1.建议使用XDelBox删除以下文件:(
XDelBox1.6下载)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
c:\program files\internet explorer\packer.tdm
c:\windows\system32\czvzfxsa.dll
c:\windows\system32\ghjsw.dll
c:\windows\system32\hbxy2.dll
c:\windows\system32\lweurqhx.dll
c:\windows\system32\nwapi32dj.dll
c:\windows\system32\xsbvgzd.dll
c:\windows\system32\zxdtye.dll
c:\windows\system32\hbchibi.dll
c:\windows\system32\hbconquer.dll
c:\windows\system32\hbct.dll
c:\windows\system32\hbfs2.dll
c:\windows\system32\hbfy.dll
c:\windows\system32\hbjxsj.dll
c:\windows\system32\hbkdxy.dll
c:\windows\system32\hbmhly.dll
c:\windows\system32\hbwulin2.dll
c:\windows\system32\hbzhuxian.dll
c:\windows\system32\rdcbl.dll
c:\windows\system32\rdwll.dll
c:\windows\system32\wrm32.dll
c:\windows\system\zyndle080919.exe
C:\WINDOWS\system32\System.exe
C:\WINDOWS\system32\explore.exe
c:\windows\system32\xsbvgzd.exe
c:\windows\system32\sizhu.exe
c:\documents and settings\all users\「开始」菜单\程序\启动\snmpo.exe
c:\windows\system32\drivers\vibus.sys
c:\windows\system32\drivers\msiffei.sys
c:\windows\system32\drivers\lveia.sys
c:\windows\system32\drivers\hbkernel32.sys
c:\windows\system32\drivers\hbkernel.sys
c:\00101176\0010117e
c:\windows\system32\e5e3454.sys
c:\windows\system32\d7ba6e.sys
c:\windows\system32\drivers\bdguard.sys
C:\SiZhu.exe
D:\SiZhu.exe
E:\SiZhu.exe
F:\SiZhu.exe
C:\autorun.inf
D:\autorun.inf
E:\autorun.inf
F:\autorun.inf
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[lweurqhx.dll] <C:\WINDOWS\system32\lweurqhx.dll>
[nwapi32dj.dll] <C:\WINDOWS\system32\nwapi32dj.dll>
[czvzfxsa.dll] <C:\WINDOWS\system32\czvzfxsa.dll>
[{DD7D4640-4464-48C0-82FD-21338366D2D2}] <C:\Program Files\Internet Explorer\Packer.tdm>
[{71A78CD4-E470-4a18-8457-E0E0283DD507}] <C:\WINDOWS\system32\lweurqhx.dll>
[{3474A8C2-BEF9-46C8-983A-A26A0030EC30}] <3474A8C2.dll>
[{A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9}] <C:\WINDOWS\system32\nwapi32dj.dll>
[{F0930A2F-D971-4828-8209-B7DFD266ED44}] <C:\WINDOWS\system32\czvzfxsa.dll>
[{495271CA-D0C6-4052-ABE6-5B01C73CDFB0}] <495271CA.dll>
[{53360697-E270-4F80-AD5D-6FB518F03D24}] <53360697.dll>
[{AF05A291-7249-4C15-B212-3E8D8C02438D}] <AF05A291.dll>
[{7ADC2AB1-5C6A-4178-82DA-94863354AF7C}] <7ADC2AB1.dll>
[{369774CA-7CB4-4A3F-A9A9-77D6BC53CB3B}] <369774CA.dll>
[{4BF9CBA3-8DEE-41A1-8BDB-FC28D30E949F}] <4BF9CBA3.dll>
[{EBE50EA1-89C8-463A-998A-69A05ECD2D26}] <EBE50EA1.dll>
[nmzy_df] <C:\WINDOWS\system\zyndle080919.exe>
[kab12] <kab12.exe>
[HBService] <explore.exe>
[xsbvgzd] <C:\WINDOWS\system32\xsbvgzd.exe>
[HBService32] <System.exe>
[SiZhu] <C:\WINDOWS\system32\SiZhu.exe>
注意该项[AppInit_DLLs]修改:把<aaa.dll,HBmhly.dlllensch.dll thermaltinc.dll follwel.dll rmchamp.dll mcromv.dllwllame.dll catower.dll inserse.dll eskisl.dllmduaey.dll,HBXY2.dll,HBJXSJ.dll,HBFS2.dll,HBFY.dll,HBWULIN2.dll,HBKDXY.dll,HBZHUXIAN.dll,HBCONQUER.dll,HBCHIBI.dll,HBCT.dll>修改为<>即清空
启动项目 -- 启动文件夹之如下项删除:
[snmpo] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\snmpo.exe>
启动项目 -- 服务-- 驱动程序之如下项删除:
(选中有问题的驱动/服务后,点"删除服务",点"设置"按钮即可。注意弹出的窗口中要点"否NO"才是确认删除服务)
[ViBus / ViBus] <\SystemRoot\system32\DRIVERS\ViBus.sys>
[msIffei / msIffei] <System32\Drivers\msIffei.sys>
[lveia / lveia] <\SystemRoot\system32\drivers\lveia.sys>
[HBKernel32 Driver / HBKernel32] <\SystemRoot\system32\DRIVERS\HBKernel32.sys>
[HBKernel Driver / HBKernel] <\SystemRoot\system32\DRIVERS\HBKernel.sys>
[xxxALLGUARD / xxxALLGUARD] <\??\C:\00101176\0010117E>
[e5e3454 / e5e3454] <\??\C:\WINDOWS\system32\e5e3454.sys>
[d7ba6e / d7ba6e] <\??\C:\WINDOWS\system32\d7ba6e.sys>
[BdGuard / BdGuard] <\SystemRoot\system32\drivers\BDGuard.SYS>