WINDOWS\system32\figsel.dll, >
[Thunder]
{BE830FD4-E393-417F-9F4B-CC70ABB3384C} <C:\WINDOWS\system32\IETool.dll, >
[HTML Doucment]
{1B0A105E-5FB9-4507-835D-68794062C367} <C:\WINDOWS\system32\figsel.dll, >
[Thunder]
{BE830FD4-E393-417F-9F4B-CC70ABB3384C} <C:\WINDOWS\system32\IETool.dll, >
下面这两个谨慎点看看文件。
==================================
正在运行的进程
[PID: 352 / SYSTEM][C:\WINDOWS\system32\acs.exe] [Atheros, 5.0.0.359]
[PID: 1468 / SYSTEM][C:\WINDOWS\system32\sc.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
==================================
HOSTS 文件
127.0.0.1 localhost
124.238.254.113
www.10280011.com124.238.254.113 10280011.com
124.238.254.113
www.10289900.com124.238.254.113 10289900.com
124.238.254.113
www.78877788.com124.238.254.113 78877788.com
124.238.254.113
www.11051122.com124.238.254.113 11051122.com
124.238.254.113 1.ehai01.com
124.238.254.113 da.ehai01.com
124.238.254.113 ehai01.com
124.238.254.113 2008.sekart.cn
124.238.254.113
www.sekart.cn124.238.254.113 sekart.cn
124.238.254.113
www.11309988.com124.238.254.113
www.12100088.com124.238.254.113
www.12108899.com124.238.254.113 d2.llsging.com
124.238.254.113 llsging.com
124.238.254.113 dd.749571.com
124.238.254.113 749571.com
124.238.254.113 pr.749571.com
124.238.254.113 txwm1204.com
124.238.254.113
www.txwm1204.com其他盘看看有没Autorun.inf和MSDOS.PIF