启动项目
注册表--删除
<{EB71E0B3-E97D-4D30-8733-E28266467617}><C:\WINDOWS\system32\wyhesm.dll> [N/A]
<{28EB3777-3E23-4E72-8449-A992D09D24C3}><C:\WINDOWS\system32\zgfdet.dll> [N/A]
<{45AADFAA-DD36-42AB-83AD-0521BBF58C24}><C:\WINDOWS\system32\zjydcx.dll> [N/A]
<{48074740-A5D7-4EFC-8949-971003C5BE3C}><C:\WINDOWS\system32\hmuyhx.dll> [N/A]
<{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}><C:\WINDOWS\system32\hhrdxd.dll> [N/A]
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> [N/A]
<{F99DEFDD-200B-4410-B572-E90883D527D2}><C:\WINDOWS\system32\wrqszl.dll> [N/A]
<{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}><C:\WINDOWS\system32\wyrsdj.dll> [N/A]
<{84143967-B645-4BFF-B873-DA1DC886E9A7}><C:\WINDOWS\system32\cedafb.dll> [N/A]
<{AA1A5CFB-22EA-4D08-87C1-E474E70FB37C}><C:\WINDOWS\system32\foogls.dll> [N/A]
<{B29583D8-033A-4B9F-8553-7C5458F3FB8E}><C:\WINDOWS\system32\jdsaex.dll> [N/A]
<{46BEF04C-6767-409D-BA67-D8C0257D4F13}><C:\WINDOWS\system32\wjkfam.dll> []
<{CFFEEAAF-6E11-4F06-BE21-1DC312760DA2}><C:\WINDOWS\system32\zvhrnt.dll> []
<{221B2421-AEA8-432B-B881-76D0640E1A82}><C:\WINDOWS\system32\zjmhay.dll> []
<{F2874520-C663-4257-93A5-0CC2329E1783}><C:\WINDOWS\system32\hgsvlx.dll> []
<{BE9D256D-775A-4910-BD0E-2C32986DAE73}><C:\WINDOWS\system32\hymvrd.dll> []
<{CF2007E6-EE13-4622-A4AA-85D26C325B0B}><C:\WINDOWS\system32\jwunqh.dll> []
<{BCF56E49-60F2-4CED-8F4D-34FC5BA4479F}><C:\WINDOWS\system32\wpbnwl.dll> []
<{40AF1289-F140-A140-D012-C1458759FC04}><C:\WINDOWS\system32\ypcqchlp.dll> [N/A]
<{AC76D464-E6EB-4E35-87B4-9446FE89374A}><C:\WINDOWS\system32\wmdowj.dll> []
<{78AFF3DD-5833-401A-B516-903510F13DF9}><C:\WINDOWS\system32\cvlrvb.dll> []
<{DDC089B2-69BB-4D48-805B-C22B7A25AE30}><C:\WINDOWS\system32\jsfrix.dll> []
<{40940F85-F015-14F1-A05F-F69858AC6D04}><C:\WINDOWS\system32\zptlbsys.dll> [N/A]
<{E06513F2-9E0B-48BB-93CC-C66F13665734}><C:\WINDOWS\system32\wyrmom.dll> []
<{B03C2265-C1F2-4C4A-84E8-0C991AD0D585}><C:\WINDOWS\system32\zpvyxt.dll> []
<{12E63C55-BC69-4B75-824C-684FD0F73924}><C:\WINDOWS\system32\zrcpfy.dll> []
<{4B0F2952-5FB3-4AB7-9905-7F3AE0CAD3CE}><C:\WINDOWS\system32\snrqeg.dll> []
<{A268CD51-B10D-4D86-BBED-5DA04CFF500D}><C:\WINDOWS\system32\hzwdjx.dll> []
<{D7A0AB68-A3A0-4F12-8457-9185F880756B}><C:\WINDOWS\system32\htiacd.dll> [N/A]
<{D56E11A0-BDF2-4C44-BC77-36E19ABCF33C}><C:\WINDOWS\system32\jjzkuh.dll> []
<{A5EC0D77-AC5D-4770-8462-60D8D1508736}><C:\WINDOWS\system32\wtuoal.dll> []
<{3BBCDFA5-3350-404A-AE9E-2DB357DF811C}><C:\WINDOWS\system32\cydwcb.dll> []
<{8277A9D8-17A2-4267-AFE2-225182A6E28B}><C:\WINDOWS\system32\spzgdh.dll> []
<{AC2EA2E7-4A8B-4C17-BE32-9E9D45C9BF63}><C:\WINDOWS\system32\jytcwx.dll> []
==================================
删除服务
[Drivers Desktop Management / Drivers Desktop][Stopped/Auto Start]
<C:\WINDOWS\system32\explore.exe><N/A>
==================================
删除驱动程序
[dohs / dohs][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp1.tmp><N/A>
[msfpfis64 / msfpfis64][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosmsfpfis64.sys><N/A>
[ping / ping][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp2C.tmp><N/A>
==================================
删除浏览器加载项
[]
{40940F85-F015-14F1-A05F-F69858AC6D04} <C:\WINDOWS\system32\zptlbsys.dll, N/A>
[]
{40AF1289-F140-A140-D012-C1458759FC04} <C:\WINDOWS\system32\ypcqchlp.dll, N/A>
[]
{40940F85-F015-14F1-A05F-F69858AC6D04} <C:\WINDOWS\system32\zptlbsys.dll, N/A>
[]
{40AF1289-F140-A140-D012-C1458759FC04} <C:\WINDOWS\system32\ypcqchlp.dll, N/A>
[EditCtrl Class]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\aliedit.dll, >
==================================
删除对应的文件