【回复“WHY520”的帖子】
1、结束下列病毒进程:
[PID: 1620][C:\WINDOWS\system32\0.exe] [N/A, N/A]
[PID: 1724][C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE] [Microsoft Corporation, 5.00.2134.1]
2、用 IceSword禁止进程创建,然后强制卸除插入Explorer.EXE进程中的病毒模块:
[PID: 980][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\yk_urh.dll] [N/A, N/A]
[C:\WINDOWS\system32\xf_kjv.dll] [N/A, N/A]
[C:\WINDOWS\system\Mvvp.dll] [N/A, N/A]
[C:\WINDOWS\system32\wmpkn.dll] [N/A, N/A]
[C:\WINDOWS\system32\WsReource.dll] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\PvSec.dll] [, 5, 1, 100, 2500]
[C:\PROGRA~1\bnxa\frbe.dll] [, 1, 2, 0, 8]
3、删除下列启动项、服务项、驱动项:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<zzpefr74><C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\zzpefr74.dll,DllCanUnloadNow> [Microsoft Corporation]
<Syetwys><C:\WINDOWS\system32\algestese.exe> []
<dfsf><RUNDLL32.EXE C:\WINDOWS\system\Mvvp.dll,DImmcv> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<WebSecurity><C:\WINDOWS\system32\PvSec.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{78BF3960-61F0-4F4E-825D-3554FA61E847}><C:\WINDOWS\system32\wmpkn.dll> [N/A]
<{B63BFF8C-2E25-4CCC-9A01-68807F567AA7}><C:\WINDOWS\system32\WsReource.dll> []
服务
[Event Service / AtHome]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\cxwchi13.dll><Microsoft Corporation>
[Transaction Provisioning Service / mitaozi]
<C:\WINDOWS\system32\0.exe><N/A>
[Remote Access Connection Management / Remote Access Connection Management]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\ncxml.dll><>
[NT Data Provider / SDTSTA]
<C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE C:\WINDOWS\SYSTEM32\WBEM\BVGCMD02.DLL,Export 1087><Microsoft Corporation>
[Computer Storage / WIDETS]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL,Export 1087><N/A>
驱动
[amdk5 / amdk5]
<\??\C:\WINDOWS\system32\drivers\amdk5.sys><N/A>
[HTTP / HTTP]
<System32\Drivers\HTTP.sys><N/A>
[jscont2 / jscont22]
<\SystemRoot\System32\DRIVERS\jscont22.sys><N/A>
[LanPort / LanPort]
<\??\C:\WINDOWS\system32\drivers\LanPort.sys><N/A>
[mffalmj / mffalmj]
<\SystemRoot\system32\drivers\mffalmj.sys><N/A>
[nwlnksipx / nwlnksipx]
<\??\C:\WINDOWS\system32\drivers\nwlnksipx.sys><Microsoft Corporation>
[uphkfla / uphkfla]
<\SystemRoot\system32\drivers\uphkfla.sys><N/A>
[wspipe / wspipe]
<\??\C:\WINDOWS\system32\drivers\wspipe.sys><N/A>
4、删除下列浏览器加载项:
[e17]
{DFCB34B6-902D-426E-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\484cntos.dll, N/A>
[]
{2BA15999-5AE3-45A0-AE2B-1B294AE19F4F} <C:\WINDOWS\system32\45a0ntos.dll, N/A>
[veru]
{55EC3AA6-7092-4274-948A-62D1E9BF414D} <C:\PROGRA~1\bnxa\frbe.dll, >
5、删除下列病毒文件:
C:\WINDOWS\system32\0.exe
C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE
C:\WINDOWS\system32\yk_urh.dll
C:\WINDOWS\system32\xf_kjv.dll
C:\WINDOWS\system\Mvvp.dll
C:\WINDOWS\system32\wmpkn.dll
C:\WINDOWS\system32\WsReource.dll
C:\WINDOWS\system32\PvSec.dll
C:\PROGRA~1\bnxa\frbe.dll
C:\WINDOWS\system32\zzpefr74.dll
C:\WINDOWS\system32\algestese.exe
C:\WINDOWS\system\Mvvp.dll
C:\WINDOWS\system32\PvSec.dll
C:\WINDOWS\system32\WsReource.dll
C:\WINDOWS\system32\cxwchi13.dll
C:\WINDOWS\system32\ncxml.dll
C:\WINDOWS\SYSTEM32\WBEM\BVGCMD02.DLL
C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL
C:\WINDOWS\system32\drivers\amdk5.sys
C:\WINDOWS\System32\Drivers\HTTP.sys
C:\WINDOWS\System32\DRIVERS\jscont22.sys
C:\WINDOWS\system32\drivers\LanPort.sys
C:\WINDOWS\system32\drivers\mffalmj.sys
C:\WINDOWS\system32\drivers\nwlnksipx.sys
C:\WINDOWS\system32\drivers\uphkfla.sys
C:\WINDOWS\system32\drivers\wspipe.sys
C:\WINDOWS\system32\484cntos.dll
C:\PROGRA~1\bnxa\frbe.dll
6、修复文件关联。
7、用LSPFix修复Winsock 。