好乱哟~~
注意,如果有你认识的文件名,是你自己安装的,请不要删除
用XDELBOX删除文件:(工具在附件)
C:\WINDOWS\system32\ljJDUlig.dll
C:\WINDOWS\system32\fvnpgggm.dll
C:\WINDOWS\system32\opnllmkl.dll
C:\WINDOWS\msccrt.exe
C:\WINDOWS\iexpl0ra.exe
I:\UUCall3.exe
C:\WINDOWS\IG.exe
选择重起后删除
重起后用SRENG删除注册表中
<ASocksrv><SocksA.exe> [N/A]
<Clip Srv><clipsv.exe> []
<b0b89028><rundll32.exe "C:\WINDOWS\system32\fvnpgggm.dll",b> []
<IVY><.vbe> []
<WUSHUANG><.vbe> []
<{36B5B879-B652-41E2-B37C-161E15053D60}><C:\WINDOWS\system32\opnllmkl.dll> [N/A]
<{4020100D-29D7-4392-AFD5-5AD713FF4B88}><C:\WINDOWS\system32\ljJDUlig.dll> []
<WinlogonNotify: ljJDUlig><ljJDUlig.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ASocksrv><; SocksA.exe> [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<EXPLORER.EXE><; EXPLORER.EXE> [(Verified)Microsoft Windows Component Publisher]
<msccrt><; C:\WINDOWS\msccrt.exe> [N/A]
<r1mzl8i1ds7jv5><; C:\WINDOWS\iexpl0ra.exe> [N/A]
<UUCallMini><; "I:\UUCall3.exe" -autorun> [N/A]
<WinSys><; C:\WINDOWS\IG.exe> [N/A]
<wsctf.exe><; wsctf.exe> [N/A]
删除启动文件夹
[conn]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\conn.bat --> [N/A]><N>
删除浏览器加载
[]
{208A73C7-BA29-4597-87AD-C7091A345CC9} <C:\WINDOWS\system32\ddcywuuv.dll, N/A>
[Flashget Catch Url Class]
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} <C:\Program Files\FlashGet\jccatch.dll, www.flashget.com>
[]
{36B5B879-B652-41E2-B37C-161E15053D60} <C:\WINDOWS\system32\opnllmkl.dll, N/A>
[]
{8703B814-B436-4D99-B126-CE5DF302731F} <C:\WINDOWS\system32\log.txt, N/A>
[]
{208A73C7-BA29-4597-87AD-C7091A345CC9} <C:\WINDOWS\system32\ddcywuuv.dll, N/A>[]
{2CDB45FD-4527-4563-8A3E-01A5AE809BA1} <C:\WINDOWS\system32\ddcywuuv.dll, N/A>[]
{36B5B879-B652-41E2-B37C-161E15053D60} <C:\WINDOWS\system32\opnllmkl.dll, N/A>[]
{8703B814-B436-4D99-B126-CE5DF302731F} <C:\WINDOWS\system32\log.txt, N/A>
[]
{EC53FD5A-F2D4-4908-B31C-941486CD2052} <C:\WINDOWS\system32\ddcywuuv.dll, N/A>
下载arswp(Windows清理助手)清理下..
http://www.arswp.com/download/arswp/arswp.rar
清理临时文件夹:
打开我的电脑-工具-文件夹选项-查看-显示隐藏文件-隐藏受保护的系统文件(勾去掉)-确定
重起进入安全模式(开机不停的按F8,选择安全模式启动) 清空下列临时文件夹中所有内容:
C:\Documents and Settings\用户名\Local Settings\Temporary Internet Files
C:\Documents and Settings\用户名\Local Settings\Temp
C:\WINDOWS\TEMP