1.建议使用XDelBox删除以下文件:(
XDelBox1.6下载)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
ukrth.dll,hjmh.dll,gyjert.dll,tjdegtr.dll,fyhje.dll,hgnmjsdg.dll,jkhjsd.dll,hjtdrh.dll,hyjmt.dll,fydgky.dll,ytjkyer.dll,dgrgfs.dll,gfcfg.dll,frntrn.dll,qrhhb.dll,drghszd.dll,fngn.dll,gnfctt.dll,xgnfn.dll,xfgnhcgfm.dll,serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,xfgnfx.dll,serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,xdndn.dll,xdfntt.dll,hgfhk.dll,dnteh.dll,xfng.dll,njritc.dll,chmfcmh.dll,jwlah.dll,gmnait.dll,hfjg.dll,thurh.dll,mgmgmm.dll,oqrthc.dll,dhugtj.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll,zdbdb.dll,ydgn.dll,dbfb.dll,fjnbv.dll,uyjtd.dll,setrhes.dll,cdxbfxdb.dll,xfgnxfn.dll,gjkhj.dll,xdhdg.dll,rhs.dll,mrjhtjd.dll,zdbfbd.dll,fjyjy.dll,fxnfnh.dll,bjrvm.dll,ektvm.dll,rdthr.dll,yjrfe.dll,dscef.dll,crugd.dll,lariytrz.dll,hjaiq.dll,kduy.dll,hkfgh.dll,awef.dll,dfhsh.dll,ethsh.dll,stehs.dll,sthth.dll,wfhyt.dll,rgghjj.dll,ghjkdr.dll,hfther.dll,
c:\progra~1\yahoo!\assist~1\ylive.exe
c:\program files\yahoo!\assistant\yassistse.exe
taskman.exe
c:\windows\qqqqqq.exe
c:\program files\internet explorer\plugins\dossys08.sys
c:\windows\system32\mmbaikok1092.dll
c:\windows\system32\mfdesy.dll
c:\windows\system32\mmmhxggd1061.dll
c:\windows\system32\mmkafnfw1097.dll
c:\windows\isscs32.exe
c:\windows\nbnwewd.exe
c:\windows\wrew2ds.exe
c:\windows\system32\drivers\svchost.exe
c:\windows\ticisms.exe
c:\windows\huifitc.exe
c:\windows\mfchlp64.exe
c:\windows\tciocp64.exe
c:\windows\hefcndy.exe
c:\windows\ponlclsy.exe
c:\windows\ptshell.exe
c:\windows\fmsbbqi.exe
c:\windows\381131m.exe
c:\windows\dbhlp32.exe
c:\windows\bincdwsa.exe
c:\windows\fmsjhif.exe
c:\windows\fmbiost.exe
c:\windows\dionpis.exe
c:\windows\issms32.exe
c:\windows\anistio.exe
c:\docume~1\aa\locals~1\temp\tmp18.tmp
c:\docume~1\aa\locals~1\temp\tmp24.tmp
c:\windows\system32\yvspqn
c:\docume~1\aa\locals~1\temp\tmp1a.tmp
c:\windows\system32\npkycryp.sys
c:\windows\system32\npkcrypt.sys
c:\windows\system32\drivers\msosmsp2p32.sys
c:\windows\system32\drivers\msosmsfpfis64.sys
c:\docume~1\aa\locals~1\temp\tmp2b.tmp
c:\docume~1\aa\locals~1\temp\tmp14.tmp
c:\docume~1\aa\locals~1\temp\1.tmp
c:\windows\system32\drivers\hdv32_c.sys
c:\windows\system32\drivers\ntgdt.sys
c:\windows\system32\ghjkdr.dll
c:\windows\system32\hjmh.dll
c:\windows\system32\ukrth.dll
c:\windows\system32\ytewcxzsw.dll
c:\windows\system32\wipxcdec.dll
c:\progra~1\yahoo!\assist~1\yalive.dll
c:\progra~1\yahoo!\assist~1\yalliveex.dll
c:\progra~1\yahoo!\assist~1\yhelper.dll
c:\program files\yahoo!\assistant\ynotifier.dll
c:\progra~1\yahoo!\assist~1\assist\yadfil~1.dll
c:\progra~1\yahoo!\assist~1\assist\yasfsks.dll
c:\progra~1\yahoo!\assist~1\assist\yasiesec.dll
c:\progra~1\yahoo!\assist~1\assist\yasnoad.dll
c:\progra~1\yahoo!\assist~1\assist\yaswiper.dll
c:\progra~1\yahoo!\assist~1\assist\ydrags~1.dll
c:\progra~1\yahoo!\assist~1\assist\yoptimum.dll
c:\progra~1\yahoo!\assist~1\assist\yrepair.dll
c:\progra~1\yahoo!\assist~1\assist\ysearch.dll
c:\progra~1\yahoo!\assist~1\assist\ysetti~1.dll
c:\progra~1\yahoo!\assist~1\assist\yxpstyle.dll
c:\progra~1\yahoo!\assist~1\assist\yzsnetproto.dll
c:\progra~1\yahoo!\assist~1\yscrblock.dll
c:\progra~1\yahoo!\assistant\shell\yassecblk.dll
c:\program files\yahoo!\assistant\assist\yangling.dll
c:\program files\yahoo!\assistant\assist\yasbar.dll
c:\program files\yahoo!\assistant\assist\yassist.dll
c:\program files\yahoo!\assistant\assist\yflashdl.dll
c:\program files\yahoo!\assistant\assist\ymailp.dll
c:\program files\yahoo!\assistant\assist\ymyweb.dll
c:\program files\yahoo!\assistant\assist\ypagetr.dll
c:\program files\yahoo!\assistant\assist\yphtb.dll
c:\program files\yahoo!\assistant\assist\yrss.dll
res://c:\program files\yahoo!\assistant\assist\yasbar.dll/203
res://c:\program files\yahoo!\assistant\assist\yrss.dll/yrssmenuext
http://cn.zs.yahoo.com/start.htm?source=yzs_icon&btn=yassistnewc:\program files\yahoo!\assistant\yalive.dll
c:\documents and settings\all users\application data\thunder network\kankan\pplayer.dll_1_work
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
注意该项[AppInit_DLLs]修改:把<ukrth.dll,hjmh.dll,gyjert.dll,tjdegtr.dll,fyhje.dll,hgnmjsdg.dll,jkhjsd.dll,hjtdrh.dll,hyjmt.dll,fydgky.dll,ytjkyer.dll,dgrgfs.dll,gfcfg.dll,frntrn.dll,qrhhb.dll,drghszd.dll,fngn.dll,gnfctt.dll,xgnfn.dll,xfgnhcgfm.dll,serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,xfgnfx.dll,serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,xdndn.dll,xdfntt.dll,hgfhk.dll,dnteh.dll,xfng.dll,njritc.dll,chmfcmh.dll,jwlah.dll,gmnait.dll,hfjg.dll,thurh.dll,mgmgmm.dll,oqrthc.dll,dhugtj.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll,zdbdb.dll,ydgn.dll,dbfb.dll,fjnbv.dll,uyjtd.dll,setrhes.dll,cdxbfxdb.dll,xfgnxfn.dll,gjkhj.dll,xdhdg.dll,rhs.dll,mrjhtjd.dll,zdbfbd.dll,fjyjy.dll,fxnfnh.dll,bjrvm.dll,ektvm.dll,rdthr.dll,yjrfe.dll,dscef.dll,crugd.dll,lariytrz.dll,hjaiq.dll,kduy.dll,hkfgh.dll,awef.dll,dfhsh.dll,ethsh.dll,stehs.dll,sthth.dll,wfhyt.dll,rgghjj.dll,ghjkdr.dll,hfther.dll,>修改为<>即清空
[YLive.exe] <C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[yassistse] <C:\Program Files\Yahoo!\Assistant\yAssistSe.exe>
[IFEO[Rav.exe]] <TASKMAN.EXE>
[IFEO[RavTask.exe]] <TASKMAN.EXE>
[ytewcxzsw] <C:\WINDOWS\qqqqqq.exe>
[{8AD0F1B1-990D-4F52-A33D-2837E43CEF58}] <C:\Program Files\Internet Explorer\PLUGINS\DosSys08.Sys>
[{18e64250-19a8-4d10-828f-30e101a22291}] <C:\WINDOWS\system32\MMBAIKOK1092.dll>
[{DC3D30AE-0380-4151-8934-EE98A34B0370}] <C:\WINDOWS\system32\mfdesy.dll>
[{c064c122-504c-4793-a16c-2b061dd0c774}] <C:\WINDOWS\system32\MMMHXGGD1061.dll>
[{d6763cab-b46e-4f7f-8347-6f098a83a164}] <C:\WINDOWS\system32\MMKAFNFW1097.dll>
[{398C9B84-4EF7-47B5-9862-DE29543B3C42}] <C:\Program Files\Internet Explorer\PLUGINS\DosSys08.Sys>
注意该项[AppInit_DLLs]修改:把<ukrth.dll,hjmh.dll,gyjert.dll,tjdegtr.dll,fyhje.dll,hgnmjsdg.dll,jkhjsd.dll,hjtdrh.dll,hyjmt.dll,fydgky.dll,ytjkyer.dll,dgrgfs.dll,gfcfg.dll,frntrn.dll,qrhhb.dll,drghszd.dll,fngn.dll,gnfctt.dll,xgnfn.dll,xfgnhcgfm.dll,serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,xfgnfx.dll,serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,xdndn.dll,xdfntt.dll,hgfhk.dll,dnteh.dll,xfng.dll,njritc.dll,chmfcmh.dll,jwlah.dll,gmnait.dll,hfjg.dll,thurh.dll,mgmgmm.dll,oqrthc.dll,dhugtj.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll,zdbdb.dll,ydgn.dll,dbfb.dll,fjnbv.dll,uyjtd.dll,setrhes.dll,cdxbfxdb.dll,xfgnxfn.dll,gjkhj.dll,xdhdg.dll,rhs.dll,mrjhtjd.dll,zdbfbd.dll,fjyjy.dll,fxnfnh.dll,bjrvm.dll,ektvm.dll,rdthr.dll,yjrfe.dll,dscef.dll,crugd.dll,lariytrz.dll,hjaiq.dll,kduy.dll,hkfgh.dll,awef.dll,dfhsh.dll,ethsh.dll,stehs.dll,sthth.dll,wfhyt.dll,rgghjj.dll,ghjkdr.dll,hfther.dll,>修改为<>即清空
[isscs32] <C:\WINDOWS\isscs32.exe>
[nbnwewd] <C:\WINDOWS\nbnwewd.exe>
[wrew2ds] <C:\WINDOWS\wrew2ds.exe>
[KVP] <C:\WINDOWS\system32\drivers\svchost.exe>
[ticisms] <C:\WINDOWS\ticisms.exe>
[huifitc] <C:\WINDOWS\huifitc.exe>
[mfchlp64] <C:\WINDOWS\mfchlp64.exe>
[tciocp64] <C:\WINDOWS\tciocp64.exe>
[hefcndy] <C:\WINDOWS\hefcndy.exe>
[xpjokncl] <C:\WINDOWS\ponlclsy.exe>
[ptshell] <C:\WINDOWS\ptshell.exe>
[fmsbbqi] <C:\WINDOWS\fmsbbqi.exe>
[WinSysM] <C:\WINDOWS\381131M.exe>
[dbhlp32] <C:\WINDOWS\dbhlp32.exe>
[bincdwsa] <C:\WINDOWS\bincdwsa.exe>
[fmsjhif] <C:\WINDOWS\fmsjhif.exe>
[fmbiost] <C:\WINDOWS\fmbiost.exe>
[dionpis] <C:\WINDOWS\dionpis.exe>
[issms32] <C:\WINDOWS\issms32.exe>
[anistio] <C:\WINDOWS\anistio.exE>
[anistio] <C:\WINDOWS\anistio.exE>
[ytewcxzsw] <C:\WINDOWS\qqqqqq.exe>
启动项目 -- 服务-- 驱动程序之如下项禁用:
[dohs / dohs] <\??\C:\DOCUME~1\aa\LOCALS~1\Temp\tmp18.tmp>
[zftp / zftp] <\??\C:\DOCUME~1\aa\LOCALS~1\Temp\tmp24.tmp>
[yvspqn / yvspqn] <\??\C:\WINDOWS\system32\yvspqn>
[tuic / tuic] <\??\C:\DOCUME~1\aa\LOCALS~1\Temp\tmp1A.tmp>
[npkycryp / npkycryp] <\??\C:\WINDOWS\system32\npkycryp.sys>
[npkcrypt / npkcrypt] <\??\C:\WINDOWS\system32\npkcrypt.sys>
[msp2p32 / msp2p32] <\??\C:\WINDOWS\system32\drivers\msosmsp2p32.sys>
[msfpfis64 / msfpfis64] <\??\C:\WINDOWS\system32\drivers\msosmsfpfis64.sys>
[mnsf / mnsf] <\??\C:\DOCUME~1\aa\LOCALS~1\Temp\tmp2B.tmp>
[mhfp / mhfp] <\??\C:\DOCUME~1\aa\LOCALS~1\Temp\tmp14.tmp>
[IIS Manager / IIS Manager ] <\??\C:\DOCUME~1\aa\LOCALS~1\Temp\1.tmp>
[Hdv32 / Hdv32] <\??\C:\WINDOWS\system32\drivers\Hdv32_c.sys>
[NTGDT / NTGDT] <\??\C:\WINDOWS\system32\Drivers\NTGDT.SYS>
系统修复-- 浏览器加载项之如下项删除:
[雅虎搜索] <res://C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll/203>
[添加到雅虎订阅(&Y)] <res://C:\Program Files\Yahoo!\Assistant\Assist\yrss.dll/YRSSMENUEXT>
[雅虎助手] <
http://cn.zs.yahoo.com/start.htm?source=yzs_icon&btn=yassistnew>
[雅虎助手] <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll>
[yFlashDl Class] <C:\Program Files\Yahoo!\Assistant\Assist\yflashdl.dll>
[Yahoo!Live] <C:\Program Files\Yahoo!\Assistant\yaLive.dll>
[DragSearch BHO] <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL>
[assist] <C:\Program Files\Yahoo!\Assistant\Assist\yassist.dll>
[AntiFish Class] <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll>
[雅虎助手] <C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll>
[yFlashDl Class] <C:\Program Files\Yahoo!\Assistant\Assist\yflashdl.dll>
[XPPlayer Class] <C:\Documents and Settings\All Users\Application Data\Thunder Network\KanKan\pplayer.dll_1_work>
[DragSearch BHO] <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL>
[assist] <C:\Program Files\Yahoo!\Assistant\Assist\yassist.dll>
[Yahoo!Photo] <C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll>
[AntiFish Class] <C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll>
[Yahoo!Photo] <C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll>
**************以上分析报告由SREngLog分析助手提供******************分析:vistalong
时间:2008-6-8
SREngLog分析助手 1.3 (20070808 更新 BY 草莽书生)下载windows清理助手清理恶意软件 升级以后再使用
http://www.arswp.com/download/arswp2/arswp2.zip