用XDelBox删除以下文件
c:\windows\system32\winlib .dll
debugfile.exe
egomoo.exe
c:\windows\system32\webprint.exe
c:\windows\system32\termsrvgmm.dll
c:\windows\system32\termsrvgmm.dll
c:\windows\system32\pihnre.dll
c:\windows\system32\aa.exe
c:\windows\lsuss.exe
c:\documents and settings\all users\favorites\netservice.exe
c:\program files\common files\microsoft shared\msinfo\server.exe
c:\windows\system32\cpfzxu.dll
c:\windows\system32\drivers\079mzxg.sys
c:\windows\system32\drivers\3pwp.sys
c:\windows\system32\drivers\cpfzxu.sys
c:\windows\system32\drivers\amuylf.sys
c:\windows\system32\drivers\rgkzkn.sys
c:\windows\system32\drivers\xproc.sys
c:\windows\system32\drivers\xblock3.sys
c:\windows\system32\drivers\mxdispdr.sys
c:\windows\system32\alxtb1.dll
c:\windows\downlo~1\submit~1.dll
c:\windows\downlo~1\inputc~1.dll
c:\program files\common files\cpush\cpush.dll
c:\windows\downloaded program files\certinstall.dll
c:\windows\system32\aliedit\aliedit.dll
c:\documents and settings\all users\application data\microsoft\pctools\pctools.dll
用SREng删除启动项:
<IFEO[1.exe]> <debugfile.exe>
<IFEO[10.exe]> <debugfile.exe>
<IFEO[11.exe]> <debugfile.exe>
<IFEO[12.exe]> <debugfile.exe>
<IFEO[13.exe]> <debugfile.exe>
<IFEO[14.exe]> <debugfile.exe>
<IFEO[15.exe]> <debugfile.exe>
<IFEO[16.exe]> <debugfile.exe>
<IFEO[17.exe]> <debugfile.exe>
<IFEO[18.exe]> <debugfile.exe>
<IFEO[19.exe]> <debugfile.exe>
<IFEO[2.exe]> <debugfile.exe>
<IFEO[20.exe]> <debugfile.exe>
<IFEO[21.exe]> <debugfile.exe>
<IFEO[22.exe]> <debugfile.exe>
<IFEO[3.exe]> <debugfile.exe>
<IFEO[4.exe]> <debugfile.exe>
<IFEO[5.exe]> <debugfile.exe>
<IFEO[6.exe]> <debugfile.exe>
<IFEO[7.exe]> <debugfile.exe>
<IFEO[8.exe]> <debugfile.exe>
<IFEO[9.exe]> <debugfile.exe>
<IFEO[aa.exe]> <debugfile.exe>
<IFEO[cmdbcs.exe]> <debugfile.exe>
<IFEO[comrepl32.exe]> <debugfile.exe>
<IFEO[dbghlp32.exe]> <debugfile.exe>
<IFEO[FuckJacks.exe]> <egomoo.exe>
<IFEO[hh.exe]> <debugfile.exe>
<IFEO[igm.exe]> <debugfile.exe>
<IFEO[igw.exe]> <debugfile.exe>
<IFEO[Logo1_.exe]> <debugfile.exe>
<IFEO[logo_1.exe]> <debugfile.exe>
<IFEO[NVDispDrv.exe]> <debugfile.exe>
<IFEO[OSO.exe]> <egomoo.exe>
<IFEO[racvsvc.exe]> <debugfile.exe>
<IFEO[rundl132.exe]> <debugfile.exe>
<IFEO[rundl133.exe]> <debugfile.exe>
<IFEO[sach0st.exe]> <debugfile.exe>
<IFEO[sedrsvedt.exe]> <debugfile.exe>
<IFEO[spoclsv.exe]> <debugfile.exe>
<IFEO[SVCH0ST.exe]> <debugfile.exe>
<IFEO[svcos.exe]> <debugfile.exe>
<IFEO[svohost.exe]> <debugfile.exe>
<IFEO[swghost.exe]> <debugfile.exe>
<IFEO[sxs.exe]> <debugfile.exe>
<IFEO[upxdnd.exe]> <debugfile.exe>
删除服务:
[WebPrint / WebPrint] <c:\windows\system32\webprint.exe>
[Terminal Services / TermService] <C:\WINDOWS\System32\svchost -k DComLaunch-->C:\WINDOWS\System32\termsrvgmm.dll>
[pihnre / pihnre] <C:\WINDOWS\system32\svchost.exe -k pihnre-->%SystemRoot%\System32\pihnre.dll>
[Provisioning Transaction Service / pangupan] <C:\WINDOWS\system32\aa.exe>
[Network Connections Manage / Network Connections Manage ] <C:\WINDOWS\lsuss.exe>
[操作系统内部进程 / netservice] <C:\Documents and Settings\All Users\Favorites\netservice.exe>
[Event System / Event System] <C:\Program Files\Common Files\Microsoft Shared\MSInfo\Server.exe>
[cpfzxu / cpfzxu] <C:\WINDOWS\system32\svchost.exe -k cpfzxu-->%SystemRoot%\System32\cpfzxu.dll>
删除驱动:
[079mzx / 079mzxg] <\SystemRoot\System32\DRIVERS\079mzxg.sys>
[3pwp / 3pwp] <\??\C:\WINDOWS\system32\drivers\3pwp.sys>
[ypfzxuiu / ypfzxuiu] <\??\C:\WINDOWS\system32\drivers\cpfzxu.sys>
[ymuylfiu / ymuylfiu] <\??\C:\WINDOWS\system32\drivers\amuylf.sys>
[ygkzknyx / ygkzknyx] <\??\C:\WINDOWS\system32\drivers\rgkzkn.sys>
[xProc / xProc] <\??\C:\WINDOWS\system32\Drivers\xProc.sys>
[xBlock3 / xBlock3] <\??\C:\WINDOWS\system32\Drivers\xBlock3.sys>
[mxdispdr / mxdispdr] <\??\C:\WINDOWS\system32\drivers\mxdispdr.sys>
删除加载项:
[AlxTB BHO Class] <C:\WINDOWS\system32\AlxTB1.dll>
[AxSubmitControl Class] <C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL>
[AxInputControl Class] <C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL>
[CAdLogic
Object] <C:\Program Files\Common Files\CPUSH\cpush.dll>
[InfosecCertInstall Class] <C:\WINDOWS\Downloaded Program Files\certInStall.dll>
[EditCtrl Class] <C:\WINDOWS\system32\aliedit\AliEdit.dll>
[Info cache] <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll>