发新话题
打印

[求助] AV终结者,谁能搞定它!!!!!!

AV终结者,谁能搞定它!!!!!!

求助,我的QQ:39440018

附件

SREngLOG.log (44.26 KB)

2008-8-9 21:49, 下载次数: 44

TOP

去看看这个帖子吧```估计对你有帮助```
http://bbs.duba.net/thread-21901776-1-1.html

TOP

1.使用金山顽固文件删除工具(点击下载)
解压并打开DelayDelFile,复制以下待删除文件列表-->粘贴进(Ctrl+V)第一个空白框中-->按"添加"-->点击"删除"按钮
执行操作.删除以下文件:

e:\windows\system32\iqi.dll
e:\windows\system32\jdsaex.dll
e:\windows\system32\tfsdmz.dll
e:\windows\system32\jfdses.dll
e:\windows\system32\pedadt.dll
f:\virtual pdf printer\virtualpdfprinter.exe
e:\windows\system32\mstimewd.dll
e:\windows\system32\fsrgeb.dll
e:\windows\system32\sichost.exe
e:\windows\system32\cliconfgzx.dll
e:\windows\system32\adsntzt.dll
e:\windows\system32\ksuserfy.dll
e:\windows\system32\dispexcb.dll
e:\windows\system32\ddserh.dll
e:\windows\system32\midimaptl.dll
e:\windows\system32\midimapzx.dll
e:\windows\system32\midimapwd.dll
e:\windows\system32\midimapqn3.dll
e:\windows\system32\midimapwl.dll
e:\windows\system32\midimapcq.dll
e:\windows\system32\tdggrz.dll
e:\windows\system32\wzcfsw.dll
e:\windows\system32\zsdgff.dll
e:\windows\system32\rfdswc.dll
e:\windows\system32\jfrwdh.dll
e:\windows\system32\dndsaf.dll
e:\windows\system32\ydggsx.dll
e:\windows\system32\tdfhex.dll
e:\windows\system32\fmcvxy.dll
e:\windows\system32\zptldsys.dll
e:\windows\system32\rowkd\lsass.exe
e:\windows\system32\drivers\000f58b2.sys
e:\docume~1\charles\locals~1\temp\tmpdd.tmp
e:\windows\system32\drivers\wcnmhceyx.sys
e:\windows\system32\drivers\tvdz0.sys
e:\docume~1\charles\locals~1\temp\tmpe7.tmp
e:\docume~1\charles\locals~1\temp\1.tmp
e:\windows\system32\drivers\hg2164dey.sys
e:\docume~1\charles\locals~1\temp\tmpe1.tmp
e:\windows\system32\drivers\eth8023.sys
e:\docume~1\charles\locals~1\temp\tmpa.tmp
e:\windows\system32\drivers\pcihdd2.sys
e:\windows\system32\drivers\b4l5az0i2o.sys
e:\program files\microsoft office\system\apcdli.sys

2.删除重启后使用SREng修复下面各项:

    启动项目 -- 注册表之如下项删除:
[{6E6CA8A1-81BC-4707-A54C-F4903DD70BAD}]    <>
[{7C954872-1230-6541-9548-6541025884C7}]    <>
[{8A041F13-A111-12A3-B0CF-F99818AA68A8}]    <>
[{3D698451-2015-6358-9871-2015987452D3}]    <>
[{AC69034A-F45F-D34D-A33A-C33C4D324FCA}]    <>
[{7319A1F1-9410-9654-3201-345FFA349137}]    <>
[{6B1AEF69-DDAE-FDAD-DCAB-698F026ABDB6}]    <>
[{4A698102-5904-AFD0-20DF-CD1A65829CA4}]    <>
[{AA59145F-315D-BC23-AC1F-145DF81A34AA}]    <>
[{37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73}]    <>
[{47AC9076-C898-B098-D098-A18319080974}]    <>
[{87FD640A-158F-48AC-FD14-1597F14A9778}]    <>
[{4A908760-8000-4000-A000-9000322145A4}]    <>
[{5D098345-6785-1098-5413-678067AE03D5}]    <>
[{1A698452-C5D8-C584-C256-C264C987C5A1}]    <>
[{7FD45A54-9875-698F-E56E-65102358FDF7}]    <>
[{80AF1289-F140-A140-D012-C1458759FC08}]    <>
[{B629FF4F-ACDB-5C90-A098-FACB3456A26B}]    <>
[{4372FE4D-E2C2-45FE-A893-E2B1691A7DD0}]    <>
[{7A041F13-A111-12A3-B0CF-F99818AA68A7}]    <>
[{60A345CD-ABCD-EFAB-CDEF-ABCD01020306}]    <>
[{7C69034A-F45F-D34D-A33A-C33C4D324FC7}]    <>
[{B490415F-65F8-B5C5-D8BA-9405FB12054B}]    <>
[{A629FF4F-ACDB-5C90-A098-FACB3456A26A}]    <>
[{20909876-4567-3908-4056-909834565102}]    <>
[{77FD640A-158F-48AC-FD14-1597F14A9777}]    <>
[{528DF602-9541-A985-210A-984A698C6F25}]    <>
[{3A908760-8000-4000-A000-9000322145A3}]    <>
[{A490415F-65F8-B5C5-D8BA-9405FB12054A}]    <>
[{6C648541-1025-9650-9057-6541258720C6}]    <>
[{8629FF4F-ACDB-5C90-A098-FACB3456A268}]    <>
[{5C69034A-F45F-D34D-A33A-C33C4D324FC5}]    <>
[{6FD45A54-9875-698F-E56E-65102358FDF6}]    <>
[{45AADFAA-DD36-42AB-83AD-0521BBF58C24}]    <>
[{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}]    <>
[{43512378-9874-5641-1025-985420368734}]    <>
[{45694105-5108-9405-3695-954187462154}]    <>
[{3C954872-1230-6541-9548-6541025884C3}]    <>
[{54FAE856-AD58-20CB-A025-CD4895FA6E45}]    <>
[{5A069845-2036-6084-9054-6087502480A5}]    <>
[{25FD6584-698F-BCD2-602C-698745210352}]    <>
[{22596546-2036-9451-6058-658402589722}]    <>
[{91954FAC-1023-154F-895A-1458258AD819}]    <>
[{50940F85-F015-14F1-A05F-F69858AC6D05}]    <>
[{35671234-7890-ABCD-CDEF-567801237653}]    <>
[{13FD5987-65D2-C58D-D87E-987451F12531}]    <>
[{4629FF4F-ACDB-5C90-A098-FACB3456A264}]    <>
[{9490415F-65F8-B5C5-D8BA-9405FB120549}]    <>
[{32023698-6984-8541-9654-698745012523}]    <>
[{83BA45AF-FAAA-CDDD-BEEE-BCDE1234AB38}]    <>
[{7C8D1401-A58D-A81C-CD24-A5915C4517C7}]    <>
[{4FD45A54-9875-698F-E56E-65102358FDF4}]    <>
[{6319A1F1-9410-9654-3201-345FFA349136}]    <>
[{2B69874A-C58C-458D-69F0-698F874E41B2}]    <>
[{91698482-6555-3666-1222-954784129019}]    <>
[{37AC9076-C898-B098-D098-A18319080973}]    <>
[{81954FAC-1023-154F-895A-1458258AD818}]    <>
[{55694105-5108-9405-3695-954187462155}]    <>
[{33512378-9874-5641-1025-985420368733}]    <>
[{19109876-7619-9101-7012-901938475191}]    <>
[{17AC9076-C898-B098-D098-A18319080971}]    <>
[{18093456-9012-4568-9076-908765467181}]    <>
[{4A069845-2036-6084-9054-6087502480A4}]    <>
[{8C41B7F7-3168-400D-A702-0E7EFE0BA304}]    <>
[{84143967-B645-4BFF-B873-DA1DC886E9A7}]    <>
[{EB71E0B3-E97D-4D30-8733-E28266467617}]    <>
[{2D698451-2015-6358-9871-2015987452D2}]    <>
[{4C648541-1025-9650-9057-6541258720C4}]    <>
[{6A041F13-A111-12A3-B0CF-F99818AA68A6}]    <>
[{DC3D30AE-0380-4151-8934-EE98A34B0370}]    <>
[{6C8D1401-A58D-A81C-CD24-A5915C4517C6}]    <>
[{28EB3777-3E23-4E72-8449-A992D09D24C3}]    <>
[{B29583D8-033A-4B9F-8553-7C5458F3FB8E}]    <E:\WINDOWS\system32\jdsaex.dll>
[{875E07B1-0614-43D9-A76E-D76A28AB3D7B}]    <E:\WINDOWS\system32\tfsdmz.dll>
[{81AF1CF6-D1C9-4C6A-AC01-EDE54E71945B}]    <E:\WINDOWS\system32\jfdses.dll>
[{5E907A48-400E-4EA8-9792-FFAE052D59E9}]    <E:\WINDOWS\system32\pedadt.dll>
[Virtual PDF Printer]    <F:\Virtual PDF Printer\VirtualPDFPrinter.exe>
[{00180018-0018-0018-0018-00180018BB15}]    <E:\WINDOWS\system32\mstimewd.dll>
[{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6}]    <E:\WINDOWS\system32\fsrgeb.dll>
注意该项[Userinit]修改:把<E:\WINDOWS\system32\userinit.exe,E:\WINDOWS\system32\sichost.exe>修改为<C:\WINDOWS\system32\userinit.exe,>逗号不可省略
[{00050005-0005-0005-0005-00050005BB15}]    <E:\WINDOWS\system32\cliconfgzx.dll>
[{00010001-0001-0001-0001-00010001BB15}]    <E:\WINDOWS\system32\adsntzt.dll>
[{00130013-0013-0013-0013-00130013BB15}]    <E:\WINDOWS\system32\ksuserfy.dll>
[{00060006-0006-0006-0006-00060006BB15}]    <E:\WINDOWS\system32\dispexcb.dll>
[{A9895933-6636-4281-BC58-EE6DE2AF96E3}]    <E:\WINDOWS\system32\ddserh.dll>
[{4F4F0064-71E0-4f0d-0017-708476C7815F}]    <E:\WINDOWS\system32\midimaptl.dll>
[{4F4F0064-71E0-4f0d-0005-708476C7815F}]    <E:\WINDOWS\system32\midimapzx.dll>
[{4F4F0064-71E0-4f0d-0018-708476C7815F}]    <E:\WINDOWS\system32\midimapwd.dll>
[{4F4F0064-71E0-4f0d-0022-708476C7815F}]    <E:\WINDOWS\system32\midimapqn3.dll>
[{4F4F0064-71E0-4f0d-0004-708476C7815F}]    <E:\WINDOWS\system32\midimapwl.dll>
[{4F4F0064-71E0-4f0d-0023-708476C7815F}]    <E:\WINDOWS\system32\midimapcq.dll>
[{4D165A2A-4BC1-4CA8-8299-08E05AAAB5A4}]    <E:\WINDOWS\system32\tdggrz.dll>
[{28766E1C-74B0-4417-8C75-F12AE309EF35}]    <E:\WINDOWS\system32\wzcfsw.dll>
[{53D44DB6-E22B-4B17-97D3-572C96CCA6E1}]    <E:\WINDOWS\system32\zsdgff.dll>
[{461D2AB4-29A5-45C2-9134-D52272D3DE38}]    <E:\WINDOWS\system32\rfdswc.dll>
[{841529CB-7F77-4B99-A895-B5441E0D302F}]    <E:\WINDOWS\system32\jfrwdh.dll>
[{259BF3CF-194D-4FE6-9ADB-DE6544B098B6}]    <E:\WINDOWS\system32\dndsaf.dll>
[{0086DD39-EB8E-4504-A085-AC8A433E34D0}]    <E:\WINDOWS\system32\ydggsx.dll>
[{0B846B26-BFE6-4E8E-A948-1DB17B77B483}]    <E:\WINDOWS\system32\tdfhex.dll>
[{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7}]    <E:\WINDOWS\system32\fmcvxy.dll>
[{60940F85-F015-14F1-A05F-F69858AC6D06}]    <E:\WINDOWS\system32\zptldsys.dll>
[N/A]    <E:\WINDOWS\system32\rowkd\lsass.exe /t>

    启动项目 -- 服务-- 驱动程序之如下项禁用:
[000f58b2 / 000f58b2]    <\??\E:\WINDOWS\system32\Drivers\000f58b2.sys>
[zftp / zftp]    <\??\E:\DOCUME~1\charles\LOCALS~1\Temp\tmpDD.tmp>
[wcnmhceyx / wcnmhceyx]    <\SystemRoot\system32\drivers\wcnmhceyx.sys>
[tvdz / tvdz0]    <\SystemRoot\System32\DRIVERS\tvdz0.sys>
[ptfs / ptfs]    <\??\E:\DOCUME~1\charles\LOCALS~1\Temp\tmpE7.tmp>
[RSPPSYS / RSPPSYS]    <\??\E:\Program Files\Rising\Rav\RSPPSYS.sys>
[IIS Manager  / IIS Manager ]    <\??\E:\DOCUME~1\charles\LOCALS~1\Temp\1.tmp>
[hg2164dey / hg2164dey]    <\SystemRoot\system32\drivers\hg2164dey.sys>
[fmsq / fmsq]    <\??\E:\DOCUME~1\charles\LOCALS~1\Temp\tmpE1.tmp>
[eth8023 / eth8023]    <\SystemRoot\system32\drivers\eth8023.sys>
[DHY / DHY]    <\??\E:\DOCUME~1\charles\LOCALS~1\Temp\tmpA.tmp>
[DeepFree Update / DeepFree Update]    <\??\E:\WINDOWS\system32\drivers\pcihdd2.sys>
[ExpScaner / ExpScaner]    <\??\E:\Program Files\Rising\Rav\ExpScan.sys>
[b4l5az0i2 / b4l5az0i2o]    <\SystemRoot\System32\DRIVERS\b4l5az0i2o.sys>
[apcdli / apcdli]    <\??\E:\Program Files\Microsoft Office\SYSTEM\apcdli.sys>
下载windows清理助手升级到最新处理下
http://www.arswp.com/download/arswp2/arswp2.zip
下载临时文件清理工具清理下   
http://www.dodudou.com/down/ATF-Cleaner-cn.exe

[ 本帖最后由 cchao21 于 2008-8-9 22:25 编辑 ]

TOP

金山顽固文件删除工具不能删除E:\WINDOWS\system32\iqi.dll文件

其他文件还不知道怎样

这毒需要其他方法删除

TOP

f:\virtual pdf printer\virtualpdfprinter.exe这文件有问题吗?似乎是正常的。

TOP

发新话题