12   2  /  2  页   跳转

今天发现中了一查不到的病毒?

又这么一堆 加我QQ  463216947帮你弄
gototop
 

注册表启动项
<Microsoft Autorun7><C:\WINDOWS\system32\nwiztlbu.exe> []
<Microsoft Autorun5><C:\WINDOWS\system32\mosou.exe> []
<Microsoft Autorun1><C:\WINDOWS\system32\nwizdh.exe> []
<WinForm><C:\WINDOWS\WinForm.exe> []
<TIMHost><C:\WINDOWS\TIMHost.exe> []
删除服务
[B7D22DCA / B7D22DCA][Stopped/Auto Start]
<C:\WINDOWS\system32\5244AC95.EXE -k><Microsoft Corporation>
删除
[C:\WINDOWS\system32\WinForm.dll] [N/A, ]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, ]
[C:\WINDOWS\system32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[C:\WINDOWS\system32\nwiztlbb.dll] [N/A, ]
[C:\WINDOWS\system32\MOSOU.dll] [N/A, ]
[C:\WINDOWS\system32\nwizwlwzs.dll] [N/A, ]
[C:\WINDOWS\system32\dh2104.dll] [N/A, ]
[C:\WINDOWS\system32\MOSOU.dll] [N/A, ]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[C:\WINDOWS\system32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\system32\WinForm.dll] [N/A, ]
[PID: 2484][C:\WINDOWS\system32\ntsd.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 2532][C:\WINDOWS\system32\ntsd.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
扫日志的时候尽量把不用的软件关掉
gototop
 

结束进程
[C:\WINDOWS\system32\WinForm.dll] [N/A, ]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, ]
[C:\WINDOWS\system32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[C:\WINDOWS\system32\nwiztlbb.dll] [N/A, ]
[C:\WINDOWS\system32\MOSOU.dll] [N/A, ]
[C:\WINDOWS\system32\nwizwlwzs.dll] [N/A, ]
[C:\WINDOWS\system32\dh2104.dll] [N/A, ]
删除启动项
<Microsoft Autorun7><C:\WINDOWS\system32\nwiztlbu.exe> []
<Microsoft Autorun5><C:\WINDOWS\system32\mosou.exe> []
<Microsoft Autorun1><C:\WINDOWS\system32\nwizdh.exe> []
<WinForm><C:\WINDOWS\WinForm.exe> []
<TIMHost><C:\WINDOWS\TIMHost.exe> []
删除服务
[B7D22DCA / B7D22DCA][Stopped/Auto Start]
<C:\WINDOWS\system32\5244AC95.EXE -k><Microsoft Corporation>
在相应路径下删除上述文件


gototop
 

删除
[C:\WINDOWS\system32\WinForm.dll] [N/A, ]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, ]
[C:\WINDOWS\system32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[C:\WINDOWS\system32\nwiztlbb.dll] [N/A, ]
[C:\WINDOWS\system32\MOSOU.dll] [N/A, ]
[C:\WINDOWS\system32\nwizwlwzs.dll] [N/A, ]
[C:\WINDOWS\system32\dh2104.dll] [N/A, ]
[C:\WINDOWS\system32\MOSOU.dll] [N/A, ]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[C:\WINDOWS\system32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\system32\WinForm.dll] [N/A, ]
[PID: 2484][C:\WINDOWS\system32\ntsd.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 2532][C:\WINDOWS\system32\ntsd.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)
这个在哪里啊?
gototop
 

是不是把所有的进程中含有下面进程都删掉?
[C:\WINDOWS\system32\WinForm.dll] [N/A, ]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, ]
[C:\WINDOWS\system32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[C:\WINDOWS\system32\nwiztlbb.dll] [N/A, ]
[C:\WINDOWS\system32\MOSOU.dll] [N/A, ]
[C:\WINDOWS\system32\nwizwlwzs.dll] [N/A, ]
[C:\WINDOWS\system32\dh2104.dll] [N/A, ]
[C:\WINDOWS\system32\MOSOU.dll] [N/A, ]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[C:\WINDOWS\system32\TIMHost.dll] [N/A, ]
[C:\WINDOWS\system32\WinForm.dll] [N/A, ]
gototop
 

xiexie!
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT