C:\WINDOWS\system32\drivers\caxyoqr.sys
C:\WINDOWS\system32\DRIVERS\HBKernel32.sys
C:\WINDOWS\system32\drivers\qabopx.sys
C:\WINDOWS\system32\drivers\qpaypqc.sys
C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\obj\wmpobj.sys
C:\WINDOWS\system32\drivers\xbqpayz.sys
C:\WINDOWS\system32\drivers\xbyqpr.sys
C:\WINDOWS\system32\drivers\yopybzc.sys
C:\WINDOWS\system32\drivers\yorxbzp.sys
C:\WINDOWS\system32\mduaey.dll
C:\WINDOWS\system32\wrm32.dll
C:\WINDOWS\system32\wups2.dll
[C:\WINDOWS\system32\aobfkbah.dll
C:\WINDOWS\system32\rydcyusc.dll
C:\WINDOWS\system32\hiplfqgd.dll
C:\WINDOWS\system32\uxtuoqes.dll
C:\WINDOWS\system32\ypzobpok.dll
C:\WINDOWS\system32\ooxddiek.dll
C:\WINDOWS\system32\nzkzctty.dll
C:\WINDOWS\system32\sslsocket.dll
C:\WINDOWS\system32\HBCT.dll
C:\WINDOWS\system32\HBFY.dll
C:\WINDOWS\system32\cvrikqjq.dll
C:\WINDOWS\system32\mltgajhz.dll
C:\WINDOWS\system32\nsenvhqp.dll
C:\WINDOWS\system32\xwgrthdl.dll
C:\WINDOWS\system32\ktcjcajs.dll
C:\WINDOWS\system32\hqlcmxap.dll
C:\WINDOWS\system32\HBTL.dll
C:\WINDOWS\system32\HBZHUXIAN.dll
C:\WINDOWS\system32\HBQQSG.dll
C:\WINDOWS\system32\HBSO2.dll
C:\WINDOWS\system32\HB1000Y.dll
C:\WINDOWS\system32\HBKDXY.dll
C:\WINDOWS\system32\HBJXSJ.dll
C:\WINDOWS\system32\kmrqrpnd.dll
C:\WINDOWS\system32\fdgusuvz.dll
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\hccutils.DLL
C:\WINDOWS\system32\nzkzctty.dll
C:\WINDOWS\system32\ooxddiek.dll
C:\WINDOWS\system32\ypzobpok.dll
C:\WINDOWS\system32\uxtuoqes.dll
C:\WINDOWS\system32\hiplfqgd.dll
C:\WINDOWS\system32\rydcyusc.dll
C:\WINDOWS\system32\aobfkbah.dll
C:\WINDOWS\system32\igfxsrvc.dll
C:\WINDOWS\system32\igfxres.dll
C:\WINDOWS\system32\cvrikqjq.dll
C:\WINDOWS\system32\mltgajhz.dll
C:\WINDOWS\system32\nsenvhqp.dll
C:\WINDOWS\system32\xwgrthdl.dll
C:\WINDOWS\system32\ktcjcajs.dll
C:\WINDOWS\system32\hqlcmxap.dll
C:\WINDOWS\system32\HB1000Y.dll
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\System.exe
C:\WINDOWS\system32\mduaeyk.exe
C:\WINDOWS\system32\hkcmd.exe
上面文件用XDelBox一次性删除
(enao.ys168.com 下载)
复制上面所有要删除的文件,打开XDelBox,在待删除列表点 右键==>选择 剪贴版导入不检查路径==>点 右键==>选择==>立刻重启执行删除
将C:\WINDOWS\System32\dllcache\alg.exe复制到C:\WINDOWS\System32\下,替换原来的alg.exe
编辑<AppInit_DLLs>内容为空 即删除<mduaey.dll>
删除注册表项目
<HBService32><System.exe> []
<{F0930A2F-D971-4828-8209-B7DFD266ED44}><C:\WINDOWS\system32\xolehlpjh.dll> [File is missing]
<{71A78CD4-E470-4a18-8457-E0E0283DD507}><C:\WINDOWS\system32\cvrikqjq.dll> []
<{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}><C:\WINDOWS\system32\wklsdd.dll> [File is missing]
<{8C648541-1025-9650-9057-6541258720C8}><C:\WINDOWS\Fonts\mndhhdwd.dll> [File is missing]
<{76D44356-B494-443a-BEDC-AA68DE4255E6}><C:\WINDOWS\system32\mltgajhz.dll> []
<{E0F3526A-4165-4589-80CD-50B6FBAC3BDA}><C:\WINDOWS\system32\nsenvhqp.dll> []
<{2CB77746-8ECC-40ca-8217-10CA8BE5EFC8}><C:\WINDOWS\system32\xwgrthdl.dll> []
<{A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9}><C:\WINDOWS\system32\ktcjcajs.dll> []
<{898E02AB-9372-4a2c-9C4A-FFE1AF61097F}><C:\WINDOWS\system32\comuidsg.dll> [File is missing]
<{D3112B69-A745-4805-874E-ABD480EA1299}><C:\WINDOWS\system32\hqlcmxap.dll> []
<{EB9660D8-E1CD-4ff0-B4A9-00CD907F928A}><C:\WINDOWS\system32\slbiopfs2.dll> [File is missing]
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> [File is missing]
<{00240024-0024-0024-0024-00240024BB15}><C:\WINDOWS\system32\scrruncqsj.dll> [File is missing]
<{DA56B183-A731-402b-9235-2CB8803E212D}><C:\WINDOWS\system32\kmrqrpnd.dll> []
<{21BE5FDF-D4CB-4850-AD99-21E68B50BF3F}><C:\WINDOWS\system32\mbwgtqub.dll> [File is missing]
<{9FD45A54-9875-698F-E56E-65102358FDF9}><C:\WINDOWS\Fonts\apsghjba.dll> [File is missing]
<{6B9FEAD7-4319-4312-AB05-D8C9CD255BFE}><C:\WINDOWS\system32\avicapwm.dll> [File is missing]
<{BA4B5EBD-AB43-4c2b-84F5-F1AD85E79E4A}><C:\WINDOWS\system32\wtsapi32yt2.dll> [File is missing]
<{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}><C:\WINDOWS\system32\fdgusuvz.dll> []
<aobfkbah.dll><C:\WINDOWS\system32\cvrikqjq.dll> []
<rydcyusc.dll><C:\WINDOWS\system32\mltgajhz.dll> []
<hiplfqgd.dll><C:\WINDOWS\system32\nsenvhqp.dll> []
<uxtuoqes.dll><C:\WINDOWS\system32\xwgrthdl.dll> []
<ypzobpok.dll><C:\WINDOWS\system32\ktcjcajs.dll> []
<comuidsg.dll><C:\WINDOWS\system32\comuidsg.dll> [File is missing]
<ooxddiek.dll><C:\WINDOWS\system32\hqlcmxap.dll> []
<slbiopfs2.dll><C:\WINDOWS\system32\slbiopfs2.dll> [File is missing]
<scrruncqsj.dll><C:\WINDOWS\system32\scrruncqsj.dll> [File is missing]
<imgutilhx2.dll><C:\WINDOWS\system32\kmrqrpnd.dll> []
<zmdivalb.dll><C:\WINDOWS\system32\mbwgtqub.dll> [File is missing]
<mbwgtqub.dll><C:\WINDOWS\system32\mbwgtqub.dll> [File is missing]
<avicapwm.dll><C:\WINDOWS\system32\avicapwm.dll> [File is missing]
<wtsapi32yt2.dll><C:\WINDOWS\system32\wtsapi32yt2.dll> [File is missing]
<nzkzctty.dll><C:\WINDOWS\system32\fdgusuvz.dll> []
<cvrikqjq.dll><C:\WINDOWS\system32\cvrikqjq.dll> []
<mltgajhz.dll><C:\WINDOWS\system32\mltgajhz.dll> []
<nsenvhqp.dll><C:\WINDOWS\system32\nsenvhqp.dll> []
<xwgrthdl.dll><C:\WINDOWS\system32\xwgrthdl.dll> []
<ktcjcajs.dll><C:\WINDOWS\system32\ktcjcajs.dll> []
<hqlcmxap.dll><C:\WINDOWS\system32\hqlcmxap.dll> []
<kmrqrpnd.dll><C:\WINDOWS\system32\kmrqrpnd.dll> []
<fdgusuvz.dll><C:\WINDOWS\system32\fdgusuvz.dll> []
<IFEO[conime.exe]><ntsd -d> [N/A]
<IFEO[taskmgar.exe]><ntsd -d> [N/A]
删除驱动服务
[caxyoqr / caxyoqr][Stopped/Disabled]
<\??\C:\WINDOWS\system32\drivers\caxyoqr.sys><N/A>
[HBKernel32 Driver / HBKernel32][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\HBKernel32.sys><N/A>
[qabopx / qabopx][Stopped/Disabled]
<\??\C:\WINDOWS\system32\drivers\qabopx.sys><N/A>
[qpaypqc / qpaypqc][Stopped/Disabled]
<\??\C:\WINDOWS\system32\drivers\qpaypqc.sys><N/A>
[wmpobj / wmpobj][Running/Auto Start]
<\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\obj\wmpobj.sys><N/A>
[xbqpayz / xbqpayz][Stopped/Disabled]
<\??\C:\WINDOWS\system32\drivers\xbqpayz.sys><N/A>
[xbyqpr / xbyqpr][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\xbyqpr.sys><N/A>
[yopybzc / yopybzc][Stopped/Disabled]
<\??\C:\WINDOWS\system32\drivers\yopybzc.sys><N/A>
[yorxbzp / yorxbzp][Stopped/Disabled]
<\??\C:\WINDOWS\system32\drivers\yorxbzp.sys><N/A>