如何vbjava.exe,LYLoader.exe,nwizdh.exe,mydata.exe等病毒?
本文主要介绍日志中出现以下病毒文件的清除方法:vbjava.exe/LYLoader.exe/nwizdh.exe/nwizzhuxians.exe/mydata.exe/nwizqjsj.exe/MsIMMs32.exe
一:SREng日志:(略)
解决方法:
注意:到down.45it.com下载SREng
1.使用SREng删除以下选项(详细步骤:打开SREng-启动项目-注册表)
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerRun]
<MSDEG32><LYLoader.exe> [N/A]
<MSDWG32><LYLoadbr.exe> [N/A]
<MSDCG32 ><LYLeador.exe> [N/A]
<MSDOG32><LYLoador.exe> [N/A]
<MSDSG32><LYLoadar.exe> [N/A]
<MSDMG32><LYLoadmr.exe> [N/A]
<MSDHG32><LYLoadhr.exe> [N/A]
<MSDQG32><LYLoadqr.exe> [N/A]
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionWinlogon]
<shell><Explorer.exe vbjava.exe> [N/A]
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
<gcs83><; D:DOCUME~1chinniLOCALS~1Tempc0nime.exe> [N/A]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
<Microsoft Autorun1><; D:WINDOWS.0system32nwizdh.exe> [N/A]
<Microsoft Autorun12><; D:WINDOWS.0system32nwizzhuxians.exe> [N/A]
<Microsoft Autorun4><; D:WINDOWS.0system32mydata.exe> [N/A]
<Microsoft Autorun7><; D:WINDOWS.0system32nwizqjsj.exe> [N/A]
<MsIMMs32><; D:WINDOWS.0MsIMMs32.exe> [N/A]
2.使用SREng删除以下服务(详细步骤:打开SREng-启动项目-win32服务应用程序):
97F54000 / 97F54000]
<D:WINDOWS.0system326C500000.EXE -a><N/A>
[EA6917D0 / EA6917D0]
<D:WINDOWS.0system321FCAAE71.EXE -EA6917D0><N/A>
[FCE82000 / FCE82000]可疑,建议删除
<D:WINDOWS.0system324807E000.EXE -k><Microsoft Corporation>
[Win32 Debug Service / MSDebugsvc]可疑,建议删除
<D:WINDOWS.0system32rundll32.exe msdebug.dll,input><Microsoft Corporation>
[WebClient / WebClient]
<D:WINDOWS.0system32svchost.exe -k LocalService-->%SystemRoot%System32webclnt.dll><Microsoft Corporation>
[Windows DHCP Service / WinDHCPsvc]可疑,建议删除
<D:WINDOWS.0system32rundll32.exe windhcp.ocx,input><Microsoft Corporation>
[WMI Performance API / WMIApiSrv]可疑,建议删除
<D:WINDOWS.0system32rundll32.exe WMIApiSrv.dll,input><Microsoft Corporation>
3.使用SREng删除以下驱动程序(详细步骤:打开SREng-启动项目-驱动程序)
[bxodv / bxodvq]
<SystemRootSystem32DRIVERSbxodvq.sys><N/A>
[kahkhl / kahkhl]
<SystemRootsystem32driverskahkhl.sys><N/A>
4.到down.45it.com下载360安全卫士进行清理。
PS:以上日志由网友博客ixigua提供,我站进行编辑整理发布。
本文地址:http://www.45fan.com/dnjc/20594.html