trojan.dl.win32.mnless.ahr(wsctf.exe)分析查杀

豆豆网   技术应用频道   2008年06月08日  【字号: 收藏本文

本文详细介绍trojan.dl.win32.mnless.ahr(wsctf.exe)分析查杀

  麻烦大虾帮忙看下怎么杀掉trojan.dl.win32.mnless.ahr这个病毒

  trojan.dl.win32.mnless.ahr,wsctf.exe查杀方法

  1.建议使用XDelBox删除以下文件:

  wfhyt.dll,kghk.dll,lfsjgf.dll,stehs.dll,fghshj.dll,frntrn.dll,qrhhb.dll,drghszd.dll,

  fngn.dll,gjjte.dll,xgnfn.dll,xfgnhcgfm.dll,serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,

  xfgnfx.dll,serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,xdndn.dll,xdfntt.dll,hgfhk.dll,

  dnteh.dll,xfng.dll,njritc.dll,chmfcmh.dll,jwlah.dll,gmnait.dll,hfjg.dll,thurh.dll,mgmgmm.dll,

  oqrthc.dll,fehom.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll,zdbdb.dll,ydgn.dll,dbfb.dll,fjnbv.dll,

  wmsat.dll,setrhes.dll,cdxbfxdb.dll,xfgnxfn.dll,gjkhj.dll,xdhdg.dll,rhs.dll,mrjhtjd.dll,zdbfbd.dll,

  fjyjy.dll,fxnfnh.dll,bjrvm.dll,ektvm.dll,rdthr.dll,rgfjj.dll,dscef.dll,crugd.dll,lariytrz.dll,hjaiq.dll,

  kduy.dll,hkfgh.dll,awef.dll,dfhsh.dll,ethsh.dll,stehs.dll,sthth.dll,msepbe.dll,

  ; wsctf.exe

  ; c:program filescommon filesmicrosoft sharedxnxlufi.exe

  ; msfir80.exe

  ; c:program filescommon filessystemyyjnldu.exe

  ; %systemroot%system32dumprep 0 -k

  ; msime80.exe

  kcomx32.exe

  c:windowssystem32 undll32.exe c:windowssystem32mscories.dll,install

  c:windowssystem32wdjqwdipvb.exe

  c:docume~1charleslocals~1  empusbcams3.sys

  c:docume~1charleslocals~1  empusbhcid.sys

  c:windowssystem32drivers pf.sys

  c:windowssystem32drivers adprobe.sys

  c:windowssystem32driversxfilemgr.sys

  2.删除重启后使用SREng修复下面各项:

  启动项目 -- 注册表之如下项删除:

  注意该项[AppInit_DLLs]修改:把<wfhyt.dll,kghk.dll,lfsjgf.dll,

  stehs.dll,fghshj.dll,frntrn.dll,qrhhb.dll,drghszd.dll,fngn.dll,gjjte.dll, xgnfn.dll,xfgnhcgfm.dll,

  serger.dll,bnxnb.dll,fxgnfx.dll,jzijj.dll,xfgnfx.dll,

  serghjm.dll,thsddh.dll,xbcvxb.dll,zfdzb.dll,xdndn.dll,xdfntt.dll,hgfhk.dll, dnteh.dll,xfng.dll,njritc.dll,

  chmfcmh.dll,jwlah.dll,gmnait.dll,hfjg.dll,thurh.dll,

  mgmgmm.dll,oqrthc.dll,fehom.dll,jyjlt.dll,ijatnaw.dll,sehhter.dll,fhjfg.dll, zdbdb.dll,ydgn.dll,dbfb.dll,

  fjnbv.dll,wmsat.dll,setrhes.dll,cdxbfxdb.dll, xfgnxfn.dll,gjkhj.dll,xdhdg.dll,rhs.dll,mrjhtjd.dll,zdbfbd.dll,fjyjy.dll, fxnfnh.dll,bjrvm.dll,ektvm.dll,rdthr.dll,rgfjj.dll,dscef.dll,crugd.dll,lariytrz.dll, hjaiq.dll,kduy.dll,

  hkfgh.dll,awef.dll,dfhsh.dll,ethsh.dll,stehs.dll,sthth.dll, msepbe.dll,>修改为<>即清空

  [wsctf.exe] <; wsctf.exe>

  [nhbivui] <; C:Program FilesCommon FilesMicrosoft Sharedxnxlufi.exe>

  [MsServer] <; msfir80.exe>

  [mhlclyg] <; C:Program FilesCommon FilesSystemyyjnldu.exe>

  [KernelFaultCheck] <; %systemroot%system32dumprep 0 -k>

  [IMJPMIG8.2] <; msime80.exe>

  [kcomx] <kcomx32.exe>

  [N/A] <C:WINDOWSsystem32Rundll32.exe C:WINDOWSsystem32mscories.dll,Install>

  启动项目 -- 服务 -- Win32服务应用程序之如下项禁用:

  [SysSetupNetWork / SetupNetWork] <C:Windowssystem32WDJQWDIPVB.EXE>

  启动项目 -- 服务-- 驱动程序之如下项禁用:

  [Sc Manager / Sc Manager] <??C:DOCUME~1charlesLOCALS~1Tempusbcams3.sys>

  [iCafe Manager / iCafe Manager] <??C:DOCUME~1charlesLOCALS~1Tempusbhcid.sys>

  [NetGroup Packet Filter Driver / NPF] <system32drivers pf.sys>

  [Radeon Probe Driver / RadProbe] <system32DRIVERSRadProbe.sys>

  [xFileMgr / xFileMgr] <??C:WINDOWSsystem32DriversxFileMgr.sys>

  系统修复-- HOSTS文件--重置

责编:豆豆技术应用

正在加载评论...