用附件工具XDELBOX删除以下文件
C:\WINDOWS\system32\ccwld32_080419.dll
C:\WINDOWS\system32\winini.exe
C:\WINDOWS\system32\CCWLAE~2.EXE
C:\WINDOWS\system32\DRIVERS\g77rm0.sys
C:\WINDOWS\system32\thbxfvgygb.dll
重起后
用SRENG删除启动文件夹
[msword]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\msword.lnk --> C:\WINDOWS\system32\CCWLAE~2.EXE [N/A]><N>
删除服务
[COM+ Windows System / WinINI][Running/Auto Start]
<C:\WINDOWS\system32\winini.exe><Microsoft Corporation>
删除驱动
[g77rm / g77rm0][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\g77rm0.sys><N/A>
禁止驱动
[XPROTECTOR / XPROTECTOR][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\Xprotector.sys><N/A>
删除浏览器加载
[]
{FB3412B6-6D67-4650-B3B4-C2A90191A80F} <C:\WINDOWS\system32\thbxfvgygb.dll, N/A>
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A>
[]
{FB3412B6-6D67-4650-B3B4-C2A90191A80F} <C:\WINDOWS\system32\thbxfvgygb.dll, N/A>