用xdelbox删除以下文件
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,勾选抑制再生
导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。
运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
C:\WINDOWS\winadr.exe
C:\WINDOWS\sourro.exe
C:\WINDOWS\WinRaR.exe
C:\WINDOWS\system32\1EXPL0RE.EXE
C:\WINDOWS\System32\DRIVERS\ftsata2.sys
C:\WINDOWS\system32\drivers\cnprov.sys
C:\WINDOWSSystem32\drivers\oblhqfj.sys
C:\Autorun.inf
D:\Autorun.inf
E:\Autorun.inf
F:\Autorun.inf
sreng->启动项目->注册表,删除
<w><%SystemRoot%\WinRaR.exe> [N/A]
<mm><%SystemRoot%\sourro.exe> [N/A]
<zx><%SystemRoot%\winadr.exe> [N/A]
<stup.exe><; > [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.EXE]
<IFEO[360rpt.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.EXE]
<IFEO[360safe.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.EXE]
<IFEO[360tray.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ANTIARP.EXE]
<IFEO[ANTIARP.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ast.EXE]
<IFEO[Ast.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AutoRunKiller.EXE]
<IFEO[AutoRunKiller.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.EXE]
<IFEO[AvMonitor.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVP.EXE]
<IFEO[AVP.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Frameworkservice.EXE]
<IFEO[Frameworkservice.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GFUpd.EXE]
<IFEO[GFUpd.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GuardField.EXE]
<IFEO[GuardField.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword.EXE]
<IFEO[IceSword.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.EXE]
<IFEO[Iparmor.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASARP.EXE]
<IFEO[KASARP.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRegEx.EXE]
<IFEO[KRegEx.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonxp.kxp]
<IFEO[KVMonxp.kxp]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVSrvXP.EXE]
<IFEO[KVSrvXP.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVWSC.EXE]
<IFEO[KVWSC.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Mmsk.EXE]
<IFEO[Mmsk.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapsvc.EXE]
<IFEO[Navapsvc.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nod32kui.EXE]
<IFEO[Nod32kui.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDOCTOR.EXE]
<IFEO[QQDOCTOR.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VPC32.EXE]
<IFEO[VPC32.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VPTRAY.EXE]
<IFEO[VPTRAY.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WOPTILITIES.EXE]
<IFEO[WOPTILITIES.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Wuauclt.EXE]
<IFEO[Wuauclt.EXE]><C:\WINDOWS\system32\1EXPL0RE.EXE> []
并将<AppInit_DLLs><rsjzapm.dll,ieprot.dll> ,修改为<AppInit_DLLs><ieprot.dll>
sreng->启动项目-〉服务-〉驱动程序,删除
[cnprov / cnprov][Stopped/Boot Start]
<\SystemRoot\system32\drivers\cnprov.sys><N/A>
[FTSATA2 / FTSATA2][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\ftsata2.sys><N/A>
[oblhqfj / oblhqfj][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\oblhqfj.sys><N/A>