运行SRENG删除启动项目注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<fmsiocps><C:\WINDOWS\fmsiocps.exe> []
<upxdnd><C:\WINDOWS\zmyumk.exe> []
<AVPSrv><C:\WINDOWS\uecapi.exe> []
<dbhlp32><C:\WINDOWS\dbhlp32.exe> []
<bincdwsa><C:\WINDOWS\bincdwsa.exe> []
<MsIMMs32><C:\WINDOWS\MsIMMs32.exE> []
<xlitbmqr><C:\WINDOWS\ltmrhhyo.exe> []
<mfchlp64><C:\WINDOWS\mfchlp64.exe> []
<fmsbbqi><C:\WINDOWS\fmsbbqi.exe> []
<PTSShell><C:\WINDOWS\PTSShell.exe> []
<cmdbcs><C:\WINDOWS\heitmp.exe> []
<WINSvr64><C:\WINDOWS\WINSvr64.exe> []
<LotusHlp><C:\WINDOWS\LotusHlp.exe> []
<huifitc><C:\WINDOWS\huifitc.exe> []
<mppds><C:\WINDOWS\mppds.EXE> []
<fmbiost><C:\WINDOWS\fmbiost.exe> []
<tciocp32><C:\WINDOWS\tciocp32.exe> []
<dndsioc><C:\WINDOWS\dndsioc.exe> []
<Kvsc3><C:\WINDOWS\Kvsc3.exE> []
<WinSysW><C:\WINDOWS\215366L.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><msosmhfp02.dll,msosdohs00.dll,msoscqit00.dll,msosmnsf00.dll,msosping00.dll,msosdrop00.dll,msosptfs00.dll,msosfmsq00.dll> 此项用ICEW修改键值 为空
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{398C9B84-4EF7-47B5-9862-DE29543B3C42}><C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys> []
修复IFEO印象劫持
删除服务:[Kerberos Key Distribution Centers / kkdc][Stopped/Auto Start]
<C:\WINDOWS\lsass.exe -netsvcs><N/A>
删除驱动服务:[ptfs / ptfs][Stopped/Auto Start]
<\??\C:\DOCUME~1\qiujian\LOCALS~1\Temp\tmp64.tmp><N/A>
[70801 / 70801][Running/]
<2 - 系统找不到指定的文件。
><N/A>
使用ICEW删除文件:
C:\WINDOWS\system32\msoscqit00.dll] [N/A, ]
[C:\WINDOWS\system32\msosping00.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop00.dll] [N/A, ]
[C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ]
[C:\WINDOWS\system32\fmsiocps.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\dbhlp32.dlL] [N/A, ]
[C:\WINDOWS\system32\bincdwsa.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[C:\WINDOWS\system32\wihmihoh.dll] [N/A, ]
[C:\WINDOWS\system32\mfchlp64.dll] [N/A, ]
[C:\WINDOWS\system32\msoscqit00.dll] [N/A, ]
[C:\WINDOWS\system32\dllcache\SXS.DLL] [Microsoft Corporation, 5.1.2600.3019 (xpsp_sp2_gdr.061019-0414)]
[C:\WINDOWS\system32\fmsbbqi.dll] [N/A, ]
[C:\WINDOWS\system32\PTSShell.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\WINSvr64.dll] [N/A, ]
[C:\WINDOWS\system32\LotusHlp.dll] [N/A, ]
[C:\WINDOWS\system32\huifitc.dll] [N/A, ]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\WINDOWS\system32\fmbiost.dll] [N/A, ]
[C:\WINDOWS\system32\tciocp32.dll] [N/A, ]
[C:\WINDOWS\system32\dndsioc.dll] [N/A, ]
[C:\WINDOWS\system32\msosping00.dll] [N/A, ]
[C:\WINDOWS\system32\msosdrop00.dll] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\WINDOWS\system32\msosfmsq00.dll] [N/A, ]
[C:\WINDOWS\215366WL.DLL] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys] [N/A, ]
<fmsiocps><C:\WINDOWS\fmsiocps.exe> []
<upxdnd><C:\WINDOWS\zmyumk.exe> []
<AVPSrv><C:\WINDOWS\uecapi.exe> []
<dbhlp32><C:\WINDOWS\dbhlp32.exe> []
<bincdwsa><C:\WINDOWS\bincdwsa.exe> []
<MsIMMs32><C:\WINDOWS\MsIMMs32.exE> []
<xlitbmqr><C:\WINDOWS\ltmrhhyo.exe> []
<mfchlp64><C:\WINDOWS\mfchlp64.exe> []
<fmsbbqi><C:\WINDOWS\fmsbbqi.exe> []
<PTSShell><C:\WINDOWS\PTSShell.exe> []
<cmdbcs><C:\WINDOWS\heitmp.exe> []
<WINSvr64><C:\WINDOWS\WINSvr64.exe> []
<LotusHlp><C:\WINDOWS\LotusHlp.exe> []
<huifitc><C:\WINDOWS\huifitc.exe> []
<mppds><C:\WINDOWS\mppds.EXE> []
<fmbiost><C:\WINDOWS\fmbiost.exe> []
<tciocp32><C:\WINDOWS\tciocp32.exe> []
<dndsioc><C:\WINDOWS\dndsioc.exe> []
<Kvsc3><C:\WINDOWS\Kvsc3.exE> []
<WinSysW><C:\WINDOWS\215366L.exe> [N/A]