启动项目
注册表--删除
<mqicujox><C:\WINDOWS\qcjxmvhw.exe> []
<WSockDrv32><C:\WINDOWS\WSockDrv32.exe> []
<DbgHlp32><C:\WINDOWS\DbgHlp32.exe> []
<tciocp32><C:\WINDOWS\tciocp32.exe> []
<LotusHlp><C:\WINDOWS\LotusHlp.exe> []
<PTSShell><C:\WINDOWS\PTSShell.exe> []
<SHAProc><C:\WINDOWS\SHAProc.exe> []
<WINSvr32><C:\WINDOWS\WINSvr32.exE> []
<Kvsc3><C:\WINDOWS\Kvsc3.exE> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<DXDLG32><DXDLG.exe> []
<MSDWG32><LYLoadbr.exe> [N/A]
<MSDCG32 ><LYLeador.exe> [N/A]
<MSDOG32><LYLoador.exe> [N/A]
<MSDSG32><LYLoadar.exe> [N/A]
<MSDMG32><LYLoadmr.exe> [N/A]
<MSDHG32><LYLoadhr.exe> [N/A]
<MSDQG32><LYLoadqr.exe> [N/A]
<{7FA4A83B-F99A-4bfc-A8E2-6A62B05D2C82}><C:\DOCUME~1\nbzjq\LOCALS~1\Temp\datB4.tmp> []
<{D29DCEE0-457B-45A2-A92D-741B95B7723B}><C:\Program Files\Internet Explorer\PLUGINS\Ns_Sys55.Sys> []
<{5E907A48-400E-4EA8-9792-FFAE052D59E9}><C:\WINDOWS\system32\pedadt.dll> []
<{C5E87A05-F463-4841-B19E-DD3EC3862368}><C:\Program Files\Internet Explorer\IEXPLORE32.Sys> [N/A]
编辑 <AppInit_DLLs><<AppInit_DLLs><>,msosdrop00.dll,msosdohs00.dll,msosfmsq02.dll,msosmhfp00.dll>
为 <AppInit_DLLs><>
==================================
SRE--启动项目--服务--驱动程序--删除
[dohs / dohs][Stopped/Auto Start]
<\??\C:\DOCUME~1\nbzjq\LOCALS~1\Temp\tmp13.tmp><N/A>
[drop / drop][Stopped/Auto Start]
<\??\C:\DOCUME~1\nbzjq\LOCALS~1\Temp\tmpAC.tmp><N/A>
[fmsq / fmsq][Stopped/Auto Start]
<\??\C:\DOCUME~1\nbzjq\LOCALS~1\Temp\tmp66.tmp><N/A>
[mnsf / mnsf][Stopped/Auto Start]
<\??\C:\DOCUME~1\nbzjq\LOCALS~1\Temp\tmpAE.tmp><N/A>
[fpids32 / fpids32][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosfpids32.sys><N/A>
==================================
SRE--系统修复--浏览器加载项--删除
[]
{C5E87A05-F463-4841-B19E-DD3EC3862368} <C:\Program Files\Internet Explorer\IEXPLORE32.Sys, N/A>
[]
{D29DCEE0-457B-45A2-A92D-741B95B7723B} <C:\Program Files\Internet Explorer\PLUGINS\Ns_Sys55.Sys, N/A>
[]
{C5E87A05-F463-4841-B19E-DD3EC3862368} <C:\Program Files\Internet Explorer\IEXPLORE32.Sys, N/A>
[]
{D29DCEE0-457B-45A2-A92D-741B95B7723B} <C:\Program Files\Internet Explorer\PLUGINS\Ns_Sys55.Sys, N/A>
==================================
删除
C:\WINDOWS\ctfmon.exe
C:\DOCUME~1\nbzjq\LOCALS~1\Temp\datB4.tmp
C:\Program Files\Internet Explorer\PLUGINS\Ns_Sys55.Sys
C:\WINDOWS\system32\pedadt.dll
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\system32\ltxqud.dll
C:\WINDOWS\system32\khvgbw.dll
C:\WINDOWS\system32\vmfcub.dll
C:\WINDOWS\system32\nwjorv.dll
C:\WINDOWS\system32\ifbqwn.dll
C:\WINDOWS\system32\wuvogd.dll
C:\WINDOWS\system32\jsqpmx.dll
C:\WINDOWS\system32\lsrajv.dll
C:\WINDOWS\system32\zcdnub.dll
C:\WINDOWS\system32\tecmet.dll
C:\WINDOWS\system32\ipahzi.dll
C:\Program Files\Internet Explorer\IEXPLORE32.Sys
C:\WINDOWS\SYSTEM32\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\msosdrop00.dll
C:\WINDOWS\SYSTEM32\msosdohs00.dll
C:\WINDOWS\SYSTEM32\msosfmsq02.dll
C:\WINDOWS\SYSTEM32\msosmhfp00.dll
C:\DOCUME~1\nbzjq\LOCALS~1\Temp\tmp13.tmp
C:\DOCUME~1\nbzjq\LOCALS~1\Temp\tmpAC.tmp
C:\DOCUME~1\nbzjq\LOCALS~1\Temp\tmp66.tmp
C:\DOCUME~1\nbzjq\LOCALS~1\Temp\tmpAE.tmp
C:\WINDOWS\system32\drivers\msosfpids32.sys
C:\WINDOWS\qcjxmvhw.exe
C:\WINDOWS\WSockDrv32.exe
C:\WINDOWS\DbgHlp32.exe
C:\WINDOWS\tciocp32.exe
C:\WINDOWS\LotusHlp.exe
C:\WINDOWS\PTSShell.exe
C:\WINDOWS\SHAProc.exe
C:\WINDOWS\WINSvr32.exE
C:\WINDOWS\Kvsc3.exE
C:\WINDOWS\msccrt.exe
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\system32\DXDLG.exe
C:\WINDOWS\system32\LYLoadbr.exe
C:\WINDOWS\system32\LYLeador.exe
C:\WINDOWS\system32\LYLoador.exe
C:\WINDOWS\system32\LYLoadar.exe
C:\WINDOWS\system32\LYLoadmr.exe
C:\WINDOWS\system32\LYLoadhr.exe
C:\WINDOWS\system32\LYLoadqr.exe
C:\DOCUME~1\nbzjq\LOCALS~1\Temp\datB4.tmp