bootvidgj.dll病毒简介:
文件名: Bootvidgj.dll
出品公司:
产品名称:
版本号:
文件大小:629676byte
上报时间:2008-8-22 11:04:59
MD5值: EC3B5EFAE7A75E17D36EA9445DEEBC4C
bootvidgj.dll病毒清除办法:
建议断网后先用下面的工具全选,清理系统临时文件和IE临时文件夹
http://www.atribune.org/public-beta/ATF-Cleaner.exe
下载windows清理助手V2.6清理一遍,记得之前更新好
http://www.arswp.com/download/arswp2/arswp2.zip
然后完成下列步骤
项目很多。。。很难保证没有纰漏,请完成后再扫一份日志过来
1.建议使用XDelBox删除以下文件:(XDelBox1.7下载)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除(请勾上“抑制再生”的选项),电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
c:windowssystem32kcien32.exe
c:windowssystem32winlib .dll
c:windowssystem32kcien32.dll
c:windowssystem32adsntzt.dll
c:windowssystem32bootvidgj.dll
c:windowssystem32catsrvwl.dll
c:windowssystem32kbdswjr.dll
c:windowssystem32ksuserfy.dll
c:windowssystem32msobjstl.dll
c:windowssystem32scrruncqsj.dll
c:windowssystem32slbiopfs2.dll
c:windowssystem32tscfgwmijxsj.dll
c:windowssystem32ptjhehlp.dll
c:windowssystem32mpwdeapi.dll
c:windowssystem32mndhfdwd.dll
c:windowssystem32apzhdtde.dll
c:windowssystem32mnmhhsrv.dll
c:windowssystem32kcien32.exe
c:windowssystem320kill.bat
c:windowssystem32usmsvc.exe(这项建议事先上传检查下)
c:windowssystem32hbmhly.exe
c:windowsavtapit.dll
c:windowsmayababymayababymain.exe
c:program filescommon filesmicrosoft sharedmsinforejoice101.exe
c:windowssystem32driversl56ftcf.sys
c:bf5a430c676b2a9.dat
c:d066785548acc5.dat
c:docume~1admini~1locals~1temptmp5.tmp
c:windowssystem32driverswvgtmoay59.sys
c:docume~1admini~1locals~1temprarsfx0vdd-x86.sys
c:docume~1admini~1locals~1temptmp9.tmp
c:docume~1admini~1locals~1temptmpf.tmp
c:docume~1admini~1locals~1temp.tmp
c:windowssystem32drivershbkernel.sys
c:docume~1admini~1locals~1temptmpd.tmp
c:docume~1admini~1locals~1temptmpb.tmp
c:windowssystem32driversacpidisk.sys
2.删除重启后使用SREng修复下面各项:
启动项目 -- 注册表之如下项删除:
[scrruncqsj.dll] <C:WINDOWSsystem32scrruncqsj.dll>
[kbdswjr.dll] <C:WINDOWSsystem32kbdswjr.dll>
[slbiopfs2.dll] <C:WINDOWSsystem32slbiopfs2.dll>
[catsrvwl.dll] <C:WINDOWSsystem32catsrvwl.dll>
[ksuserfy.dll] <C:WINDOWSsystem32ksuserfy.dll>
[bootvidgj.dll] <C:WINDOWSsystem32bootvidgj.dll>
[tscfgwmijxsj.dll] <C:WINDOWSsystem32tscfgwmijxsj.dll>
[adsntzt.dll] <C:WINDOWSsystem32adsntzt.dll>
[msobjstl.dll] <C:WINDOWSsystem32msobjstl.dll>
[] <C:WINDOWSsystem32ksuserfy.dll>
[] <C:WINDOWSsystem32bootvidgj.dll>
[]
<C:WINDOWSsystem32tscfgwmijxsj.dll>
[] <C:WINDOWSsystem32adsntzt.dll>
[] <C:WINDOWSsystem32msobjstl.dll>
[] <C:WINDOWSsystem32ptjhehlp.dll>
[] <C:WINDOWSsystem32mpwdeapi.dll>
[] <C:WINDOWSsystem32scrruncqsj.dll>
[] <C:WINDOWSsystem32kbdswjr.dll>
[] <C:WINDOWSsystem32slbiopfs2.dll>
[] <C:WINDOWSsystem32catsrvwl.dll>
[] <C:WINDOWSsystem32mndhfdwd.dll>
[] <C:WINDOWSsystem32apzhdtde.dll>
[] <C:WINDOWSsystem32mnmhhsrv.dll>
[kcien32] <kcien32.exe>
[kvonreboot] <; C:WINDOWSsystem320Kill.bat>
[usmsvc] <; C:WINDOWSsystem32usmsvc.exe>
[HBmhly] <; "C:WINDOWSsystem32HBmhly.exe" -r>
[IFEO[QQDoctor.exe]] <TASKMAN.EXE>
[IFEO[QQDoctorMain.exe]] <TASKMAN.EXE>
[IFEO[SelfUpdate.exe]] <TASKMAN.EXE>
启动项目 -- 服务 -- Win32服务应用程序之如下项删除:
[WbWin / WbWin] <C:WINDOWSSystem32svchost.exe -k
netsvcs-->%SystemRoot%avtapit.dll>
[网络服务 / Network Services] <C:WINDOWSMayaBabyMayaBabyMain.exe>
[Windows_rejoice2007_101 / Windows_rejoice2007_101] <C:Program FilesCommon
FilesMicrosoft SharedMSINFOrejoice101.exe>
启动项目 -- 服务-- 驱动程序之如下项删除:
[0l56ftcf / 0l56ftcf] <SystemRootsystem32driversl56ftcf.sys>
[3bf5a430c676b2a9 / 3bf5a430c676b2a9] <??C:bf5a430c676b2a9.dat>
[49d066785548acc5 / 49d066785548acc5] <??C:d066785548acc5.dat>
[zftp / zftp] <??C:DOCUME~1ADMINI~1LOCALS~1Temptmp5.tmp>
[wvgtmoay5 / wvgtmoay59] <SystemRootSystem32DRIVERSwvgtmoay59.sys>
[VirtualDrive / VirtualDrive]
<??C:DOCUME~1ADMINI~1LOCALS~1TempRarSFX0vdd-x86.sys>
[mnsf / mnsf] <??C:DOCUME~1ADMINI~1LOCALS~1Temptmp9.tmp>
[jtio / jtio] <??C:DOCUME~1ADMINI~1LOCALS~1TemptmpF.tmp>
[IIS Manager / IIS Manager ] <??C:DOCUME~1ADMINI~1LOCALS~1Temp.tmp>
[HBKernel Driver / HBKernel] <SystemRootsystem32DRIVERSHBKernel.sys>
[drop / drop] <??C:DOCUME~1ADMINI~1LOCALS~1TemptmpD.tmp>
[cqit / cqit] <??C:DOCUME~1ADMINI~1LOCALS~1TemptmpB.tmp>
[acpidisk / acpidisk] <??C:WINDOWSsystem32driversacpidisk.sys>