Win32.Downloader.RvDog.f 类型:下载器 文件路径:C:WINDOWSsvchost.exe
另外,在卡卡助手查杀恶意软件时发现8个恶意软件,但都无法清除
Win32.Downloader.RvDog.f 查杀方法
1.建议使用XDelBox删除以下文件:
c:windowssystem32jdsaex.dll
c:windowssystem32cedafb.dll
c:windowssystem32wyrsdj.dll
c:windowssystem32wrqszl.dll
c:windowssystem32jfrwdh.dll
c:windowssystem32hhrdxd.dll
c:windowssystem32hfrdzx.dll
c:windowssystem32zjydcx.dll
c:windowssystem32sgrefg.dll
c:windowssystem32zgfdet.dll
; c:windowsyuiabct.exe
; c:windowswinsvr64.exe
tvt_gina.dll
c:windowssystem32drivers smapip.sys
c:windowssystem32drivers ppwrif.sys
c:progra~1common~1symant~1symcdatascfids~120050404.003symidsco.sys
c:docume~1yjiulocals~1 emp mp31.tmp
c:windowssystem32driverspcdrndisuio.sys
c:windowssystem32driversibmbldid.sys
c:docume~1yjiulocals~1 emp mp35.tmp
c:docume~1yjiulocals~1 emp mp22.tmp
c:docume~1yjiulocals~1 emp mp29.tmp
c:windowssystem32driversasc3550.sys
c:windowssystem32driversdac2w2k.sys
c:windowssystem32driversaeaudio.sys
c:windowssystem32drivershsxhwazl.sys
c:windowssystem32driversoxser.sys
c:windowssystem32driverssym_hi.sys
c:windowssystem32driverssym_u3.sys
2.删除重启后使用SREng修复下面各项:
启动项目 -- 注册表之如下项删除:
[{B29583D8-033A-4B9F-8553-7C5458F3FB8E}] <C:WINDOWSsystem32jdsaex.dll>
[{84143967-B645-4BFF-B873-DA1DC886E9A7}] <C:WINDOWSsystem32cedafb.dll>
[{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}] <C:WINDOWSsystem32wyrsdj.dll>
[{F99DEFDD-200B-4410-B572-E90883D527D2}] <C:WINDOWSsystem32wrqszl.dll>
[{841529CB-7F77-4B99-A895-B5441E0D302F}] <C:WINDOWSsystem32jfrwdh.dll>
[{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}] <C:WINDOWSsystem32hhrdxd.dll>
[{1DB3C525-5271-46F7-887A-D4E1ADAA7632}] <C:WINDOWSsystem32hfrdzx.dll>
[{45AADFAA-DD36-42AB-83AD-0521BBF58C24}] <C:WINDOWSsystem32zjydcx.dll>
[{8C41B7F7-3168-400D-A702-0E7EFE0BA304}] <C:WINDOWSsystem32sgrefg.dll>
[{28EB3777-3E23-4E72-8449-A992D09D24C3}] <C:WINDOWSsystem32zgfdet.dll>
[{45AADFAA-DD36-42AB-83AD-0521BBF58C24}] <C:WINDOWSsystem32zjydcx.dll>
[{45AADFAA-DD36-42AB-83AD-0521BBF58C24}] <C:WINDOWSsystem32zjydcx.dll>
[yuiabct] <; C:WINDOWSyuiabct.exe>
[WINSvr64] <; C:WINDOWSWINSvr64.exe>
[GinaDLL] <tvt_gina.dll>
启动项目 -- 服务-- 驱动程序之如下项禁用:
[TSMAPIP / TSMAPIP] <System32driversTSMAPIP.SYS>
[TPPWRIF / TPPWRIF] <System32driversTppwrif.sys>
[SYMIDSCO / SYMIDSCO] <??C:PROGRA~1COMMON~1SYMANT~1SymcDataSCFIDS~120050404.003symidsco.sys>
[ping / ping] <??C:DOCUME~1yjiuLOCALS~1Temp mp31.tmp>
[PCDRNDISUIO Usermode I/O Protocol / PcdrNdisuio] <system32DRIVERSpcdrndisuio.sys>
[IBMTPCHK / IBMTPCHK] <??C:WINDOWSsystem32DriversIBMBLDID.sys>
[fmsq / fmsq] <??C:DOCUME~1yjiuLOCALS~1Temp mp35.tmp>
[dohs / dohs] <??C:DOCUME~1yjiuLOCALS~1Temp mp22.tmp>
[cqit / cqit] <??C:DOCUME~1yjiuLOCALS~1Temp mp29.tmp>
[asc3550 / asc3550] <SystemRootsystem32DRIVERSasc3550.sys>
[dac2w2k / dac2w2k] <SystemRootsystem32DRIVERSdac2w2k.sys>
[AEAudio Service / AEAudioService] <system32driversAEAudio.sys>
[HSXHWAZL / HSXHWAZL] <system32DRIVERShsxhwazl.sys>
[OX16C95x Serial port driver / oxser] <system32DRIVERSoxser.sys>
[sym_hi / sym_hi] <SystemRootsystem32DRIVERSsym_hi.sys>
[sym_u3 / sym_u3] <SystemRootsystem32DRIVERSsym_u3.sys>