1.建议使用XDelBox删除以下文件:(
XDelBox1.6下载)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
c:\windows\system32\msoscqet01.dll
c:\windows\system32\msosdrop01.dll
c:\windows\system32\msosfmsq01.dll
c:\windows\system32\msosjtfo01.dll
c:\windows\system32\awlvsm.dll
c:\windows\system32\ffffff.dll
c:\windows\system32\msoscqet00.dll
c:\windows\system32\msosdrop00.dll
c:\windows\system32\msosfmsq00.dll
c:\windows\system32\msosjtfo00.dll
c:\windows\system32\ytewcxzsw.dll
c:\windows\system32\wipicdec.dll
c:\windows\system32\xcvaver1.dll
c:\docume~1\admini~1\locals~1\temp\explorer.exe
c:\windows\system32\cccccc.dll
c:\windows\system32\sbwrlg.dll
c:\windows\system32\daxflj.dll
c:\windows\system32\iiiiii.dll
e:\解压缩\formats\ace.fmt
e:\解压缩\formats\arj.fmt
e:\解压缩\formats\bz2.fmt
e:\解压缩\formats\cab.fmt
e:\解压缩\formats\gz.fmt
e:\解压缩\formats\iso.fmt
e:\解压缩\formats\lzh.fmt
e:\解压缩\formats\tar.fmt
e:\解压缩\formats\uue.fmt
e:\解压缩\formats\z.fmt
syszxack.dll,msosdohs01.dll,nicozftp01.dll,sbwrlg.dll,wipicdec.dll,awlvsm.dll,msoscqet01.dll,msosdrop01.dll,msosjtfo01.dll,msosmhfp01.dll,msosmnsf01.dll,msosfmsq01.dll,ytewcxzsw.dll,ffffff.dll,iiiiii.dll,daxflj.dll
c:\windows\wipicdec.exe
c:\windows\isndntio.exe
c:\windows\wrew2ds.exe
c:\windows\dndsioc.exe
c:\windows\mfchlp64.exe
c:\windows\juejwcx.exe
c:\windows\ptshell.exe
c:\windows\ldwtariz.exe
c:\windows\fmsjhif.exe
c:\windows\dbhlp32.exe
c:\windows\bincdwsa.exe
c:\windows\fmsbbqi.exe
c:\windows\hefcndy.exe
c:\windows\yuiabct.exe
c:\windows\nbnwewd.exe
c:\windows\anistio.exe
c:\windows\ytewcxzsw.exe
c:\docume~1\admini~1\locals~1\temp\tmpb.tmp
c:\docume~1\admini~1\locals~1\temp\tmp7.tmp
c:\docume~1\admini~1\locals~1\temp\tmp95.tmp
c:\windows\system32\drivers\msosmsp2p32.sys
c:\windows\system32\drivers\msosmsfpfis64.sys
c:\docume~1\admini~1\locals~1\temp\tmp99.tmp
c:\docume~1\admini~1\locals~1\temp\tmp9f.tmp
c:\docume~1\admini~1\locals~1\temp\tmpa1.tmp
c:\docume~1\admini~1\locals~1\temp\tmp9d.tmp
c:\docume~1\admini~1\locals~1\temp\tmp9b.tmp
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
注意该项[AppInit_DLLs]修改:把<SysZxack.dll,msosdohs01.dll,nicozftp01.dll,sbwrlg.dll,wipicdec.dll,awlvsm.dll,msoscqet01.dll,msosdrop01.dll,msosjtfo01.dll,msosmhfp01.dll,msosmnsf01.dll,msosfmsq01.dll,ytewcxzsw.dll,ffffff.dll,iiiiii.dll,daxflj.dll>修改为<>即清空
[{C3D16072-2E1B-450B-B843-50EADDC8EB63}] <C:\WINDOWS\system32\xcvaver1.dll>
[wipicdec] <C:\WINDOWS\wipicdec.exe>
[isndntio] <C:\WINDOWS\isndntio.exe>
[wrew2ds] <C:\WINDOWS\wrew2ds.exe>
[dndsioc] <C:\WINDOWS\dndsioc.exe>
[mfchlp64] <C:\WINDOWS\mfchlp64.exe>
[juejwcx] <C:\WINDOWS\juejwcx.exe>
[ptshell] <C:\WINDOWS\ptshell.exe>
[slmdkwdt] <C:\WINDOWS\ldwtariz.exe>
[fmsjhif] <C:\WINDOWS\fmsjhif.exe>
[dbhlp32] <C:\WINDOWS\dbhlp32.exe>
[bincdwsa] <C:\WINDOWS\bincdwsa.exe>
[fmsbbqi] <C:\WINDOWS\fmsbbqi.exe>
[hefcndy] <C:\WINDOWS\hefcndy.exe>
[yuiabct] <C:\WINDOWS\yuiabct.exe>
[nbnwewd] <C:\WINDOWS\nbnwewd.exe>
[anistio] <C:\WINDOWS\anistio.exE>
[ytewcxzsw] <C:\WINDOWS\ytewcxzsw.exe>
启动项目 -- 服务-- 驱动程序之如下项禁用:
[dohs / dohs] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpB.tmp>
[mhfp / mhfp] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp7.tmp>
[zftp / zftp] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp95.tmp>
[msp2p32 / msp2p32] <\??\C:\WINDOWS\system32\drivers\msosmsp2p32.sys>
[msfpfis64 / msfpfis64] <\??\C:\WINDOWS\system32\drivers\msosmsfpfis64.sys>
[mnsf / mnsf] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp99.tmp>
[jtfo / jtfo] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp9F.tmp>
[fmsq / fmsq] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpA1.tmp>
[drop / drop] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp9D.tmp>
[cqet / cqet] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp9B.tmp>
**************以上分析报告由SREngLog分析助手提供******************分析:vistalong
时间:2008-6-7
SREngLog分析助手 1.3 (20070808 更新 BY 草莽书生)下载windows清理助手清理恶意软件 升级以后再使用
http://www.arswp.com/download/arswp2/arswp2.zip