楼主按以下操作:
1. 杀毒前关闭系统还原(Win2000系统可以忽略):右键 我的电脑 ,属性,系统还原,在所有驱动器上关闭系统还原 打勾即可。
清除IE的临时文件:打开IE 点工具-->Internet选项 : Internet临时文件,点“删除文件”按钮 ,将 删除所有脱机内容 打勾,点确定删除。
关闭QQ等应用程序。进行如下操作前,请不要进行任何双击打开磁盘的操作。所有下载的工具都直接放桌面上。
2.建议使用XDelBox删除以下文件:(XDelBox1.7下载)
http://www.dodudou.com/down/index.php?dirpath=./01.原创软件&order=0
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入不检查路径,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
C:\WINDOWS\system32\d4761.exe
C:\WINDOWS\system32\vistaAA.exe
C:\Program Files\Windows NT\colbi.dll
C:\WINDOWS\system32\1d1.dll
C:\WINDOWS\system32\zyzxfime.dll
C:\WINDOWS\system32\opshbbty.dll
C:\WINDOWS\system32\zxptejpg.dll
C:\WINDOWS\system32\ypcqdhlp.dll
C:\WINDOWS\system32\zptlbsys.dll
C:\WINDOWS\system32\mndsdsrv.dll
C:\WINDOWS\system32\oohxcbyt.dll
C:\WINDOWS\system32\zywmdime.dll
C:\WINDOWS\system32\zxmsbwin.dll
C:\WINDOWS\system32\ypdjebmp.dll
C:\WINDOWS\system32\yxcschlp.dll
C:\WINDOWS\system32\mnmhcsrv.dll
C:\WINDOWS\system32\yzztemsn.dll
C:\WINDOWS\system32\pjjxcdwd.dll
C:\WINDOWS\system32\ozfydbyt.dll
C:\WINDOWS\system32\mpwdcapi.dll
C:\WINDOWS\system32\ptjhdhlp.dll
3.删除重启后使用SREng修复下面各项:
SREng详细操作方法:
http://hi.baidu.com/peaset/blog/item/3114a7fb17dd19224e4aeadf.html 启动项目 -- 注册表之如下项删除:
<{6A59145F-315D-BC23-AC1F-145DF81A34A6}><C:\WINDOWS\system32\zyzxfime.dll> [N/A]
<{22596546-2036-9451-6058-658402589722}><C:\WINDOWS\system32\opshbbty.dll> [N/A]
<{91698482-6555-3666-1222-954784129019}><C:\WINDOWS\system32\zxptejpg.dll> [N/A]
<{40940F85-F015-14F1-A05F-F69858AC6D04}><C:\WINDOWS\system32\zptlbsys.dll> [N/A]
<{50AF1289-F140-A140-D012-C1458759FC05}><C:\WINDOWS\system32\ypcqdhlp.dll> [N/A]
<{4B1AEF69-DDAE-FDAD-DCAB-698F026ABDB4}><C:\WINDOWS\system32\oohxcbyt.dll> [N/A]
<{47FD640A-158F-48AC-FD14-1597F14A9774}><C:\WINDOWS\system32\mndsdsrv.dll> [N/A]
<{4319A1F1-9410-9654-3201-345FFA349134}><C:\WINDOWS\system32\zywmdime.dll> [N/A]
<{5A041F13-A111-12A3-B0CF-F99818AA68A5}><C:\WINDOWS\system32\zxmsbwin.dll> [N/A]
<{71954FAC-1023-154F-895A-1458258AD817}><C:\WINDOWS\system32\ypdjebmp.dll> [N/A]
<{35671234-7890-ABCD-CDEF-567801237653}><C:\WINDOWS\system32\yxcschlp.dll> [N/A]
<{3C8D1401-A58D-A81C-CD24-A5915C4517C3}><C:\WINDOWS\system32\mnmhcsrv.dll> [N/A]
<{5490415F-65F8-B5C5-D8BA-9405FB120545}><C:\WINDOWS\system32\yzztemsn.dll> [N/A]
<{34FAE856-AD58-20CB-A025-CD4895FA6E43}><C:\WINDOWS\system32\pjjxcdwd.dll> [N/A]
<{4A069845-2036-6084-9054-6087502480A4}><C:\WINDOWS\system32\ozfydbyt.dll> [N/A]
<{35694105-5108-9405-3695-954187462153}><C:\WINDOWS\system32\mpwdcapi.dll> [N/A]
<{428DF602-9541-A985-210A-984A698C6F24}><C:\WINDOWS\system32\ptjhdhlp.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\45fghfd.exe]
<IFEO[45fghfd.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\5784sddfgiaa.exe]
<IFEO[5784sddfgiaa.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appdllman.exe]
<IFEO[appdllman.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto.exe]
<IFEO[auto.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AutoRun.exe]
<IFEO[AutoRun.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cross.exe]
<IFEO[cross.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dfcxfg.exe]
<IFEO[dfcxfg.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Discovery.exe]
<IFEO[Discovery.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FuckAAAAAAA.exe]
<IFEO[FuckAAAAAAA.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guangd.exe]
<IFEO[guangd.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kernelwind32.exe]
<IFEO[kernelwind32.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\logogo.exe]
<IFEO[logogo.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVSetup.exe]
<IFEO[NAVSetup.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pagefile.exe]
<IFEO[pagefile.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pagefile.pif]
<IFEO[pagefile.pif]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit32.Exe]
<IFEO[regedit32.Exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwProxy.exe]
<IFEO[rfwProxy.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDGames.exe]
<IFEO[SDGames.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\servet.exe]
<IFEO[servet.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sos.exe]
<IFEO[sos.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SSDtDiscovery.exe]
<IFEO[SSDtDiscovery.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TNT.Exe]
<IFEO[TNT.Exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TxoMoU.Exe]
<IFEO[TxoMoU.Exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\U.exe]
<IFEO[U.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UFO.exe]
<IFEO[UFO.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USBoot.exe]
<IFEO[USBoot.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Wsyscheck.exe]
<IFEO[Wsyscheck.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\XP.exe]
<IFEO[XP.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xxxdgfdfg.exe]
<IFEO[xxxdgfdfg.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zxsweep.exe]
<IFEO[zxsweep.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~.exe]
<IFEO[~.exe]><C:\WINDOWS\system32\vistaAA.exe> [N/A]
启动项目 -- 服务 -- Win32服务应用程序之如下项删除:
[NetBI0S / NetBI0S][Running/Auto Start]
<C:\WINDOWS\system32\d4761.exe><Microsoft Corporation>
启动项目 -- 服务-- 驱动程序之如下项删除:
[HapDrv32 / HapDrv32][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\hapdrv2.sys><N/A>
[inok3z / inok3z2][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\inok3z2.sys><N/A>
[q6g4 / q6g4e][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\q6g4e.sys><N/A>
[XNGAnti / XNGAnti][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\ReloadAnti.sys><N/A>
系统修复-- 浏览器加载项之如下项删除:
[]
{4B1AEF69-DDAE-FDAD-DCAB-698F026ABDB4} <C:\WINDOWS\system32\oohxcbyt.dll, N/A>
[]
{50AF1289-F140-A140-D012-C1458759FC05} <C:\WINDOWS\system32\ypcqdhlp.dll, N/A>
[]
{5490415F-65F8-B5C5-D8BA-9405FB120545} <C:\WINDOWS\system32\yzztemsn.dll, N/A>
[]
{5A041F13-A111-12A3-B0CF-F99818AA68A5} <C:\WINDOWS\system32\zxmsbwin.dll, N/A>
[]
{6A59145F-315D-BC23-AC1F-145DF81A34A6} <C:\WINDOWS\system32\zyzxfime.dll, N/A>
[]
{71954FAC-1023-154F-895A-1458258AD817} <C:\WINDOWS\system32\ypdjebmp.dll, N/A>
[Invoke Class]
{77929B3F-50EB-449b-9982-CAD99180EC0F} <C:\WINDOWS\system32\dd41.dll, >
[]
{91698482-6555-3666-1222-954784129019} <C:\WINDOWS\system32\zxptejpg.dll, N/A>
[]
{22596546-2036-9451-6058-658402589722} <C:\WINDOWS\system32\opshbbty.dll, N/A>
[]
{34FAE856-AD58-20CB-A025-CD4895FA6E43} <C:\WINDOWS\system32\pjjxcdwd.dll, N/A>
[]
{35671234-7890-ABCD-CDEF-567801237653} <C:\WINDOWS\system32\yxcschlp.dll, N/A>
[]
{35694105-5108-9405-3695-954187462153} <C:\WINDOWS\system32\mpwdcapi.dll, N/A>
[]
{3C8D1401-A58D-A81C-CD24-A5915C4517C3} <C:\WINDOWS\system32\mnmhcsrv.dll, N/A>
[]
{40940F85-F015-14F1-A05F-F69858AC6D04} <C:\WINDOWS\system32\zptlbsys.dll, N/A>
[]
{428DF602-9541-A985-210A-984A698C6F24} <C:\WINDOWS\system32\ptjhdhlp.dll, N/A>
[]
{4319A1F1-9410-9654-3201-345FFA349134} <C:\WINDOWS\system32\zywmdime.dll, N/A>
[]
{47FD640A-158F-48AC-FD14-1597F14A9774} <C:\WINDOWS\system32\mndsdsrv.dll, N/A>
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\system32\msxml3.dll, N/A>
[]
{4A069845-2036-6084-9054-6087502480A4} <C:\WINDOWS\system32\ozfydbyt.dll, N/A>
[]
{4B1AEF69-DDAE-FDAD-DCAB-698F026ABDB4} <C:\WINDOWS\system32\oohxcbyt.dll, N/A>
[]
{50AF1289-F140-A140-D012-C1458759FC05} <C:\WINDOWS\system32\ypcqdhlp.dll, N/A>
[]
{5490415F-65F8-B5C5-D8BA-9405FB120545} <C:\WINDOWS\system32\yzztemsn.dll, N/A>
[]
{5A041F13-A111-12A3-B0CF-F99818AA68A5} <C:\WINDOWS\system32\zxmsbwin.dll, N/A>
[]
{6A59145F-315D-BC23-AC1F-145DF81A34A6} <C:\WINDOWS\system32\zyzxfime.dll, N/A>
[]
{71954FAC-1023-154F-895A-1458258AD817} <C:\WINDOWS\system32\ypdjebmp.dll, N/A>
[Invoke Class]
{77929B3F-50EB-449B-9982-CAD99180EC0F} <C:\WINDOWS\system32\dd41.dll, >
[]
{91698482-6555-3666-1222-954784129019} <C:\WINDOWS\system32\zxptejpg.dll, N/A>
打开 SREng ,依次点击“系统修复”->“HOSTS文件”->重置->确定
引用:
清理系统临时文件和IE临时文件夹
http://www.atribune.org/public-beta/ATF-Cleaner.exe 用金山清理专家清理恶意软件
http://client.download.duba.net/KASSetup_10_1.EXE下载windows清理助手清理一遍
http://www.arswp.com/download/arswp2/arswp2.zip