第二个日志解决方案:
用xdelbox重启后删除
c:\windows\system32\kncer32.exe
C:\WINDOWS\system32\zofaianu.dll
C:\WINDOWS\system32\cliconfgzx.dll
C:\WINDOWS\system32\adsntzt.dll
C:\WINDOWS\system32\bootvidgj.dll
C:\WINDOWS\system32\certmgrkd.dll
C:\WINDOWS\system32\avicapwm.dll
C:\WINDOWS\system32\imgutilhx2.dll
C:\WINDOWS\system32\dpvvoxmh.dll
C:\WINDOWS\system32\lweurqhx.dll
C:\WINDOWS\system32\tscfgwmijxsj.dll
C:\WINDOWS\system32\imgutilhx2.dll
C:\WINDOWS\system32\xolehlpjh.dll
C:\WINDOWS\system32\dispexcb.dll
C:\WINDOWS\system32\cliconfgzx.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1.tmp
c:\windows\System32\Drivers\msiffei.sys
c:\windows\system32\drivers\NPF.sys
C:\WINDOWS\system32\gdipro.dll
C:\WINDOWS\system32\sys07003.dll
C:\WINDOWS\system32\mfc40loc.dll
c:\windows\system32\srpcss.dll
修复注册表:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<kcien32><kncer32.exe> []
将kcien32键值删除
从[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]中删除键值
<{21BE5FDF-D4CB-4850-AD99-21E68B50BF3F}><C:\WINDOWS\system32\zofaianu.dll> []
<{00050005-0005-0005-0005-00050005BB15}><C:\WINDOWS\system32\cliconfgzx.dll> [File is
missing]
<{E0F3526A-4165-4589-80CD-50B6FBAC3BDA}><C:\WINDOWS\system32\adsntzt.dll> [File is
missing]
<{D3112B69-A745-4805-874E-ABD480EA1299}><C:\WINDOWS\system32\bootvidgj.dll> [File is
missing]
<{9E8287B0-0F3A-48ae-99C5-A6E0AAC36BC5}><C:\WINDOWS\system32\certmgrkd.dll> []
<{6B9FEAD7-4319-4312-AB05-D8C9CD255BFE}><C:\WINDOWS\system32\avicapwm.dll> []
<{00300030-0030-0030-0030-00300030BB15}><C:\WINDOWS\system32\imgutilhx2.dll> [File is
missing]
<{2876D76C-CAAA-4313-AF97-8D1D9A2A1087}><C:\WINDOWS\system32\dpvvoxmh.dll> [File is
missing]
<{71A78CD4-E470-4a18-8457-E0E0283DD507}><C:\WINDOWS\system32\lweurqhx.dll> [File is
missing]
<{2CB77746-8ECC-40ca-8217-10CA8BE5EFC8}><C:\WINDOWS\system32\tscfgwmijxsj.dll> [File is
missing]
<{DA56B183-A731-402b-9235-2CB8803E212D}><C:\WINDOWS\system32\imgutilhx2.dll> [File is
missing]
<{F0930A2F-D971-4828-8209-B7DFD266ED44}><C:\WINDOWS\system32\xolehlpjh.dll> [File is
missing]
<{76D44356-B494-443a-BEDC-AA68DE4255E6}><C:\WINDOWS\system32\dispexcb.dll> [File is
missing]
<{7A6DF30E-D0F2-446f-B4F0-BF4232D60E07}><C:\WINDOWS\system32\cliconfgzx.dll> [File is
missing]
从[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]中删除键值
<pygvdsxs.dll><C:\WINDOWS\system32\zofaianu.dll> []
<cliconfgzx.dll><C:\WINDOWS\system32\cliconfgzx.dll> [File is missing]
<adsntzt.dll><C:\WINDOWS\system32\adsntzt.dll> [File is missing]
<bootvidgj.dll><C:\WINDOWS\system32\bootvidgj.dll> [File is missing]
<certmgrkd.dll><C:\WINDOWS\system32\certmgrkd.dll> []
<avicapwm.dll><C:\WINDOWS\system32\avicapwm.dll> []
<imgutilhx2.dll><C:\WINDOWS\system32\imgutilhx2.dll> [File is missing]
<jpkerkxk.dll><C:\WINDOWS\system32\zofaianu.dll> []
<qvrxpduj.dll><C:\WINDOWS\system32\zofaianu.dll> []
<hcihisoj.dll><C:\WINDOWS\system32\zofaianu.dll> []
<bpidufhz.dll><C:\WINDOWS\system32\zofaianu.dll> []
<mqzuhbva.dll><C:\WINDOWS\system32\zofaianu.dll> []
<dimygspd.dll><C:\WINDOWS\system32\zofaianu.dll> []
<dpvvoxmh.dll><C:\WINDOWS\system32\dpvvoxmh.dll> [File is missing]
<lweurqhx.dll><C:\WINDOWS\system32\lweurqhx.dll> [File is missing]
<tscfgwmijxsj.dll><C:\WINDOWS\system32\tscfgwmijxsj.dll> [File is missing]
<plrhrebn.dll><C:\WINDOWS\system32\zofaianu.dll> []
<xolehlpjh.dll><C:\WINDOWS\system32\xolehlpjh.dll> [File is missing]
<dispexcb.dll><C:\WINDOWS\system32\dispexcb.dll> [File is missing]
<pvuzehed.dll><C:\WINDOWS\system32\zofaianu.dll> []
<zofaianu.dll><C:\WINDOWS\system32\zofaianu.dll> []
用Sreng把三个服务删除
[IIS Manager / IIS Manager ][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1.tmp><N/A>
[msiffei / msiffei][Stopped/Manual Start]
<System32\Drivers\msiffei.sys><N/A>
[WinPcap Packet Driver (NPF) / NPF][Running/Manual Start]
<system32\drivers\NPF.sys><CACE Technologies>
用Sreng将.txt ,.chm,.ini的文件关联修复好
用Sreng将<AppInit_DLLs><offscrl.dll squalle.dll ckicps.dll cmonos.dll lenowos.dll therbrek.dll
pciboxl.dll wdhotem.dll aliens.dll esceps.dll mssetd.dll nvidons.dll tesxdx.dll rmbsony.dll
jolinos.dll dearnts.dll joause.dll fackwir.dll,kmon.dll> [N/A]
修改,只剩下kmon.dll
<AppInit_DLLs><
kmon.dll> [N/A]