建议使用XDelBox(下载地址:
http://bbs.ikaka.com/attachment.aspx?attachmentid=446806)
删除以下文件:(使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择剪贴板导入不检查路径,导入后记得勾选抑制其再生,在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储设备)
C:\WINDOWS\system32\iaabdjdp.dll
C:\WINDOWS\system32\jfkbnobi.dll
C:\WINDOWS\system32\pobbofem.dll
C:\WINDOWS\system32\lkfecpib.dll
C:\WINDOWS\system32\mngiclbd.dll
C:\WINDOWS\system32\bpebgfgk.dll
C:\WINDOWS\system32\ngknkigb.dll
C:\WINDOWS\system32\oeglgfgl.dll
C:\WINDOWS\system32\knbiibno.dll
C:\WINDOWS\system32\jjoenhkg.dll
C:\WINDOWS\system32\kaccapan.dll
C:\WINDOWS\system32\anymie360.dll
C:\WINDOWS\system32\eaineldp.dll
C:\WINDOWS\system32\eneaadep.dll
C:\WINDOWS\system32\lgpjfjpi.dll
C:\WINDOWS\system32\pgagbdog.dll
C:\WINDOWS\system32\lngjjeki.dll
C:\WINDOWS\system32\fpdeieml.dll
C:\WINDOWS\system32\ejdcgcbh.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WowInitcode.dat
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wooolinit.dat
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\CPWGameRecord.dll
C:\Program Files\Internet Explorer\JoooNt8.Jzx
C:\WINDOWS\system\jjxzwzjy090122.exe
C:\WINDOWS\system32\anymie360.exe
2重启后用sreng删除下列注册表项。
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{3FDEB171-8F86-0009-0001-69B8DB553683}><C:\WINDOWS\system32\sysdlwd2.dll> []
<{3FDEB171-8F86-0008-0001-69B8DB553683}><C:\WINDOWS\system32\sysdlyy4.dll> []
<{2AABD3D9-6812-485F-9FBA-EC0C8AF21412}><C:\WINDOWS\system32\iaabdjdp.dll> []
<{3CC4968B-7713-4D61-83C2-5264CECF51A2}><C:\WINDOWS\system32\jcckpmob.dll> []
<{3F4B78B2-28DE-41E9-A796-75378AECFFC3}><C:\WINDOWS\system32\jfkbnobi.dll> []
<{3FDEB171-8F86-0004-0001-69B8DB553683}><C:\WINDOWS\system32\sysmxd7.dll> []
<{B9EB0F04-5E36-4329-93A7-7991A7D799F0}><C:\WINDOWS\system32\bpebgfgk.dll> []
<{7047420B-96DA-4010-AF9B-980B4C4D2011}><C:\WINDOWS\system32\ngknkigb.dll> []
<{8E050F05-75D0-4976-87FC-1B96385BD027}><C:\WINDOWS\system32\oeglgfgl.dll> [File is missing]
<{6FFF5655-C50A-4B39-AFCC-E76D2496732F}><C:\WINDOWS\system32\mffflmll.dll> [File is missing]
<{EA27E5D9-DD91-4F17-80DF-95F6B99B56A3}><C:\WINDOWS\system32\eaineldp.dll> []
<{E7EAADE9-74D4-4DBC-8C5B-6A8EBE1E798E}><C:\WINDOWS\system32\eneaadep.dll> []
<{5093F392-124D-49EC-93CC-E7EAC253C16A}><C:\WINDOWS\system32\lgpjfjpi.dll> []
<{90A0BD80-923D-47F1-B380-D4741406CFE6}><C:\WINDOWS\system32\pgagbdog.dll> []
<{57033E42-854C-4EC0-B159-B5AF9AA037BE}><C:\WINDOWS\system32\lngjjeki.dll> []
<{F9DE2E65-7BE7-4D2B-BD03-4D9CDA303905}><C:\WINDOWS\system32\fpdeieml.dll> []
<{E3DC0CB1-5166-4ECA-B31E-4000C23C3AB2}><C:\WINDOWS\system32\ejdcgcbh.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<2AABD3D9><C:\WINDOWS\system32\iaabdjdp.dll> []
<3CC4968B><C:\WINDOWS\system32\jcckpmob.dll> []
<3F4B78B2><C:\WINDOWS\system32\jfkbnobi.dll> []
<B9EB0F04><C:\WINDOWS\system32\bpebgfgk.dll> []
<7047420B><C:\WINDOWS\system32\ngknkigb.dll> []
<6FFF5655><C:\WINDOWS\system32\mffflmll.dll> [File is missing]
<8E050F05><C:\WINDOWS\system32\oeglgfgl.dll> [File is missing]
<EA27E5D9><C:\WINDOWS\system32\eaineldp.dll> []
<E7EAADE9><C:\WINDOWS\system32\eneaadep.dll> []
<5093F392><C:\WINDOWS\system32\lgpjfjpi.dll> []
<90A0BD80><C:\WINDOWS\system32\pgagbdog.dll> []
<57033E42><C:\WINDOWS\system32\lngjjeki.dll> []
<F9DE2E65><C:\WINDOWS\system32\fpdeieml.dll> []
<E3DC0CB1><C:\WINDOWS\system32\ejdcgcbh.dll> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><将此键值设为空>
C:\WINDOWS\system32\userinit.exe文件被感染,建议在开始——运行中输入dllcache,在里面找到userinit.exe替换被感染的。
水平有限,不排除有删错的。