用巡警删除下面文件
c:\windows\system32\adsntzt.dll
c:\windows\system32\kbdgrms.dll
c:\windows\system32\dfqiewwk.dll
c:\windows\system32\lweurqhx.dll
c:\windows\system32\dispexcb.dll
c:\windows\system32\cliconfgzx.dll
c:\windows\system32\dpvvoxmh.dll
c:\windows\system32\slcyf.dll
c:\windows\system32\tdfhex.dll
c:\program files\internet explorer\iexplore32.win
c:\program files\internet explorer\iexplore32.dat
c:\program files\internet explorer\iexplore32.sys
c:\windows\system32\jhrcar.dll
c:\program files\internet explorer\plugins\winsys8k.sys
"c:\program files\rising\rav\ravtask.exe" -system
c:\docume~1\david\locals~1\temp\tmp29d.tmp
c:\docume~1\david\locals~1\temp\usbcams3.sys
c:\windows\system32\drivers\protectora.sys
c:\windows\system32\drivers\protector.sys
c:\windows\system32\drivers\edk2.sys
c:\windows\system32\drivers\d347prt.sys
c:\windows\system32\drivers\d347bus.sys
c:\docume~1\david\locals~1\temp\tmp2bb.tmp
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[adsntzt.dll] <C:\WINDOWS\system32\adsntzt.dll>
[kbdgrms.dll] <C:\WINDOWS\system32\kbdgrms.dll>
[dfqiewwk.dll] <C:\WINDOWS\system32\dfqiewwk.dll>
[lweurqhx.dll] <C:\WINDOWS\system32\lweurqhx.dll>
[dispexcb.dll] <C:\WINDOWS\system32\dispexcb.dll>
[dispexcb.dll] <C:\WINDOWS\system32\dispexcb.dll>
[cliconfgzx.dll] <C:\WINDOWS\system32\cliconfgzx.dll>
[taucioha.dll] <C:\WINDOWS\system32\dfqiewwk.dll>
[dpvvoxmh.dll] <C:\WINDOWS\system32\dpvvoxmh.dll>
[xqhdk] <C:\WINDOWS\system32\slcyf.dll>
[{E560642D-A32D-432c-9E7E-9A135CC37E0F}] <C:\WINDOWS\system32\kbdgrms.dll>
[{E0F3526A-4165-4589-80CD-50B6FBAC3BDA}] <C:\WINDOWS\system32\adsntzt.dll>
[{7A6DF30E-D0F2-446f-B4F0-BF4232D60E07}] <C:\WINDOWS\system32\cliconfgzx.dll>
[{21BE5FDF-D4CB-4850-AD99-21E68B50BF3F}] <C:\WINDOWS\system32\dfqiewwk.dll>
[{71A78CD4-E470-4a18-8457-E0E0283DD507}] <C:\WINDOWS\system32\lweurqhx.dll>
[{76D44356-B494-443a-BEDC-AA68DE4255E6}] <C:\WINDOWS\system32\dispexcb.dll>
[{0B846B26-BFE6-4E8E-A948-1DB17B77B483}] <C:\WINDOWS\system32\tdfhex.dll>
[{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}] <C:\Program Files\Internet Explorer\IEXPLORE32.win>
[{EE12D60D-AD9A-4095-B839-3BE6862679FD}] <C:\Program Files\Internet Explorer\IEXPLORE32.Dat>
[{C5E87A05-F463-4841-B19E-DD3EC3862368}] <C:\Program Files\Internet Explorer\IEXPLORE32.Sys>
[{CAED0F3B-DF8B-4DBF-BB20-8DFBC3199068}] <C:\WINDOWS\system32\jhrcar.dll>
[{6167F471-EF2B-41DD-A5E5-C26ACDB5C096}] <C:\Program Files\Internet Explorer\PLUGINS\WinSys8k.Sys>
[RavTask] <"C:\Program Files\Rising\Rav\RavTask.exe" -system>
[ShowLOMControl] <>
启动项目 -- 服务-- 驱动程序之如下项禁用:
[TL / TL] <\??\C:\DOCUME~1\david\LOCALS~1\Temp\tmp29D.tmp>
[Sc Manager / Sc Manager] <\??\C:\DOCUME~1\david\LOCALS~1\Temp\usbcams3.sys>
[ProtectorA / ProtectorA] <\??\C:\WINDOWS\system32\drivers\ProtectorA.sys>
[Protector / Protector] <system32\drivers\Protector.sys>
[edk / edk2] <\SystemRoot\System32\DRIVERS\edk2.sys>
[d347prt / d347prt] <\SystemRoot\System32\Drivers\d347prt.sys>
[d347bus / d347bus] <\SystemRoot\system32\DRIVERS\d347bus.sys>
[CQSJ / CQSJ] <\??\C:\DOCUME~1\david\LOCALS~1\Temp\tmp2BB.tmp>
系统修复-- 浏览器加载项之如下项删除:
[] <C:\Program Files\Internet Explorer\IEXPLORE32.Dat>
[] <C:\Program Files\Internet Explorer\IEXPLORE32.Sys>
[] <C:\Program Files\Internet Explorer\IEXPLORE32.Dat>
[] <C:\Program Files\Internet Explorer\IEXPLORE32.Sys>
[