解决方法:
由于多个病毒文件插入系统进程, 需要借助 xdelbox 来处理
xdelbox:
http://bbs.ikaka.com/showtopic-8442813.aspx 三楼可以下载到
xdelbox使用方法:
http://forum.ikaka.com/topic.asp?board=28&artid=8381032下载完xdelbox后,断网,打开 xdelbox 添加以下文件路径
C:\WINDOWS\temp\b.bat
C:\WINDOWS\system32\mpwddapi.dll
C:\WINDOWS\system32\zxmscwin.dll
C:\WINDOWS\system32\mndhddwd.dll
C:\WINDOWS\system32\mpmydapi.dll
C:\WINDOWS\system32\mndsesrv.dll
C:\WINDOWS\system32\yzzthmsn.dll
C:\WINDOWS\system32\zptlcsys.dll
C:\WINDOWS\system32\apsgdjba.dll
C:\WINDOWS\system32\oohxdbyt.dll
C:\WINDOWS\system32\apzhbtde.dll
C:\WINDOWS\system32\jkhxaklo.dll
C:\WINDOWS\system32\yxcschlp.dll
C:\WINDOWS\system32\ptjhehlp.dll
C:\WINDOWS\system32\zycbdime.dll
C:\WINDOWS\system32\mnmhfsrv.dll
C:\WINDOWS\system32\opshbbty.dll
C:\WINDOWS\system32\ypdjfbmp.dll
C:\WINDOWS\system32\ozfydbyt.dll
C:\Program Files\Internet Explorer\PLUGINS\WinSys48.Sys
C:\WINDOWS\system32\zywmfime.dll
C:\WINDOWS\system32\zyzxiime.dll
C:\WINDOWS\system32\pjjxddwd.dll
C:\WINDOWS\system32\nhmxajkl.dll
C:\WINDOWS\system32\cdwsbkop.dll
C:\WINDOWS\system32\zgfdet.dll
C:\WINDOWS\system32\hhrdxd.dll
C:\WINDOWS\system32\zdesfx.dll
C:\WINDOWS\system32\wyrsdj.dll
C:\WINDOWS\system32\tdffdl.dll
C:\WINDOWS\system32\cedafb.dll
C:\WINDOWS\system32\sgrefg.dll
C:\WINDOWS\18be.scr
C:\WINDOWS\System32\DRIVERS\4zj64ds9.sys
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~wxp2ins.78.tmp
C:\WINDOWS\system32\drivers\HBKernel.sys
C:\WINDOWS\system32\drivers\zvee57.sys
添加完毕,选择 立即重启执行删除. 等待系统重新启动
打开 SREng - 启动项目 - 注册表 - 将下列项删除
<virustrj><C:\WINDOWS\temp\b.bat> []
<{45694105-5108-9405-3695-954187462154}><C:\WINDOWS\system32\mpwddapi.dll> [N/A]
<{6A041F13-A111-12A3-B0CF-F99818AA68A6}><C:\WINDOWS\system32\zxmscwin.dll> [N/A]
<{4C648541-1025-9650-9057-6541258720C4}><C:\WINDOWS\system32\mndhddwd.dll> [N/A]
<{4629FF4F-ACDB-5C90-A098-FACB3456A264}><C:\WINDOWS\system32\mpmydapi.dll> [N/A]
<{57FD640A-158F-48AC-FD14-1597F14A9775}><C:\WINDOWS\system32\mndsesrv.dll> [N/A]
<{8490415F-65F8-B5C5-D8BA-9405FB120548}><C:\WINDOWS\system32\yzzthmsn.dll> [N/A]
<{50940F85-F015-14F1-A05F-F69858AC6D05}><C:\WINDOWS\system32\zptlcsys.dll> [N/A]
<{4FD45A54-9875-698F-E56E-65102358FDF4}><C:\WINDOWS\system32\apsgdjba.dll> [N/A]
<{5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5}><C:\WINDOWS\system32\oohxdbyt.dll> [N/A]
<{2D698451-2015-6358-9871-2015987452D2}><C:\WINDOWS\system32\apzhbtde.dll> [N/A]
<{14698742-2059-3025-9058-954023874141}><C:\WINDOWS\system32\jkhxaklo.dll> [N/A]
<{35671234-7890-ABCD-CDEF-567801237653}><C:\WINDOWS\system32\yxcschlp.dll> [N/A]
<{528DF602-9541-A985-210A-984A698C6F25}><C:\WINDOWS\system32\ptjhehlp.dll> [N/A]
<{4A698102-5904-AFD0-20DF-CD1A65829CA4}><C:\WINDOWS\system32\zycbdime.dll> [N/A]
<{6C8D1401-A58D-A81C-CD24-A5915C4517C6}><C:\WINDOWS\system32\mnmhfsrv.dll> [N/A]
<{22596546-2036-9451-6058-658402589722}><C:\WINDOWS\system32\opshbbty.dll> [N/A]
<{81954FAC-1023-154F-895A-1458258AD818}><C:\WINDOWS\system32\ypdjfbmp.dll> [N/A]
<{4A069845-2036-6084-9054-6087502480A4}><C:\WINDOWS\system32\ozfydbyt.dll> [N/A]
<{1AB1F65A-964F-4AE7-B254-05146A0E602E}><C:\Program Files\Internet Explorer\PLUGINS\WinSys48.Sys> []
<{6319A1F1-9410-9654-3201-345FFA349136}><C:\WINDOWS\system32\zywmfime.dll> [N/A]
<{9A59145F-315D-BC23-AC1F-145DF81A34A9}><C:\WINDOWS\system32\zyzxiime.dll> [N/A]
<{44FAE856-AD58-20CB-A025-CD4895FA6E44}><C:\WINDOWS\system32\pjjxddwd.dll> [N/A]
<{17AC9076-C898-B098-D098-A18319080971}><C:\WINDOWS\system32\nhmxajkl.dll> []
<{2A095412-A568-B258-C587-D148E148F0A2}><C:\WINDOWS\system32\cdwsbkop.dll> [N/A]
<{28EB3777-3E23-4E72-8449-A992D09D24C3}><C:\WINDOWS\system32\zgfdet.dll> []
<{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}><C:\WINDOWS\system32\hhrdxd.dll> [N/A]
<{45AADFAA-DD36-42AB-83AD-0521BBF58C24}><C:\WINDOWS\system32\zdesfx.dll> []
<{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}><C:\WINDOWS\system32\wyrsdj.dll> [N/A]
<{C0595A7E-2E2F-4B34-A83A-019270A0A464}><C:\WINDOWS\system32\tdffdl.dll> [N/A]
<{84143967-B645-4BFF-B873-DA1DC886E9A7}><C:\WINDOWS\system32\cedafb.dll> [N/A]
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgrefg.dll> []
<SCRNSAVE.EXE><C:\WINDOWS\18be.scr> []
打开 SREng - 启动项目 - 注册表 - 将所有 Image File Execution Options 项删除
打开 SREng - 启动项目 - 驱动服务 - 将下列项删除
[4zj64ds / 4zj64ds9][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\4zj64ds9.sys><>
[Atixeve29218 / Atixeve29218][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~wxp2ins.78.tmp><N/A>
[HBKernel Driver / HBKernel][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\HBKernel.sys><N/A>
[zvee57 / zvee57][Stopped/Boot Start]
<\SystemRoot\system32\drivers\zvee57.sys><N/A>
打开SREng - 系统修复 - 浏览器加载项 - 将下列项删除
[]
{44FAE856-AD58-20CB-A025-CD4895FA6E44} <C:\WINDOWS\system32\pjjxddwd.dll, N/A>
[]
{45694105-5108-9405-3695-954187462154} <C:\WINDOWS\system32\mpwddapi.dll, N/A>
[]
{4629FF4F-ACDB-5C90-A098-FACB3456A264} <C:\WINDOWS\system32\mpmydapi.dll, N/A>
[]
{4A069845-2036-6084-9054-6087502480A4} <C:\WINDOWS\system32\ozfydbyt.dll, N/A>
[]
{4A698102-5904-AFD0-20DF-CD1A65829CA4} <C:\WINDOWS\system32\zycbdime.dll, N/A>
[]
{4C648541-1025-9650-9057-6541258720C4} <C:\WINDOWS\system32\mndhddwd.dll, N/A>
[]
{4FD45A54-9875-698F-E56E-65102358FDF4} <C:\WINDOWS\system32\apsgdjba.dll, N/A>
[]
{50940F85-F015-14F1-A05F-F69858AC6D05} <C:\WINDOWS\system32\zptlcsys.dll, N/A>
[]
{528DF602-9541-A985-210A-984A698C6F25} <C:\WINDOWS\system32\ptjhehlp.dll, N/A>
[]
{57FD640A-158F-48AC-FD14-1597F14A9775} <C:\WINDOWS\system32\mndsesrv.dll, N/A>
[]
{5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5} <C:\WINDOWS\system32\oohxdbyt.dll, N/A>
[]
{6319A1F1-9410-9654-3201-345FFA349136} <C:\WINDOWS\system32\zywmfime.dll, N/A>
[]
{6A041F13-A111-12A3-B0CF-F99818AA68A6} <C:\WINDOWS\system32\zxmscwin.dll, N/A>
[]
{6C8D1401-A58D-A81C-CD24-A5915C4517C6} <C:\WINDOWS\system32\mnmhfsrv.dll, N/A>
[]
{81954FAC-1023-154F-895A-1458258AD818} <C:\WINDOWS\system32\ypdjfbmp.dll, N/A>
[]
{8490415F-65F8-B5C5-D8BA-9405FB120548} <C:\WINDOWS\system32\yzzthmsn.dll, N/A>
[]
{9A59145F-315D-BC23-AC1F-145DF81A34A9} <C:\WINDOWS\system32\zyzxiime.dll, N/A>
[]
{14698742-2059-3025-9058-954023874141} <C:\WINDOWS\system32\jkhxaklo.dll, N/A>
[]
{17AC9076-C898-B098-D098-A18319080971} <C:\WINDOWS\system32\nhmxajkl.dll, N/A>
[]
{1AB1F65A-964F-4AE7-B254-05146A0E602E} <C:\Program Files\Internet Explorer\PLUGINS\WinSys48.Sys, N/A>
[]
{22596546-2036-9451-6058-658402589722} <C:\WINDOWS\system32\opshbbty.dll, N/A>
[]
{2D698451-2015-6358-9871-2015987452D2} <C:\WINDOWS\system32\apzhbtde.dll, N/A>
[]
{35671234-7890-ABCD-CDEF-567801237653} <C:\WINDOWS\system32\yxcschlp.dll, N/A>
[]
{44FAE856-AD58-20CB-A025-CD4895FA6E44} <C:\WINDOWS\system32\pjjxddwd.dll, N/A>
[]
{45694105-5108-9405-3695-954187462154} <C:\WINDOWS\system32\mpwddapi.dll, N/A>
[]
{4629FF4F-ACDB-5C90-A098-FACB3456A264} <C:\WINDOWS\system32\mpmydapi.dll, N/A>
[]
{4A069845-2036-6084-9054-6087502480A4} <C:\WINDOWS\system32\ozfydbyt.dll, N/A>
[]
{4A698102-5904-AFD0-20DF-CD1A65829CA4} <C:\WINDOWS\system32\zycbdime.dll, N/A>
[]
{4C648541-1025-9650-9057-6541258720C4} <C:\WINDOWS\system32\mndhddwd.dll, N/A>
[]
{4FD45A54-9875-698F-E56E-65102358FDF4} <C:\WINDOWS\system32\apsgdjba.dll, N/A>
[]
{50940F85-F015-14F1-A05F-F69858AC6D05} <C:\WINDOWS\system32\zptlcsys.dll, N/A>
[]
{528DF602-9541-A985-210A-984A698C6F25} <C:\WINDOWS\system32\ptjhehlp.dll, N/A>
[]
{57FD640A-158F-48AC-FD14-1597F14A9775} <C:\WINDOWS\system32\mndsesrv.dll, N/A>
[]
{5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5} <C:\WINDOWS\system32\oohxdbyt.dll, N/A>
[]
{6319A1F1-9410-9654-3201-345FFA349136} <C:\WINDOWS\system32\zywmfime.dll, N/A>
[]
{6A041F13-A111-12A3-B0CF-F99818AA68A6} <C:\WINDOWS\system32\zxmscwin.dll, N/A>
[]
{6C8D1401-A58D-A81C-CD24-A5915C4517C6} <C:\WINDOWS\system32\mnmhfsrv.dll, N/A>
[]
{81954FAC-1023-154F-895A-1458258AD818} <C:\WINDOWS\system32\ypdjfbmp.dll, N/A>
[]
{8490415F-65F8-B5C5-D8BA-9405FB120548} <C:\WINDOWS\system32\yzzthmsn.dll, N/A>
[]
{9A59145F-315D-BC23-AC1F-145DF81A34A9} <C:\WINDOWS\system32\zyzxiime.dll, N/A>
处理完上述项目后,请将下列文件重命名, 删除扩展名
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\mfc40u.dll
待重命名完毕后,系统将自动修复这俩个文件
如果没有恢复,请前往路径 C:\WINDOWS\system32\dllcache 复制 lsass.exe 和 mfc40u.dll ,并覆盖到对应路径
再次重启后检查系统是否正常