瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 遇见个棘手的问题..杀了很多次杀不掉.达人来帮帮忙.附SRENG

12   2  /  2  页   跳转

遇见个棘手的问题..杀了很多次杀不掉.达人来帮帮忙.附SRENG

怎么清除呢
gototop
 


运行System Repair Engineer 注册表服务,删除


<kavshell><C:\Progra~1\Eset\svch0st.exe> [N/A]
<66><C:\SysDayN6\svchost.exe> []
<333><C:\Syswm1h\svchost.exe> []
<50><C:\SysAd5D\svchost.exe> []
<4><C:\SysWsj6\svchost.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<yupxdnd><C:\DOCUME~1\new\LOCALS~1\Temp\yupxdnd.exe> [N/A]
<upxdnd><C:\DOCUME~1\new\LOCALS~1\Temp\upxdnd.exe> []
<nwiz><; nwiz.exe /install> []

重起,安全模式,查看,显示所有文件夹,把"隐藏受保护的系统文件"的勾去掉,删除

[C:\WINDOWS\system32\nvshell.dll] [, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\WINDOWS\system32\msdmo.dll]
[C:\SysDayN6\Ghook.dll] [N/A, ]
[C:\SysAd5D\Ghook.dll] [N/A, ]
[C:\Syswm1h\Ghook.dll] [N/A, ]
[C:\SysWsj6\Ghook.dll] [N/A, ]
清空临时文件夹
C:\DOCUME~1\new\LOCALS~1\Temp
gototop
 

删除注册表:
<kavshell><C:\Progra~1\Eset\svch0st.exe> [N/A]
<66><C:\SysDayN6\svchost.exe> []
<333><C:\Syswm1h\svchost.exe> []
<50><C:\SysAd5D\svchost.exe> []
<4><C:\SysWsj6\svchost.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<nortons><C:\WINDOWS\nortons.exe> []
<yupxdnd><C:\DOCUME~1\new\LOCALS~1\Temp\yupxdnd.exe> [N/A]
<upxdnd><C:\DOCUME~1\new\LOCALS~1\Temp\upxdnd.exe> []
删除服务:
[AA803AE4 / AA803AE4][Stopped/Auto Start]
<C:\WINDOWS\system32\AA803AE4.EXE -service><Microsoft Corporation>
结束进程,删除对应的文件:
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\SysDayN6\Ghook.dll] [N/A, ]
[C:\SysAd5D\Ghook.dll] [N/A, ]
[C:\Syswm1h\Ghook.dll] [N/A, ]
[C:\SysWsj6\Ghook.dll] [N/A, ]
在安全模式删除:
C:\Progra~1\Eset\svch0st.exe
C:\SysDayN6\svchost.exe
C:\Syswm1h\svchost.exe
C:\SysAd5D\svchost.exe
C:\SysWsj6\svchost.exe
C:\WINDOWS\mppds.exe
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\nortons.exe
C:\DOCUME~1\new\LOCALS~1\Temp\yupxdnd.exe
C:\DOCUME~1\new\LOCALS~1\Temp\upxdnd.exe
C:\WINDOWS\system32\AA803AE4.EXE
C:\SysDayN6\Ghook.dll
C:\SysAd5D\Ghook.dll
C:\Syswm1h\Ghook.dll
C:\SysWsj6\Ghook.dll
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT