FjOs0r.dll, OnlO0r.dll Trojan Group removal method _ virus killing
Last Update:2017-01-18
Source: Internet
Author: User
There should be a special generator, encountered a lot of
Do not write analysis of the ...
Workaround:
1, download Sreng2.zip and Icesword120_cn.zip (hereinafter referred to as the Ice blade)
After downloading, put the desktop directly.
2. Disconnect the network and close unwanted connections.
3, open the ice blade, set-prohibit thread creation, OK.
4, delete the following files (such as the hint does not exist the file does not exist skip can):
Code:
C:\Program Files\Common Files\fjos0r.dll 31791 bytes
C:\Program files\internet Explorer\onlo0r.bak 27183 bytes
C:\Program files\internet Explorer\onlo0r.dll 31791 bytes
C:\Program files\internet explorer\onlo0r.obk 31791 bytes
These 4 are principals and may not have the same filename. Note the file size.
And these Trojans:
Code:
C:\Windows\system32\dadoor0.dll
C:\Windows\system32\dhdoor0.dll
C:\Windows\system32\mhdoor0.dll
C:\Windows\system32\mydoor0.dll
C:\Windows\system32\qhdoor0.dll
C:\Windows\system32\qjdoor0.dll
C:\Windows\system32\rxdoor0.dll
C:\Windows\system32\tldoor0.dll
C:\Windows\system32\wddoor0.dll
C:\Windows\system32\wgdoor0.dll
C:\Windows\system32\wldoor0.dll
C:\Windows\system32\wodoor0.dll
C:\Windows\system32\ztfree0.dll
C:\Windows\system32\zxdoor0.dll
and find out if there are any autorun.inf and suspicious files under the c-f disk. If anything, it's deleted.
5, set the ice blade, reboot and monitor.
6, after reboot, open Sreng, delete:
Code:
[Hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
<{cc3596cb-d6c1-eca1-ae51-deea63f6c21c}><c:\program files\internet Explorer\onlo0r.dll> [Microsoft Corporation]
<{3422FB0F-95EB-458A-8B56-39552017A4EF}><C:\winnt\system32\mhdoor0.dll> []
<{5731EA1D-6AAF-4DE9-BDDA-7B390A75B286}><C:\winnt\system32\wodoor0.dll> []
<{E952B8F8-D91A-4EDD-851C-EE1A0F944469}><C:\winnt\system32\ztfree0.dll> []
<{E03C23BD-35B7-49C2-BBCA-6D8CEC2507E3}><C:\winnt\system32\wldoor0.dll> []
<{A3C95A74-638D-4C6B-A856-4B27664A7F47}><C:\winnt\system32\wgdoor0.dll> []
<{D8CC4845-441C-44F8-9053-28F2EF67655B}><C:\winnt\system32\dadoor0.dll> []
<{0DAEBA6A-86CA-4B96-AF96-0C8C2C358FBD}><C:\winnt\system32\dhdoor0.dll> []
<{6826A3DB-EA8E-4E67-880D-53D04C7C0BD8}><C:\winnt\system32\qjdoor0.dll> []
<{EDFF29C1-5A70-4460-AC1D-16DCB4B672F0}><C:\winnt\system32\rxdoor0.dll> []
<{68F7767A-090C-4BBF-A015-720ACC6706E2}><C:\winnt\system32\wddoor0.dll> []
<{08E909A4-B236-48DD-8BCC-90A604B93E68}><C:\winnt\system32\tldoor0.dll> []
<{781FBCC1-99C7-4AE0-95F7-66EA49E86DD7}><C:\winnt\system32\zxdoor0.dll> []
<{4E3FBFA4-F1CC-4B66-B333-B9F0FF4B4748}><C:\winnt\system32\mydoor0.dll> []
<{ABD0935D-B35A-47BD-BA9A-81678DDE74DD}><C:\winnt\system32\qhdoor0.dll> []
7, if the kill soft can not open, prompt initialization error, to kill soft directory folder.
Open the "Drag to delete to me. bat", there are see Ws2_32.dll or MFC42.dll folder dragged to it.
8, continue to reboot. Restart after the revision of QQ, online games and other passwords.