用扫日志的SRENG工具删除注册表项,
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<System><C:\WINDOWS\system32\kernels32.exe> []
<runner1><C:\WINDOWS\retadpu20.exe 61A847B5BBF72810328B2B27128065E9C084320161C4661227A755E9C2933154389A> [N/A]
<service><C:\WINDOWS\internat.exe> []
<winform><C:\WINDOWS\winform.exe> []
<mppdss><C:\WINDOWS\mppdss.exe> []
<upxdnd><C:\DOCUME~1\z\LOCALS~1\Temp\upxdnd.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{0F9503E0-03E0-F956-E0F9-3E0953E0F956}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\03E0F956.dll> []
<{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.bmp> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rpcc]
<WinlogonNotify: rpcc><C:\WINDOWS\system32\rpcc.dll> []
==================================
服务
[620B37FA / 620B37FA][Stopped/Auto Start]
<C:\WINDOWS\system32\60562AE7.EXE -g><Microsoft Corporation>
[Windows aeoa RunThem / aeoa][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\vzjv\fjtf.dll>< >
[B535D973 / B535D973][Stopped/Auto Start]
<C:\WINDOWS\system32\62881724.EXE -k><Microsoft Corporation>
[BA5500AC / BA5500AC][Stopped/Auto Start]
<C:\WINDOWS\system32\614FE93B.EXE -p><Microsoft Corporation>
[Registry Protector / DiRVIn][Running/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL2KXP.EXE C:\WINDOWS\SYSTEM32\WBEM\EUHSN.DLL,Export 1087><Microsoft Corporation>
[inetinfo / inefo][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\system32\inefo\inetinfo.dll><Microsoft Corporation>
[kkdj3sdf3 / kkdj3sdf3][Stopped/Auto Start]
<C:\WINDOWS\system32\kkdj3sdf3.exe -j><Microsoft Corporation>
[Windows Gateway / Partner][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\vmqki.dll><Microsoft Corporation>
[System Event Notification / SENS][Running/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\akkmkcof.dll><N/A>
[Windows Accounts Driver / windows_0][Stopped/Auto Start]
<C:\WINDOWS\system32\dl4.exe><N/A>
==================================
驱动程序
[acpidisk / acpidisk][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[akkmkcof / akkmkcof][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\akkmkcof.sys><N/A>
[bbchabeb / bbchabeb][Stopped/Boot Start]
<\SystemRoot\system32\drivers\bbchabeb.sys><N/A>
[cdnprot / cdnprot][Running/Boot Start]
<\SystemRoot\system32\drivers\cdnprot.sys><中国互联网络信息中心(CNNIC)>
[diyctu4 / diyctu44][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\diyctu44.sys><Microsoft Corporation>
[ebceibad / ebceibad][Stopped/Boot Start]
<\SystemRoot\system32\drivers\ebceibad.sys><N/A>
[fgiihgci / fgiihgci][Stopped/Boot Start]
<\SystemRoot\system32\drivers\fgiihgci.sys><N/A>
[mszxfz76 / mszxfz76][Stopped/Boot Start]
<\SystemRoot\system32\\drivers\\system32\\drivers\\%s.sys.sys><N/A>
[mvyzvz2 / mvyzvz29][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\mvyzvz29.sys><N/A>
[pifmgy / pifmgy][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\pifmgy.sys><N/A>
[yiqmfk6 / yiqmfk67][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\yiqmfk67.sys><Microsoft Corporation>
==================================
浏览器加载项
[CAdLogic
Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\CPUSH\cpush.dll, >
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[]
{C74CDF30-68C2-49B4-9918-EBD66B8D9FBF} <C:\WINDOWS\system32\ieqzetetvcyhl.dll, >
[ieshow Class]
{CE7C3CF0-4B15-11D1-ABED-709549C15050} <C:\WINDOWS\ieshow\ieshow.dll, ieshow.cn, Inc.>
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[CAdLogic
Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\CPUSH\cpush.dll, >
[CdnForIE Class]
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} <C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC>
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[RDS.DataSpace]
{BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Common Files\System\msadc\msadco.dll, Microsoft Corporation>
[]
{C74CDF30-68C2-49B4-9918-EBD66B8D9FBF} <C:\WINDOWS\system32\ieqzetetvcyhl.dll, >
[ieshow Class]
{CE7C3CF0-4B15-11D1-ABED-709549C15050} <C:\WINDOWS\ieshow\ieshow.dll, ieshow.cn, Inc.>
[访问通用网址]
<C:\Program Files\CNNIC\Cdn\cnnic.htm, N/A>
——————————————————————————————————————————————
用冰刃删除文件。
C:\WINDOWS\system32\kernels32.exe
C:\WINDOWS\retadpu20.exe
C:\WINDOWS\internat.exe
C:\WINDOWS\winform.exe
C:\WINDOWS\mppdss.exe
C:\DOCUME~1\z\LOCALS~1\Temp\upxdnd.exe
C:\Program Files\Common Files\Microsoft Shared\MSINFO\03E0F956.dll
C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.bmp
C:\WINDOWS\system32\rpcc.dll
C:\WINDOWS\system32\60562AE7.EXE
C:\PROGRA~1\vzjv\fjtf.dll
C:\WINDOWS\system32\62881724.EXE
C:\WINDOWS\system32\614FE93B.EXE
C:\WINDOWS\SYSTEM32\RUNDLL2KXP.EXE
C:\WINDOWS\SYSTEM32\WBEM\EUHSN.DLL
C:\WINDOWS\system32\inefo\inetinfo.dll
C:\WINDOWS\system32\kkdj3sdf3.exe
C:\WINDOWS\system32\vmqki.dll
C:\WINDOWS\System32\akkmkcof.dll
C:\WINDOWS\system32\dl4.exe
C:\WINDOWS\system32\drivers\acpidisk.sys
C:\WINDOWS\system32\drivers\akkmkcof.sys
C:\WINDOWS\system32\drivers\bbchabeb.sys
C:\WINDOWS\system32\drivers\cdnprot.sys
C:\WINDOWS\System32\DRIVERS\diyctu44.sys
C:\WINDOWS\system32\drivers\ebceibad.sys
C:\WINDOWS\system32\drivers\fgiihgci.sys
C:\WINDOWS\system32\\drivers\\system32\\drivers\\%s.sys.sys
C:\WINDOWS\System32\DRIVERS\mvyzvz29.sys
C:\WINDOWS\System32\DRIVERS\pifmgy.sys
C:\WINDOWS\System32\DRIVERS\yiqmfk67.sys
C:\Program Files\Common Files\CPUSH\cpush.dll
C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
C:\WINDOWS\system32\ieqzetetvcyhl.dll
C:\WINDOWS\ieshow\ieshow.dll
C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
C:\Program Files\Common Files\CPUSH\cpush.dll
C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
C:\WINDOWS\system32\shdocvw.dll
C:\Program Files\Common Files\System\msadc\msadco.dll
C:\WINDOWS\system32\ieqzetetvcyhl.dll
C:\WINDOWS\ieshow\ieshow.dll
C:\Program Files\CNNIC\Cdn\cnnic.htm
————————————————————————————————
用SRENG工具修改注册表项
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,c:\WINDOWS\k11156408682.exe> [N/A]
将 <Userinit><C:\WINDOWS\system32\userinit.exe,c:\WINDOWS\k11156408682.exe> [N/A]
改为 <Userinit><C:\WINDOWS\system32\userinit.exe,> [N/A]
用冰刃删除文件:
c:\WINDOWS\k11156408682.exe
————————————————————————————————
唉........................
太多了,重装吧!!!!!!!!!!!!!!!!!