改注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE,pppppp.exe,zzzzz.exe,xxxxx.exe,qqqqqq.exe> [(Verified)Microsoft Windows Component Publisher][HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
改为
<shell><EXPLORER.EXE> [(Verified)Microsoft Windows Component Publisher]
在计算机里搜索pppppp.exe,zzzzz.exe,xxxxx.exe,qqqqqq.exe
删除
删除启动项的
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]下的
以下注册表项目及<>内文件 <{00070007-0007-0007-0007-00070007BB15}><C:\WINDOWS\system32\dpvvoxmh.dll> []
<{00150015-0015-0015-0015-00150015BB15}><C:\WINDOWS\system32\cqpraytv.dll> []
<{00170017-0017-0017-0017-00170017BB15}><C:\WINDOWS\system32\msobjstl.dll> []
<{00010001-0001-0001-0001-00010001BB15}><C:\WINDOWS\system32\adsntzt.dll> []
<{00180018-0018-0018-0018-00180018BB15}><C:\WINDOWS\system32\mstimewd.dll> []
<{00140014-0014-0014-0014-00140014BB15}><C:\WINDOWS\system32\kbdgrms.dll> []
<{00270027-0027-0027-0027-00270027BB15}><C:\WINDOWS\system32\wmpuiqhx.dll> []
<{00230023-0023-0023-0023-00230023BB15}><C:\WINDOWS\system32\rasdlgcq.dll> []
<{00240024-0024-0024-0024-00240024BB15}><C:\WINDOWS\system32\scrruncqsj.dll> []
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgdewg.dll> [File is missing]
<{4D698451-2015-6358-9871-2015987452D4}><C:\WINDOWS\system32\apzhdtde.dll> []
<{00030003-0003-0003-0003-00030003BB15}><C:\WINDOWS\system32\bootvidgj.dll> []
<{00060006-0006-0006-0006-00060006BB15}><C:\WINDOWS\system32\dispexcb.dll> []
<{8C954872-1230-6541-9548-6541025884C8}><C:\WINDOWS\system32\fd233ds4f4.dll> []
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> [File is missing]
<{00120012-0012-0012-0012-00120012BB15}><C:\WINDOWS\system32\kbdswjr.dll> []
<{47A924AF-1A5F-CF21-AB1D-1D5CF82A8A74}><C:\WINDOWS\system32\zywldime.dll> [File is missing]
<{00050005-0005-0005-0005-00050005BB15}><C:\WINDOWS\system32\cliconfgzx.dll> []
<{52023698-6984-8541-9654-698745012525}><C:\WINDOWS\system32\skqnebib.dll> []
<{00130013-0013-0013-0013-00130013BB15}><C:\WINDOWS\system32\ksuserfy.dll> []
<{64FAE856-AD58-20CB-A025-CD4895FA6E46}><C:\WINDOWS\system32\pjjxfdwd.dll> [File is missing]
<{00250025-0025-0025-0025-00250025BB15}><C:\WINDOWS\system32\slbiopfs2.dll> []
<{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6}><C:\WINDOWS\system32\fsrgeb.dll> [File is missing]
<{57AC9076-C898-B098-D098-A18319080975}><C:\WINDOWS\system32\nhmxejkl.dll> []
<{40618412-C528-C784-C056-C164D1F7C504}><C:\WINDOWS\system32\detxdiua.dll> []
<{00040004-0004-0004-0004-00040004BB15}><C:\WINDOWS\system32\catsrvwl.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
下的分支及<>内文件
<dpvvoxmh.dll><C:\WINDOWS\system32\dpvvoxmh.dll> []
<wjrjovit.dll><C:\WINDOWS\system32\cqpraytv.dll> []
<msobjstl.dll><C:\WINDOWS\system32\msobjstl.dll> []
<adsntzt.dll><C:\WINDOWS\system32\adsntzt.dll> []
<mstimewd><C:\WINDOWS\system32\mstimewd.dll> []
<kbdgrms.dll><C:\WINDOWS\system32\kbdgrms.dll> []
<wmpuiqhx.dll><C:\WINDOWS\system32\wmpuiqhx.dll> []
<rasdlgcq.dll><C:\WINDOWS\system32\rasdlgcq.dll> []
<scrruncqsj.dll><C:\WINDOWS\system32\scrruncqsj.dll> []
<bootvidgj.dll><C:\WINDOWS\system32\bootvidgj.dll> []
<dispexcb.dll><C:\WINDOWS\system32\dispexcb.dll> []
<kbdswjr.dll><C:\WINDOWS\system32\kbdswjr.dll> []
<cliconfgzx.dll><C:\WINDOWS\system32\cliconfgzx.dll> []
<ksuserfy.dll><C:\WINDOWS\system32\ksuserfy.dll> []
<slbiopfs2.dll><C:\WINDOWS\system32\slbiopfs2.dll> []
<ghgrfsos.dll><C:\WINDOWS\system32\cqpraytv.dll> []
<fcvpnfte.dll><C:\WINDOWS\system32\cqpraytv.dll> []
<catsrvwl.dll><C:\WINDOWS\system32\catsrvwl.dll> []
<rkzswrkk.dll><C:\WINDOWS\system32\cqpraytv.dll> []
<btxnopii.dll><C:\WINDOWS\system32\cqpraytv.dll> []
<lcpsvlut.dll><C:\WINDOWS\system32\cqpraytv.dll> []
<pbbiestd.dll><C:\WINDOWS\system32\cqpraytv.dll> []
<clfucwzm.dll><C:\WINDOWS\system32\cqpraytv.dll> []
<sgevqdkh.dll><C:\WINDOWS\system32\cqpraytv.dll> []
<hyyioufh.dll><C:\WINDOWS\system32\cqpraytv.dll> []
<cqpraytv.dll><C:\WINDOWS\system32\cqpraytv.dll> []
<qtawgvsh.dll><C:\WINDOWS\system32\cqpraytv.dll> []
删除驱动
[wqkdy / wqkdy][Stopped/Manual Start]
<\??\C:\DOCUME~1\a\LOCALS~1\Temp\_tmp.bat><N/A>
[xxxxxx / xxxxxx][Stopped/Manual Start]
<2 - 系统找不到指定的文件。
><N/A>
[xxxxxxx / xxxxxxx][Stopped/]
<2 - 系统找不到指定的文件。
><N/A>
[aaaaaa / aaaaaa][Running/]
<2 - 系统找不到指定的文件。
><N/A>
[zzzzzzz / zzzzzzz][Stopped/]
<2 - 系统找不到指定的文件。
><N/A>
[ppppppp / ppppppp][Stopped/]
<2 - 系统找不到指定的文件。
><N/A>
[ccccccc / ccccccc][Stopped/]
<2 - 系统找不到指定的文件。
><N/A>
[aaaaaaa / aaaaaaa][Stopped/]
<2 - 系统找不到指定的文件。
><N/A>
[zzzqqqq / zzzqqqq][Stopped/]
<2 - 系统找不到指定的文件。
><N/A>
用附件去映像劫持最后卡卡上网助手,Windos清理助手清理系统