1、断开网络连接后,进入注册表编辑器,删除以下注册表值项:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{B629FF4F-ACDB-5C90-A098-FACB3456A26B}><C:\WINDOWS\system32\hdf453d.dll> [File is missing]
<{C490415F-65F8-B5C5-D8BA-9405FB12054C}><C:\WINDOWS\system32\yzztlmsn.dll> [File is missing]
<{B490415F-65F8-B5C5-D8BA-9405FB12054B}><C:\WINDOWS\system32\yzztlmsn.dll> [File is missing]
<{80AF1289-F140-A140-D012-C1458759FC08}><C:\WINDOWS\system32\ypcqghlp.dll> [File is missing]
<{37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73}><C:\WINDOWS\system32\zywlcime.dll> [File is missing]
<{87FD640A-158F-48AC-FD14-1597F14A9778}><C:\WINDOWS\system32\mndshsrv.dll> [File is missing]
<{7FD45A54-9875-698F-E56E-65102358FDF7}><C:\WINDOWS\system32\apsggjba.dll> [File is missing]
<{9C69034A-F45F-D34D-A33A-C33C4D324FC9}><C:\WINDOWS\system32\arjrgler.dll> [File is missing]
<{38093456-9012-4568-9076-908765467183}><C:\WINDOWS\system32\tisqctyu.dll> [File is missing]
<{5D098345-6785-1098-5413-678067AE03D5}><C:\WINDOWS\system32\tysqbkol.dll> [File is missing]
<{1A698452-C5D8-C584-C256-C264C987C5A1}><C:\WINDOWS\system32\ijdyapaw.dll> [File is missing]
<{39109876-7619-9101-7012-901938475193}><C:\WINDOWS\system32\ietzcpaq.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{H8I12RB03-AB-B70-7-11d2-9CBD-0O00FS7AH6-9E2121BHJLK}]
<safeint><%windir%\Tasks\killbase.vbs> []
2、运行SRENG扫描工具,系统修复--浏览器加载项,删除以下浏览器加载项:
[]
{1A698452-C5D8-C584-C256-C264C987C5A1} <C:\WINDOWS\system32\ijdyapaw.dll, N/A>
[]
{37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73} <C:\WINDOWS\system32\zywlcime.dll, N/A>
[]
{38093456-9012-4568-9076-908765467183} <C:\WINDOWS\system32\tisqctyu.dll, N/A>
[]
{39109876-7619-9101-7012-901938475193} <C:\WINDOWS\system32\ietzcpaq.dll, N/A>
[]
{5D098345-6785-1098-5413-678067AE03D5} <C:\WINDOWS\system32\tysqbkol.dll, N/A>
[]
{7FD45A54-9875-698F-E56E-65102358FDF7} <C:\WINDOWS\system32\apsggjba.dll, N/A>
[]
{80AF1289-F140-A140-D012-C1458759FC08} <C:\WINDOWS\system32\ypcqghlp.dll, N/A>
[]
{87FD640A-158F-48AC-FD14-1597F14A9778} <C:\WINDOWS\system32\mndshsrv.dll, N/A>
[]
{9C69034A-F45F-D34D-A33A-C33C4D324FC9} <C:\WINDOWS\system32\arjrgler.dll, N/A>
[]
{B490415F-65F8-B5C5-D8BA-9405FB12054B} <C:\WINDOWS\system32\yzztlmsn.dll, N/A>
[]
{B629FF4F-ACDB-5C90-A098-FACB3456A26B} <C:\WINDOWS\system32\hdf453d.dll, N/A>
[]
{C490415F-65F8-B5C5-D8BA-9405FB12054C} <C:\WINDOWS\system32\yzztlmsn.dll, N/A>
[]
{1A698452-C5D8-C584-C256-C264C987C5A1} <C:\WINDOWS\system32\ijdyapaw.dll, N/A>
[]
{37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73} <C:\WINDOWS\system32\zywlcime.dll, N/A>
[]
{38093456-9012-4568-9076-908765467183} <C:\WINDOWS\system32\tisqctyu.dll, N/A>
[]
{39109876-7619-9101-7012-901938475193} <C:\WINDOWS\system32\ietzcpaq.dll, N/A>
[]
{5D098345-6785-1098-5413-678067AE03D5} <C:\WINDOWS\system32\tysqbkol.dll, N/A>
[]
{7FD45A54-9875-698F-E56E-65102358FDF7} <C:\WINDOWS\system32\apsggjba.dll, N/A>
[]
{80AF1289-F140-A140-D012-C1458759FC08} <C:\WINDOWS\system32\ypcqghlp.dll, N/A>
[]
{87FD640A-158F-48AC-FD14-1597F14A9778} <C:\WINDOWS\system32\mndshsrv.dll, N/A>
[]
{9C69034A-F45F-D34D-A33A-C33C4D324FC9} <C:\WINDOWS\system32\arjrgler.dll, N/A>
[]
{B490415F-65F8-B5C5-D8BA-9405FB12054B} <C:\WINDOWS\system32\yzztlmsn.dll, N/A>
[]
{B629FF4F-ACDB-5C90-A098-FACB3456A26B} <C:\WINDOWS\system32\hdf453d.dll, N/A>
[]
{C490415F-65F8-B5C5-D8BA-9405FB12054C} <C:\WINDOWS\system32\yzztlmsn.dll, N/A>
3、运行SRENG扫描工具,系统修复--HOSTS文件--重置
4、重启电脑,运行WINRAR压缩工具,查找是否有个c:\windows\tasks\killbase.vbs的文件,找到后删除。