先断网
1.建议使用XDelBox删除以下文件:(
XDelBox1.3下载
)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后
在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最
好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
c:\autorun.pif
c:\Autorun.inf
d:\Autorun.inf
d:\Autorun.pif
c:\windows\system32\system.exe
c:\windows\dllhost.exe
c:\windows\system32\hbasktao.dll
c:\windows\system32\hbdnf.dll
c:\windows\system32\hbmhly.dll
c:\windows\system32\hbqqsg.dll
c:\windows\system32\hbtl.dll
c:\windows\system32\hbwd.dll
c:\windows\system32\hbxmj.dll
c:\windows\system32\hbyy.dll
c:\windows\system32\hbzhuxian.dll
c:\windows\system32\08223b03.dll
c:\windows\system32\4fbfd5a4.dll
c:\windows\system32\58ff3024.dll
c:\windows\system32\5934ea2b.dll
c:\windows\system32\70b0129e.dll
c:\windows\system32\a1a6bc2e.dll
c:\windows\system32\ad794e6b.dll
c:\windows\system32\d7c79813.dll
c:\windows\system32\da63e650.dll
c:\windows\system32\e3367679.dll
c:\windows\system32\122b901e.dll
c:\windows\system32\34a25f04.dll
c:\windows\system32\3b8da919.dll
c:\windows\system32\66afcb56.dll
c:\windows\system32\9f684de8.dll
c:\windows\system32\b3721c07.dll
c:\windows\system32\c8ffd223.dll
c:\windows\system32\chmhp.dll
c:\windows\system32\f65bdec7.dll
c:\windows\system32\sh02004.dll
c:\windows\system32\sh14016.dll
c:\windows\system32\sslsocket.dll
c:\documents and settings\all users\application data\microsoft\office\userdata\g17asgezn3.dll
c:\program files\common files\pushware\cpush.dll
ifeo[syssafe.exe]
ifeo[taskmgr.exe]
ifeo[trojandetector.exe]
ifeo[trojanwall.exe]
ifeo[trojdie.exe]
ifeo[uihost.exe]
ifeo[umxagent.exe]
ifeo[umxattachment.exe]
ifeo[umxcfg.exe]
ifeo[umxfwhlp.exe]
ifeo[umxpol.exe]
ifeo[upiea.exe]
ifeo[uplive.exe]
ifeo[usbcleaner.exe]
ifeo[vsstat.exe]
ifeo[webscanx.exe]
ifeo[wopticlean.exe]
ifeo[zxsweep.exe]
scrnsave.exe
ifeo[rtvscan.exe]
ifeo[runiep.exe]
ifeo[safeboxtray.exe]
ifeo[safelive.exe]
ifeo[scan32.exe]
ifeo[selfupdate.exe]
ifeo[shcfg32.exe]
755d0ed0.dll
ifeo[smartup.exe]
ifeo[sreng.exe]
e1d19fcc.dll
ifeo[superkiller.exe]
ifeo[symlcsvc.exe]
ntsd -d
setuprs1.pif
0236.pif
c:\windows\dllhost.exe
c:\windows\system32\drivers\aliimz.sys
c:\windows\system32\b160485.sys
c:\windows\system32\d435fd4.sys
c:\windows\system32\xdva200.sys
c:\documents and settings\all users\application data\microsoft\media player\obj\wmpobj.sys
c:\windows\system32\drivers\hbkernel32.sys
c:\windows\system32\f35ee9e.sys
c:\windows\system32\c39e8db.sys
c:\windows\system32\xdva200.sys
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[{34A25F04-008D-403E-8EE6-2307BC02FA2E}] <34A25F04.dll>
[{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8}] <A1A6BC2E.dll>
[{AD794E6B-90B7-4F9D-8FD6-0C16E3298FF2}] <AD794E6B.dll>
[{3B8DA919-1139-4B10-AD8F-91E8FBCFD375}] <3B8DA919.dll>
[{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}] <122B901E.dll>
[{66AFCB56-FAA9-42D2-8C72-2767A46C7FA8}] <66AFCB56.dll>
[{58FF3024-8A83-4B1A-88E9-302F47646EEE}] <58FF3024.dll>
[{B3721C07-62B3-411A-9DC7-F5F27E3E21FF}] <B3721C07.dll>
[{70B0129E-726E-4789-A7C0-5DDC33241E94}] <70B0129E.dll>
[{E3367679-4775-4244-A62E-4CFE58FC850B}] <E3367679.dll>
[{5934EA2B-B2C4-4BE7-BF7A-FBA781A12E40}] <5934EA2B.dll>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\SysSafe.exe]] <IFEO[SysSafe.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\taskmgr.exe]] <IFEO[taskmgr.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\TrojanDetector.exe]] <IFEO[TrojanDetector.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\Trojanwall.exe]] <IFEO[Trojanwall.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\TrojDie.exe]] <IFEO[TrojDie.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\UIHost.exe]] <IFEO[UIHost.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\UmxAgent.exe]] <IFEO[UmxAgent.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\UmxAttachment.exe]] <IFEO[UmxAttachment.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\UmxCfg.exe]] <IFEO[UmxCfg.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\UmxFwHlp.exe]] <IFEO[UmxFwHlp.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\UmxPol.exe]] <IFEO[UmxPol.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\upiea.exe]] <IFEO[upiea.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\UpLive.exe]] <IFEO[UpLive.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\USBCleaner.exe]] <IFEO[USBCleaner.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\vsstat.exe]] <IFEO[vsstat.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\webscanx.exe]] <IFEO[webscanx.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\WoptiClean.exe]] <IFEO[WoptiClean.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\zxsweep.exe]] <IFEO[zxsweep.exe]>
[[HKEY_CURRENT_USER\Control Panel\Desktop]] <SCRNSAVE.EXE>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\Rtvscan.exe]] <IFEO[Rtvscan.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\runiep.exe]] <IFEO[runiep.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\safeboxTray.exe]] <IFEO[safeboxTray.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\safelive.exe]] <IFEO[safelive.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\scan32.exe]] <IFEO[scan32.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\SelfUpdate.exe]] <IFEO[SelfUpdate.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\shcfg32.exe]] <IFEO[shcfg32.exe]>
[{755D0ED0-3996-4ADB-9B1F-AD8F0E9E4738}] <755D0ED0.dll>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\SmartUp.exe]] <IFEO[SmartUp.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\SREng.exe]] <IFEO[SREng.exe]>
[{E1D19FCC-4777-4D71-B863-6A0A5B4E59BC}] <E1D19FCC.dll>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\SuperKiller.exe]] <IFEO[SuperKiller.exe]>
[[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\symlcsvc.exe]] <IFEO[symlcsvc.exe]>
[IFEO[360rpt.exe]] <ntsd -d>
[IFEO[360Safe.exe]] <ntsd -d>
[IFEO[360safebox.exe]] <ntsd -d>
[IFEO[360tray.exe]] <ntsd -d>
[IFEO[adam.exe]] <ntsd -d>
[IFEO[AgentSvr.exe]] <ntsd -d>
[IFEO[AntiArp.exe]] <ntsd -d>
[IFEO[AppSvc32.exe]] <ntsd -d>
[IFEO[arswp.exe]] <ntsd -d>
[IFEO[AST.exe]] <ntsd -d>
[IFEO[autoruns.exe]] <ntsd -d>
[IFEO[avcenter.exe]] <ntsd -d>
[IFEO[avconsol.exe]] <ntsd -d>
[IFEO[avgnt.exe]] <ntsd -d>
[IFEO[avgrssvc.exe]] <ntsd -d>
[IFEO[AvMonitor.exe]] <ntsd -d>
[IFEO[avp.com]] <ntsd -d>
[IFEO[avp.exe]] <ntsd -d>
[IFEO[CCenter.exe]] <ntsd -d>
[IFEO[ccSvcHst.exe]] <ntsd -d>
[IFEO[cmd.exe]] <setuprs1.PIF>
[IFEO[DrvAnti.exe]] <ntsd -d>
[IFEO[EGHOST.exe]] <ntsd -d>
[IFEO[FileDsty.exe]] <ntsd -d>
[IFEO[filemon.exe]] <ntsd -d>
[IFEO[FTCleanerShell.exe]] <ntsd -d>
[IFEO[FYFireWall.exe]] <ntsd -d>
[IFEO[GFRing3.exe]] <ntsd -d>
[IFEO[GFUpd.exe]] <ntsd -d>
[IFEO[HijackThis.exe]] <ntsd -d>
[IFEO[IceSword.exe]] <ntsd -d>
[IFEO[iparmo.exe]] <ntsd -d>
[IFEO[Iparmor.exe]] <ntsd -d>
[IFEO[isPwdSvc.exe]] <ntsd -d>
[IFEO[kabaload.exe]] <ntsd -d>
[IFEO[KASMain.exe]] <ntsd -d>
[IFEO[KASTask.exe]] <ntsd -d>
[IFEO[KAV32.exe]] <ntsd -d>
[IFEO[KAVDX.exe]] <ntsd -d>
[IFEO[KAVPF.exe]] <ntsd -d>
[IFEO[KAVPFW.exe]] <ntsd -d>
[IFEO[KAVSetup.exe]] <ntsd -d>
[IFEO[KAVStart.exe]] <ntsd -d>
[IFEO[KISLnchr.exe]] <ntsd -d>
[IFEO[KMailMon.exe]] <ntsd -d>
[IFEO[KMFilter.exe]] <ntsd -d>
[IFEO[KPFW32.exe]] <ntsd -d>
[IFEO[KPFW32X.exe]] <ntsd -d>
[IFEO[KPfwSvc.exe]] <ntsd -d>
[IFEO[Kregex.exe]] <ntsd -d>
[IFEO[KRepair.com]] <ntsd -d>
[IFEO[KsLoader.exe]] <ntsd -d>
[IFEO[KvDetect.exe]] <ntsd -d>
[IFEO[KvfwMcl.exe]] <ntsd -d>
[IFEO[kvol.exe]] <ntsd -d>
[IFEO[kvolself.exe]] <ntsd -d>
[IFEO[KVSrvXP.exe]] <ntsd -d>
[IFEO[kvupload.exe]] <ntsd -d>
[IFEO[kvwsc.exe]] <ntsd -d>
[IFEO[KvXP.kxp]] <ntsd -d>
[IFEO[KWatch.exe]] <ntsd -d>
[IFEO[KWatch9x.exe]] <ntsd -d>
[IFEO[KWatchX.exe]] <ntsd -d>
[IFEO[MagicSet.exe]] <ntsd -d>
[IFEO[mcconsol.exe]] <ntsd -d>
[IFEO[McNASvc.exe]] <ntsd -d>
[IFEO[McProxy.exe]] <ntsd -d>
[IFEO[Mcshield.exe]] <ntsd -d>
[IFEO[mcsysmon.exe]] <ntsd -d>
[IFEO[mmqczj.exe]] <ntsd -d>
[IFEO[mmsk.exe]] <ntsd -d>
[IFEO[MpfSrv.exe]] <ntsd -d>
[IFEO[msconfig.exe]] <0236.PIF>
[IFEO[Navapsvc.exe]] <ntsd -d>
[IFEO[Navapw32.exe]] <ntsd -d>
[IFEO[NAVSetup.exe]] <ntsd -d>
[IFEO[nod32.exe]] <ntsd -d>
[IFEO[nod32krn.exe]] <ntsd -d>
[IFEO[nod32kui.exe]] <ntsd -d>
[IFEO[NPFMntor.exe]] <ntsd -d>
[IFEO[PFW.exe]] <ntsd -d>
[IFEO[PFWLiveUpdate.exe]] <ntsd -d>
[IFEO[ProcessSafe.exe]] <ntsd -d>
[IFEO[procexp.exe]] <ntsd -d>
[IFEO[QHSET.exe]] <ntsd -d>
[IFEO[QQDoctor.exe]] <ntsd -d>
[IFEO[QQDoctorMain.exe]] <ntsd -d>
[IFEO[QQKav.exe]] <ntsd -d>
[IFEO[Ras.exe]] <ntsd -d>
[IFEO[Rav.exe]] <ntsd -d>
[IFEO[RavMon.exe]] <ntsd -d>
[IFEO[RavMonD.exe]] <ntsd -d>
[IFEO[RavStub.exe]] <ntsd -d>
[IFEO[RavTask.exe]] <ntsd -d>
[IFEO[RawCopy.exe]] <ntsd -d>
[IFEO[RegClean.exe]] <ntsd -d>
[IFEO[regedit.exe]] <setuprs1.PIF>
[IFEO[regedt32.exe]] <setuprs1.PIF>
[IFEO[regmon.exe]] <ntsd -d>
[IFEO[RegTool.exe]] <ntsd -d>
[IFEO[rfwcfg.exe]] <ntsd -d>
[IFEO[rfwmain.exe]] <ntsd -d>
[IFEO[rfwProxy.exe]] <ntsd -d>
[IFEO[rfwsrv.exe]] <ntsd -d>
[IFEO[rfwstub.exe]] <ntsd -d>
[IFEO[RsAgent.exe]] <ntsd -d>
[IFEO[Rsaupd.exe]] <ntsd -d>
[IFEO[RStray.exe]] <ntsd -d>
[IFEO[rstrui.exe]] <ntsd -d>
[34A25F04.dll] <>
[A1A6BC2E.dll] <>
[AD794E6B.dll] <>
[3B8DA919.dll] <>
[122B901E.dll] <>
[66AFCB56.dll] <>
[58FF3024.dll] <>
[B3721C07.dll] <>
[70B0129E.dll] <>
[E3367679.dll] <>
[5934EA2B.dll] <>
[IFEO[SysSafe.exe]] <ntsd -d>
[IFEO[taskmgr.exe]] <ntsd -d>
[IFEO[TrojanDetector.exe]] <ntsd -d>
[IFEO[Trojanwall.exe]] <ntsd -d>
[IFEO[TrojDie.exe]] <ntsd -d>
[IFEO[UIHost.exe]] <ntsd -d>
[IFEO[UmxAgent.exe]] <ntsd -d>
[IFEO[UmxAttachment.exe]] <ntsd -d>
[IFEO[UmxCfg.exe]] <ntsd -d>
[IFEO[UmxFwHlp.exe]] <ntsd -d>
[IFEO[UmxPol.exe]] <ntsd -d>
[IFEO[upiea.exe]] <ntsd -d>
[IFEO[UpLive.exe]] <ntsd -d>
[IFEO[USBCleaner.exe]] <ntsd -d>
[IFEO[vsstat.exe]] <ntsd -d>
[IFEO[webscanx.exe]] <ntsd -d>
[IFEO[WoptiClean.exe]] <ntsd -d>
[IFEO[zxsweep.exe]] <ntsd -d>
启动项目 -- 服务 -- Win32服务应用程序之如下项禁用:
[COM+ System Applications / COMSystemApp] <C:\WINDOWS\dllhost.exe -netsvcs>
启动项目 -- 服务-- 驱动程序之如下项禁用:
[aliimz / aliimz] <System32\Drivers\aliimz.sys>
[b160485 / b160485] <\??\C:\WINDOWS\system32\b160485.sys>
[d435fd4 / d435fd4] <\??\C:\WINDOWS\system32\d435fd4.sys>
[XDva200 / XDva200] <\??\C:\WINDOWS\system32\XDva200.sys>
[wmpobj / wmpobj] <\??\C:\Documents and Settings\All Users\Application
Data\Microsoft\Media Player\obj\wmpobj.sys>
[HBKernel32 Driver / HBKernel32] <\SystemRoot\system32\drivers\HBKernel32.sys>
[f35ee9e / f35ee9e] <\??\C:\WINDOWS\system32\f35ee9e.sys>
[c39e8db / c39e8db] <\??\C:\WINDOWS\system32\c39e8db.sys>
[XDva200 / XDva200] <\??\C:\WINDOWS\system32\XDva200.sys>
系统修复-- 浏览器加载项之如下项删除:
[RisingSurfer Class] <C:\Documents and Settings\All Users\Application
Data\Microsoft\OFFICE\USERDATA\G17AsGezN3.dll>
[RisingSurfer Class] <C:\Documents and Settings\All Users\Application
Data\Microsoft\OFFICE\USERDATA\G17AsGezN3.dll>
[CAdLogic Object] <C:\Program Files\Common Files\PushWare\cpush.dll>
用下载的“清理临时文件工具ATF-Cleaner-cn”,全选所有项目,点击“立即清理”
下载:
http://bbs.ikaka.com/attachment.aspx?attachmentid=447126用W i n d o w s 清理助手 ,清理你那系统。
W i n d o w s 清理助手 下载:
http://www.arswp.com/————————————————————————————————————
再重启电脑,反复检查,操作的结果,
杀毒软件如果有异常,可能需要卸载重装,升级至最新版本全盘杀。
SRENG工具的各项操作看这里:
http://bbs.ikaka.com/showtopic-8545446.aspx C:\Program Files\IGALIVE\IGALIVE.sys
C:\WINDOWS\system32\drivers\EagleNT.sys
将以上两个文件上传
http://www.virustotal.com/zh-cn/检测