用xdelbox重启后删除
D:\QQDownload\QQDownload.exe
c:\windows\system32\HBInject.exe
c:\windows\system32\kncer32.exe
c:\windows\system32\kcodu32.exe
c:\windows\system32\HBmhly.dll
C:\Program Files\Common Files\Microsoft Shared\MSInfo\Come_System.sys
C:\WINDOWS\system32\dpvvoxmh.dll
C:\WINDOWS\system32\ddserh.dll
C:\WINDOWS\system32\jfrwdh.dll
C:\WINDOWS\system32\bootvidgj.dll
C:\WINDOWS\system32\dispexcb.dll
C:\WINDOWS\system32\wrqszl.dll
C:\WINDOWS\system32\wklsdd.dll
C:\WINDOWS\system32\hufabhsz.dll
C:\WINDOWS\system32\tdffdl.dll
C:\WINDOWS\system32\jfdses.dll
C:\WINDOWS\system32\dntggf.dll
C:\WINDOWS\system32\rfdswc.dll
C:\WINDOWS\system32\sgdewg.dll
C:\WINDOWS\system32\hhrdxd.dll
C:\WINDOWS\system32\adsntzt.dll
C:\WINDOWS\system32\tdfhex.dll
C:\WINDOWS\system32\zycdex.dll
C:\WINDOWS\system32\jhfrxz.dll
C:\WINDOWS\system32\cliconfgzx.dll
C:\WINDOWS\system32\wzcfsw.dll
C:\WINDOWS\system32\jdsaex.dll
C:\WINDOWS\system32\kbdswjr.dll
C:\WINDOWS\system32\catsrvwl.dll
C:\WINDOWS\system32\dpvvoxmh.dll
C:\WINDOWS\system32\cliconfgzx.dll
C:\WINDOWS\system32\mttwfh.dll
C:\WINDOWS\Fonts\mnmhisrv.dll
C:\WINDOWS\system32\wyhesm.dll
C:\WINDOWS\Fonts\zywmjime.dl
C:\WINDOWS\Fonts\lopdfeab.dll
C:\Program Files\Internet Explorer\PLUGINS\CDown.sys
C:\WINDOWS\system32\nhmxfjkl.dll
C:\WINDOWS\Fonts\apsghjba.dll
C:\WINDOWS\system32\zxmshwin.dll
C:\WINDOWS\Fonts\zptlesys.dll
C:\Program Files\Internet Explorer\PLUGINS\WinNt64.Sys
C:\WINDOWS\Fonts\ijdycpaw.dll
C:\WINDOWS\Fonts\mndhhdwd.dll
C:\WINDOWS\system32\dpvvoxmh.dll
C:\WINDOWS\system32\bootvidgj.dll
C:\WINDOWS\system32\dispexcb.dll
C:\WINDOWS\system32\hufabhsz.dll
C:\WINDOWS\system32\adsntzt.dll
C:\WINDOWS\system32\cliconfgzx.dll
C:\WINDOWS\system32\kbdswjr.dll
C:\WINDOWS\system32\catsrvwl.dll
C:\WINDOWS\system32\Drivers\0012ea29.sys
C:\002287A9\002287B1
c:\windows\system32\DRIVERS\HBKernel.sys
c:\windows\System32\Drivers\msiffei.sys
C:\000520DD\000520E5
在[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
中删除 <QQDownload><"D:\QQDownload\QQDownload.exe" autostart>
在[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
中删除<HBService><HBInject.exe>
在[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
中删除
<kcier32><kncer32.exe> []
<kcien32><kncer32.exe> []
<kcodu><kcodu32.exe> []
在[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
中删除
<AppInit_DLLs><HBmhly.dll>
在[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
中删除
<{5B77087D-AB76-4C22-B0A6-C34D1F438E55}><C:\Program Files\Common Files\Microsoft Shared\MSInfo\Come_System.sys> []
<{2876D76C-CAAA-4313-AF97-8D1D9A2A1087}><C:\WINDOWS\system32\dpvvoxmh.dll> [File is missing]
<{A9895933-6636-4281-BC58-EE6DE2AF96E3}><C:\WINDOWS\system32\ddserh.dll> [File is missing]
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> [File is missing]
<{D3112B69-A745-4805-874E-ABD480EA1299}><C:\WINDOWS\system32\bootvidgj.dll> [File is missing]
<{76D44356-B494-443a-BEDC-AA68DE4255E6}><C:\WINDOWS\system32\dispexcb.dll> [File is missing]
<{F99DEFDD-200B-4410-B572-E90883D527D2}><C:\WINDOWS\system32\wrqszl.dll> [File is missing]
<{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}><C:\WINDOWS\system32\wklsdd.dll> [File is missing]
<{21BE5FDF-D4CB-4850-AD99-21E68B50BF3F}><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<{C0595A7E-2E2F-4B34-A83A-019270A0A464}><C:\WINDOWS\system32\tdffdl.dll> [File is missing]
<{81AF1CF6-D1C9-4C6A-AC01-EDE54E71945B}><C:\WINDOWS\system32\jfdses.dll> [File is missing]
<{259BF3CF-194D-4FE6-9ADB-DE6544B098B6}><C:\WINDOWS\system32\dntggf.dll> [File is missing]
<{461D2AB4-29A5-45C2-9134-D52272D3DE38}><C:\WINDOWS\system32\rfdswc.dll> [File is missing]
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgdewg.dll> [File is missing]
<{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}><C:\WINDOWS\system32\hhrdxd.dll> [File is missing]
<{E0F3526A-4165-4589-80CD-50B6FBAC3BDA}><C:\WINDOWS\system32\adsntzt.dll> [File is missing]
<{0B846B26-BFE6-4E8E-A948-1DB17B77B483}><C:\WINDOWS\system32\tdfhex.dll> [File is missing]
<{45AADFAA-DD36-42AB-83AD-0521BBF58C24}><C:\WINDOWS\system32\zycdex.dll> [File is missing]
<{7914E0AA-ECCB-4311-B584-C49538227824}><C:\WINDOWS\system32\jhfrxz.dll> [File is missing]
<{7A6DF30E-D0F2-446f-B4F0-BF4232D60E07}><C:\WINDOWS\system32\cliconfgzx.dll> [File is missing]
<{28766E1C-74B0-4417-8C75-F12AE309EF35}><C:\WINDOWS\system32\wzcfsw.dll> [File is missing]
<{B29583D8-033A-4B9F-8553-7C5458F3FB8E}><C:\WINDOWS\system32\jdsaex.dll> [File is missing]
<{432BDC7C-DE5B-43f4-AA81-E7F8AFB0182D}><C:\WINDOWS\system32\kbdswjr.dll> [File is missing]
<{AF976DCD-754F-4ac2-BE49-951DC7AA57D2}><C:\WINDOWS\system32\catsrvwl.dll> [File is missing]
<{00070007-0007-0007-0007-00070007BB15}><C:\WINDOWS\system32\dpvvoxmh.dll> [File is missing]
<{00050005-0005-0005-0005-00050005BB15}><C:\WINDOWS\system32\cliconfgzx.dll> [File is missing]
<{021F087F-4378-545F-74FA-37D345AD7A8C}><C:\WINDOWS\system32\mttwfh.dll> [File is missing]
<{9C8D1401-A58D-A81C-CD24-A5915C4517C9}><C:\WINDOWS\Fonts\mnmhisrv.dll> [File is missing]
<{EB71E0B3-E97D-4D30-8733-E28266467617}><C:\WINDOWS\system32\wyhesm.dll> [File is missing]
<{A319A1F1-9410-9654-3201-345FFA34913A}><C:\WINDOWS\Fonts\zywmjime.dll> [File is missing]
<{C629FF4F-ACDB-5C90-A098-FACB3456A26C}><C:\WINDOWS\Fonts\lopdfeab.dll> [File is missing]
<{5D06580A-08EB-4DD0-8425-DDBB5198B30C}><C:\Program Files\Internet Explorer\PLUGINS\CDown.sys> [File is missing]
<{67AC9076-C898-B098-D098-A18319080976}><C:\WINDOWS\system32\nhmxfjkl.dll> [File is missing]
<{9FD45A54-9875-698F-E56E-65102358FDF9}><C:\WINDOWS\Fonts\apsghjba.dll> [File is missing]
<{AA041F13-A111-12A3-B0CF-F99818AA68AA}><C:\WINDOWS\system32\zxmshwin.dll> [File is missing]
<{70940F85-F015-14F1-A05F-F69858AC6D07}><C:\WINDOWS\Fonts\zptlesys.dll> [File is missing]
<{86899D14-95D7-4E22-8AB3-7ACC53076FC9}><C:\Program Files\Internet Explorer\PLUGINS\WinNt64.Sys> [File is missing]
<{3A698452-C5D8-C584-C256-C264C987C5A3}><C:\WINDOWS\Fonts\ijdycpaw.dll> [File is missing]
<{8C648541-1025-9650-9057-6541258720C8}><C:\WINDOWS\Fonts\mndhhdwd.dll> [File is missing]
<{48691221-F05C-4AB4-B9D0-50D6D36CC27F}><C:\Program Files\Internet Explorer\PLUGINS\WinNt64.Sys> [File is missing]
在[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]中删除
<dpvvoxmh.dll><C:\WINDOWS\system32\dpvvoxmh.dll> [File is missing]
<bootvidgj.dll><C:\WINDOWS\system32\bootvidgj.dll> [File is missing]
<dispexcb.dll><C:\WINDOWS\system32\dispexcb.dll> [File is missing]
<ncsktxet.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<adsntzt.dll><C:\WINDOWS\system32\adsntzt.dll> [File is missing]
<cliconfgzx.dll><C:\WINDOWS\system32\cliconfgzx.dll> [File is missing]
<mfkahadj.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<ifrmcbah.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<kbdswjr.dll><C:\WINDOWS\system32\kbdswjr.dll> [File is missing]
<zbdfyqlg.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<jiqhuoqx.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<catsrvwl.dll><C:\WINDOWS\system32\catsrvwl.dll> [File is missing]
<xhwhnrzg.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<vhmrhuqz.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<wbvnzpyk.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<uzcpieyi.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<nldvalgj.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<zckilxmb.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<jjduqhth.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<wcizqfnc.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<xjdyrhtq.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<uimtylss.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<ihhwenfg.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<hwvhduhy.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<qfgnrvfk.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<mriuewpy.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<konkgncg.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<fjkylzvy.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<oilgdtsl.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<mtsghagy.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<yttjtkcr.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<pgxggijc.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
<hufabhsz.dll><C:\WINDOWS\system32\hufabhsz.dll> [File is missing]
用SReng删除服务,驱动中
[0012ea29 / 0012ea29][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\0012ea29.sys><N/A>
[xxxALLGUARD / xxxALLGUARD][Stopped/Manual Start]
<\??\C:\002287A9\002287B1><N/A>
[HBKernel Driver / HBKernel][Stopped/Boot Start]
<\SystemRoot\system32\DRIVERS\HBKernel.sys><N/A>
[msiffei / msiffei][Stopped/Manual Start]
<System32\Drivers\msiffei.sys><N/A>
[SZNB / SZNB][Stopped/Manual Start]
<\??\C:\000520DD\000520E5><N/A>
用SReng修复.txt,.chm.ini关联文件