建议使用XDelBox删除以下文件
复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,重启删除
c:\windows\system32\kcien32.exe
c:\windows\system32\womsoyk.exe
c:\windows\system32\nhmxdjkl.dll
c:\windows\system32\kcien32.dll
c:\windows\system32\tdggrz.dll
c:\windows\system32\tdfhex.dll
c:\windows\system32\adsntzt.dll
c:\windows\system32\apsggjba.dll
c:\windows\system32\apzhctde.dll
c:\windows\system32\bootvidgj.dll
c:\windows\system32\catsrvwl.dll
c:\windows\system32\cedafb.dll
c:\windows\system32\cliconfgzx.dll
c:\windows\system32\ddserh.dll
c:\windows\system32\hdf453d.dll
c:\windows\system32\hhrdxd.dll
c:\windows\system32\ijdybpaw.dll
c:\windows\system32\jfrwdh.dll
c:\windows\system32\kbdswjr.dll
c:\windows\system32\mfdesy.dll
c:\windows\system32\mmhadpqg1101.dll
c:\windows\system32\mndshsrv.dll
c:\windows\system32\mnmhgsrv.dll
c:\windows\system32\mpwdeapi.dll
c:\windows\system32\msobjstl.dll
c:\windows\system32\mtewdh.dll
c:\windows\system32\opshcbty.dll
c:\windows\system32\pedadt.dll
c:\windows\system32\pjjxfdwd.dll
c:\windows\system32\sgdewg.dll
c:\windows\system32\tdffdl.dll
c:\windows\system32\tscfgwmijxsj.dll
c:\windows\system32\wklsdd.dll
c:\windows\system32\ypcqghlp.dll
c:\windows\system32\yxcsdhlp.dll
c:\windows\system32\zgrjdx.dll
c:\windows\system32\zptlcsys.dll
c:\windows\system32\zxmsewin.dll
c:\program files\internet explorer\plugins\unixsys08.sys
mmhadpqg1101.dll
womsoy.dll,nhmxdjkl.dll,ieprot.dll
kcien32.exe
c:\windows\system32\ozfyebyt.dll
"f:\program files\tencent\accproxy\accproxy.exe" autostart
"c:\program files\winamp\winampa.exe"
c:\windows\system32\rijxbkin.dll
c:\windows\system32\skqnebib.dll
c:\program files\vvsn\vvsn.exe
"f:\program files\daemon tools\daemon.exe" -lang 1033
c:\windows\temp\pandrv.sys
c:\windows\system32\drivers\hdv32_c.sys
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[{47AC9076-C898-B098-D098-A18319080974}] <C:\WINDOWS\system32\nhmxdjkl.dll>
[{50940F85-F015-14F1-A05F-F69858AC6D05}] <C:\WINDOWS\system32\zptlcsys.dll>
[{32596546-2036-9451-6058-658402589723}] <C:\WINDOWS\system32\opshcbty.dll>
[{d332093c-9d73-4868-b201-9464a1d97512}] <MMHADPQG1101.dll>
[{45671234-7890-ABCD-CDEF-567801237654}] <C:\WINDOWS\system32\yxcsdhlp.dll>
[{2A698452-C5D8-C584-C256-C264C987C5A2}] <C:\WINDOWS\system32\ijdybpaw.dll>
[{0B846B26-BFE6-4E8E-A948-1DB17B77B483}] <C:\WINDOWS\system32\tdfhex.dll>
[{35671234-7890-ABCD-CDEF-567801237653}] <>
[{64FAE856-AD58-20CB-A025-CD4895FA6E46}] <C:\WINDOWS\system32\pjjxfdwd.dll>
[{7FD45A54-9875-698F-E56E-65102358FDF7}] <C:\WINDOWS\system32\apsggjba.dll>
[{87FD640A-158F-48AC-FD14-1597F14A9778}] <C:\WINDOWS\system32\mndshsrv.dll>
[{B629FF4F-ACDB-5C90-A098-FACB3456A26B}] <C:\WINDOWS\system32\hdf453d.dll>
[{8A041F13-A111-12A3-B0CF-F99818AA68A8}] <C:\WINDOWS\system32\zxmsewin.dll>
[{3D698451-2015-6358-9871-2015987452D3}] <C:\WINDOWS\system32\apzhctde.dll>
[{55694105-5108-9405-3695-954187462155}] <C:\WINDOWS\system32\mpwdeapi.dll>
[{80AF1289-F140-A140-D012-C1458759FC08}] <C:\WINDOWS\system32\ypcqghlp.dll>
[{4D165A2A-4BC1-4CA8-8299-08E05AAAB5A4}] <C:\WINDOWS\system32\tdggrz.dll>
[{7C8D1401-A58D-A81C-CD24-A5915C4517C7}] <C:\WINDOWS\system32\mnmhgsrv.dll>
注意该项[AppInit_DLLs]修改:把<womsoy.dll,nhmxdjkl.dll,ieprot.dll>修改为<>即清空
[kcien32] <kcien32.exe>
[{DC3D30AE-0380-4151-8934-EE98A34B0370}] <C:\WINDOWS\system32\mfdesy.dll>
[{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}] <C:\WINDOWS\system32\hhrdxd.dll>
[{A9895933-6636-4281-BC58-EE6DE2AF96E3}] <C:\WINDOWS\system32\ddserh.dll>
[{5A069845-2036-6084-9054-6087502480A5}] <C:\WINDOWS\system32\ozfyebyt.dll>
[AccProxy] <"F:\Program Files\Tencent\AccProxy\AccProxy.exe" autostart>
[{00010001-0001-0001-0001-00010001BB15}] <C:\WINDOWS\system32\adsntzt.dll>
[{5E907A48-400E-4EA8-9792-FFAE052D59E9}] <C:\WINDOWS\system32\pedadt.dll>
[WinampAgent] <"C:\Program Files\Winamp\Winampa.exe">
[{00030003-0003-0003-0003-00030003BB15}] <C:\WINDOWS\system32\bootvidgj.dll>
[{00050005-0005-0005-0005-00050005BB15}] <C:\WINDOWS\system32\cliconfgzx.dll>
[{84143967-B645-4BFF-B873-DA1DC886E9A7}] <C:\WINDOWS\system32\cedafb.dll>
[{25FD6584-698F-BCD2-602C-698745210352}] <C:\WINDOWS\system32\rijxbkin.dll>
[{52023698-6984-8541-9654-698745012525}] <C:\WINDOWS\system32\skqnebib.dll>
[{189F087F-4378-405F-85FA-37D955AD7A8C}] <C:\WINDOWS\system32\mtewdh.dll>
[{45AADFAA-DD36-42AB-83AD-0521BBF58C24}] <C:\WINDOWS\system32\zgrjdx.dll>
[{C0595A7E-2E2F-4B34-A83A-019270A0A464}] <C:\WINDOWS\system32\tdffdl.dll>
[{00040004-0004-0004-0004-00040004BB15}] <C:\WINDOWS\system32\catsrvwl.dll>
[VVSN] <C:\Program Files\VVSN\VVSN.exe>
[DAEMON Tools] <"F:\Program Files\DAEMON Tools\daemon.exe" -lang 1033>
[{00170017-0017-0017-0017-00170017BB15}] <C:\WINDOWS\system32\msobjstl.dll>
[{841529CB-7F77-4B99-A895-B5441E0D302F}] <C:\WINDOWS\system32\jfrwdh.dll>
[{00120012-0012-0012-0012-00120012BB15}] <C:\WINDOWS\system32\kbdswjr.dll>
[{8C41B7F7-3168-400D-A702-0E7EFE0BA304}] <C:\WINDOWS\system32\sgdewg.dll>
[{00330033-0033-0033-0033-00330033BB15}] <C:\WINDOWS\system32\tscfgwmijxsj.dll>
[{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}] <C:\WINDOWS\system32\wklsdd.dll>
[{74381DEC-D78B-43E4-BA5D-5244F669EBE4}] <C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys>
[adsntzt.dll] <C:\WINDOWS\system32\adsntzt.dll>
[bootvidgj.dll] <C:\WINDOWS\system32\bootvidgj.dll>
[cliconfgzx.dll] <C:\WINDOWS\system32\cliconfgzx.dll>
[catsrvwl.dll] <C:\WINDOWS\system32\catsrvwl.dll>
[msobjstl.dll] <C:\WINDOWS\system32\msobjstl.dll>
[kbdswjr.dll] <C:\WINDOWS\system32\kbdswjr.dll>
[tscfgwmijxsj.dll] <C:\WINDOWS\system32\tscfgwmijxsj.dll>
启动项目 -- 服务-- 驱动程序之如下项删除:
[Pandrv / Pandrv] <\??\C:\WINDOWS\TEMP\Pandrv.sys>
[Hdv32 / Hdv32] <\??\C:\WINDOWS\system32\drivers\Hdv32_c.sys>
系统修复-- 浏览器加载项之如下项删除:
[] <C:\WINDOWS\system32\mndshsrv.dll>
[] <C:\WINDOWS\system32\mnmhgsrv.dll>
[] <C:\WINDOWS\system32\mpwdeapi.dll>
[] <C:\WINDOWS\system32\skqnebib.dll>
[] <C:\WINDOWS\system32\zptlcsys.dll>
[] <C:\WINDOWS\system32\nhmxdjkl.dll>
[] <C:\WINDOWS\system32\opshcbty.dll>
[] <C:\WINDOWS\system32\rijxbkin.dll>
[] <C:\WINDOWS\system32\mndshsrv.dll>
[] <C:\WINDOWS\system32\mnmhgsrv.dll>
[] <C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys>
[] <C:\WINDOWS\system32\mpwdeapi.dll>
[] <C:\WINDOWS\system32\skqnebib.dll>
[] <C:\WINDOWS\system32\zptlcsys.dll>
[] <C:\WINDOWS\system32\nhmxdjkl.dll>
[] <C:\WINDOWS\system32\opshcbty.dll>
[] <C:\WINDOWS\system32\rijxbkin.dll>