先下载附件 解压 记住保存的路径
参考这里:
http://bbs.ikaka.com/showtopic-8502100.aspx下载PE安装并下载附件里的“费尔木马强力清除助手”,
重起进入安全模式删除以下文件:
c:\windows\system32\msoscqit00.dll
c:\windows\system32\msosdohs00.dll
c:\windows\system32\msosfmsq00.dll
c:\windows\system32\msosmnsf00.dll
c:\windows\system32\msosping00.dll
c:\docume~1\admini~1\locals~1\temp\rsv17.tmp
c:\windows\system32\dnteh.dll
c:\windows\system32\fdght.dll
c:\windows\system32\sperls.dll
c:\windows\system32\mndscsrv.dll
c:\program files\internet explorer\plugins\winsys16.sys
c:\windows\system32\aennjo.dll
c:\windows\system32\anistio.dll
c:\windows\system32\bincdwsa.dll
c:\windows\system32\dbhlp32.dll
c:\windows\system32\dqabcabc1031.dll
c:\windows\system32\dqbaibai1067.dll
c:\windows\system32\dqdabdab1071.dll
c:\windows\system32\dqezzezz1056.dll
c:\windows\system32\dqwlvwlv1014.dll
c:\windows\system32\fgtnos.dll
c:\windows\system32\fiosectc.dll
c:\windows\system32\fmbiost.dll
c:\windows\system32\fmsjhif.dll
c:\windows\system32\fzdcrs.dll
c:\windows\system32\gnbxbv.dll
c:\windows\system32\huifitc.dll
c:\windows\system32\hwahwd.dll
c:\windows\system32\ijexwc.dll
c:\windows\system32\keunxm.dll
c:\windows\system32\lywliu.dll
c:\windows\system32\mmaaamtm1038.dll
c:\windows\system32\mmbaikok1071.dll
c:\windows\system32\mmdabluu1076.dll
c:\windows\system32\mmdlqjer1010.dll
c:\windows\system32\mmezzpop1062.dll
c:\windows\system32\mmhadpqg1072.dll
c:\windows\system32\mmkafnfw1075.dll
c:\windows\system32\mmmysbdr1054.dll
c:\windows\system32\mmmysbdr1055.dll
c:\windows\system32\mmnnbhdr1057.dll
c:\windows\system32\mmsadzfb1045.dll
c:\windows\system32\rzysdhbx.dll
c:\windows\system32\ticisms.dll
c:\windows\system32\ttdlqdlq1009.dll
c:\windows\system32\ttkafkaf1072.dll
c:\windows\system32\ttnnbnnb1056.dll
c:\windows\system32\winsvr64.dll
c:\windows\system32\wnkdif.dll
c:\windows\system32\x016q7r9s1.dll
c:\windows\system32\yksuyc.dll
c:\windows\system32\yuiabct.dll
c:\windows\fiosectc.exe
c:\windows\anistio.exe
c:\windows\fmbiost.exe
c:\windows\huifitc.exe
c:\windows\yuiabct.exe
c:\windows\winsvr64.exe
c:\windows\bincdwsa.exe
c:\windows\ticisms.exe
c:\windows\fmsjhif.exe
c:\windows\dbhlp32.exe
c:\windows\gwsmhxuq.exe
c:\windows\lssas.exe
C:\WINDOWS\RSHIDE
c:\windows\system32\drivers\w9i11.sys
c:\docume~1\admini~1\locals~1\temp\tmp3e.tmp
c:\windows\system32\drivers\msosmsp2p32.sys
c:\windows\system32\drivers\msosmsfpfis64.sys
c:\docume~1\admini~1\locals~1\temp\tmpb.tmp
c:\windows\temp\tmp1.tmp
c:\docume~1\admini~1\locals~1\temp\tmp42.tmp
c:\docume~1\admini~1\locals~1\temp\tmp8.tmp
c:\docume~1\admini~1\locals~1\temp\tmp46.tmp
删除完文件以后还有个很重要的要做:复制刚才下载的附件里的两文件 全部粘贴到c:\windows\system32\文件夹里 提示替换的时候选“是”
这一步很重要 没替换的话重起可能又来一堆木马
2.上面的做完以后重启进入安全模式或者正常模式,使用SREng修复下面各项:
启动项目 -- 注册表之如下项删除:
[{8472766e-ee81-412c-91f9-7454ca6b9e15}]
[{bdd43303-267b-4853-b19a-17a9630004c3}]
[{4211ec0a-2f8b-4140-ad1b-a1b07e0ab4a5}]
[{1f46cbfa-d110-49b9-8ab4-f88c7e60fa09}]
[{27326302-f5f0-4f9d-a8ff-24a62328ef38}]
[{75308caa-9a15-491a-9535-3cba0d617f5b}]
[{37FD640A-158F-48AC-FD14-1597F14A9773}]
[{630662c4-3282-44ea-8c6a-c2866bac1316}]
[{ff3456d7-4846-4354-93ca-ea6453c97b00}]
[{f409f282-451b-400a-93ed-f83e11bb930a}]
[{c6512f3d-dd9b-403a-8099-6216c783214d}]
[{FCEAF8AB-7DC0-4E09-8E8D-163C1024E04B}]
[{67ba0720-e5a5-4b59-92cc-63faf4816f27}]
[{1950369a-7bb1-4235-83a3-054b26f1943b}]
注意该项[AppInit_DLLs]修改:把<ghjdtry.dll,dgxsrr.dll,fdght.dll,rgghjj.dll,sefawe.dll,frntrn.dll,qrhhb.dll,drghszd.dll,fngn.dll,gjjte.dll,xgnfn.dll,xfgnhcgfm.dll,serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,xfgnfx.dll,serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,xdndn.dll,xdfntt.dll,hgfhk.dll,dnteh.dll,xfng.dll,njritc.dll,chmfcmh.dll,jwlah.dll,gmnait.dll,hfjg.dll,thurh.dll,mgmgmm.dll,oqrthc.dll,hktrre.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll,zdbdb.dll,ydgn.dll,dbfb.dll,fjnbv.dll,fghshj.dll,setrhes.dll,cdxbfxdb.dll,xfgnxfn.dll,gjkhj.dll,xdhdg.dll,rhs.dll,mrjhtjd.dll,zdbfbd.dll,fjyjy.dll,fxnfnh.dll,bjrvm.dll,ektvm.dll,rdthr.dll,rgfjj.dll,dscef.dll,crugd.dll,lariytrz.dll,hjaiq.dll,kduy.dll,hkfgh.dll,awef.dll,dfhsh.dll,ethsh.dll,stehs.dll,sthth.dll,wfhyt.dll,sperls.dll,,msoscqit00.dll,msosfmsq00.dll,msosmnsf00.dll,msosdohs00.dll,msosping00.dll>修改为<>即清空
[fiosectc]
[anistio]
[fmbiost]
[huifitc]
[yuiabct]
[WINSvr64]
[bincdwsa]
[ticisms]
[fmsjhif]
[dbhlp32]
[igzwzslm]
启动项目 -- 服务 -- Win32服务应用程序之如下项删除:
[NetMeeting Remote Desktop / NetMeeting Remote Desktop Shar]
启动项目 -- 服务-- 驱动程序之如下项删除:
[1xfc / 1xfc]
[1xfc / 1xfc]
[1xfc / 1xfc]
[w9i1 / w9i11]
[ping / ping]
[msp2p32 / msp2p32]
[msfpfis64 / msfpfis64]
[mnsf / mnsf]
[mhfp / mhfp]
[fmsq / fmsq]
[dohs / dohs]
[cqit / cqit]
系统修复-- 浏览器加载项之如下项删除:
[] <C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys>
[] <C:\WINDOWS\system32\mndscsrv.dll>
[] <C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys>
[] <C:\WINDOWS\system32\mndscsrv.dll>
最后下载以下软件清理一次并更新杀毒软件至最新进行全盘杀毒
清理系统临时文件和IE临时文件夹
http://www.atribune.org/public-beta/ATF-Cleaner.exe 用金山清理专家清理恶意软件
http://www.duba.net/zt/ksc/down.shtml 下载 windows清理助手清理一遍
http://www.arswp.com/download/arswp2/arswp2.zip