下载“附件1”,解压后将注册表导入
参考这里:
http://bbs.ikaka.com/showtopic-8502100.aspx下载并安装PE,并下载“费尔……助手” 重起选择进入PE系统做两件事;
1.用费尔……助手删除以下文件:
c:\docume~1\networ~1\locals~1\temp\b31.exe
c:\docume~1\locals~1\locals~1\temp\b31.exe
c:\windows\system32\msosdohs04.dll
c:\windows\system32\msosdohs05.dll
c:\windows\system32\hiwave.dll
c:\windows\system32\msosdohs03.dll
c:\windows\system32\tphklock.dll
c:\docume~1\networ~1\locals~1\temp\m28.exe
c:\docume~1\locals~1\locals~1\temp\m28.exe
c:\windows\temp\2b31.exe
c:\windows\temp\1b31.exe
c:\docume~1\networ~1\locals~1\temp\m23.exe
c:\docume~1\locals~1\locals~1\temp\m23.exe
c:\docume~1\networ~1\locals~1\temp\x22.exe
c:\docume~1\locals~1\locals~1\temp\x22.exe
c:\docume~1\networ~1\locals~1\temp\l18.exe
c:\docume~1\locals~1\locals~1\temp\1l18.exe
c:\docume~1\networ~1\locals~1\temp\1j17.exe
c:\docume~1\locals~1\locals~1\temp\n14.exe
c:\windows\temp\2l10.exe
c:\docume~1\networ~1\locals~1\temp\n14.exe
c:\docume~1\locals~1\locals~1\temp\m13.exe
c:\windows\temp\1b11.exe
c:\windows\temp\2x9.exe
c:\docume~1\networ~1\locals~1\temp\m13.exe
c:\windows\temp\b11.exe
c:\windows\temp\1l10.exe
c:\docume~1\locals~1\locals~1\temp\b11.exe
c:\windows\temp\2i8.exe
c:\docume~1\networ~1\locals~1\temp\b11.exe
c:\windows\temp\l10.exe
c:\windows\temp\1x9.exe
c:\windows\temp\2r7.exe
c:\docume~1\locals~1\locals~1\temp\l10.exe
c:\docume~1\networ~1\locals~1\temp\l10.exe
c:\windows\temp\x9.exe
c:\windows\temp\1i8.exe
c:\windows\temp\2m6.exe
c:\docume~1\locals~1\locals~1\temp\x9.exe
c:\docume~1\networ~1\locals~1\temp\x9.exe
c:\windows\temp\i8.exe
c:\windows\temp\1r7.exe
c:\windows\temp\2y5.exe
c:\docume~1\locals~1\locals~1\temp\i8.exe
c:\docume~1\networ~1\locals~1\temp\i8.exe
c:\windows\temp\r7.exe
c:\windows\temp\1m6.exe
c:\docume~1\locals~1\locals~1\temp\r7.exe
c:\docume~1\networ~1\locals~1\temp\r7.exe
c:\windows\temp\m6.exe
c:\windows\temp\1y5.exe
c:\windows\temp\2a3.exe
c:\docume~1\locals~1\locals~1\temp\m6.exe
c:\docume~1\networ~1\locals~1\temp\m6.exe
c:\windows\temp\y5.exe
c:\docume~1\locals~1\locals~1\temp\y5.exe
c:\docume~1\networ~1\locals~1\temp\y5.exe
c:\windows\temp\1a3.exe
c:\windows\temp\a3.exe
c:\docume~1\networ~1\locals~1\temp\1a3.exe
c:\docume~1\locals~1\locals~1\temp\a3.exe
c:\windows\system32\tpkmpsvc.exe
c:\windows\dxoroc.exe
c:\docume~1\networ~1\locals~1\temp\2e1.exe
c:\docume~1\locals~1\locals~1\temp\3e1.exe
c:\windows\system32\msosdohs00.dll
c:\windows\system32\msosdohs02.dll
c:\windows\system32\msosdohs01.dll
c:\windows\system32\nfrpna.dll
c:\windows\system32\ticisms.dll
c:\windows\system32\ahufcx.dll
c:\windows\system32\boqceo.dll
c:\windows\system32\fmxvlj.dll
c:\windows\system32\hefxxxy.dll
c:\windows\system32\huifitc.dll
c:\windows\system32\ocyzre.dll
c:\windows\system32\xpuvyb.dll
c:\windows\system32\xusekp.dll
c:\windows\system32\tphklock.dll
c:\windows\system32\notifyf2.dll
c:\windows\system32\sysdajhv.dll
c:\windows\system32\hiwave.dll
c:\windows\system32\msosdohs05.dll
c:\windows\system32\nfrpna.dll
c:\windows\cinfonmc.exe
c:\windows\huifitc.exe
c:\windows\ticisms.exe
c:\windows\fmsbbqi.exe
c:\windows\dbhlp32.exe
c:\windows\ptshell.exe
c:\windows\issms32.exe
c:\windows\mfchlp64.exe
c:\windows\tciocp64.exe
c:\windows\qpcxvvoo.exe
c:\windows\system32\tdffdl.dll
c:\windows\system32\zgxfdx.dll
c:\windows\system32\ffxams.dll
c:\windows\system32\phnrqt.dll
c:\windows\system32\tfsdmz.dll
c:\windows\system32\jhrcar.dll
c:\windows\system32\wyrsdj.dll
c:\windows\temp\data9.tmp
c:\windows\fmsjhif.exe
c:\windows\system32\dms.exe
c:\windows\microsoftimm.exe
c:\windows\system32\drivers\8nev1.sys
c:\windows\system32\drivers\acpidisk.sys
c:\windows\system32\drivers\msosmsfpfis64.sys
c:\windows\temp\tmp20e.tmp
c:\windows\temp\tmpab.tmp
c:\windows\temp\tmp8c.tmp
c:\windows\\systemroot\system32\drivers\ojmiphs.sys
c:\windows\system32\drivers\nicomsp2p32.sys
c:\windows\temp\tmp81.tmp
c:\windows\temp\tmp4a.tmp
c:\windows\temp\tmp71.tmp
c:\windows\temp\tmp87.tmp
c:\windows\temp\tmp6c.tmp
c:\windows\system32\izyajddadh.dll
c:\windows\downloaded program files\acpir2.dll
c:\windows\downloaded program files\acpcontroller2.dll
c:\documents and settings\all users\application data\microsoft\pctools\pctools.dll
c:\program files\common files\cpush\cpush1.dll
c:\windows\vqqsdl10.dll
2,复制c:\windows\system32\dllcache\文件夹里的services.exe cdfview.dll 和 svchost.exe三文件 全部粘贴到c:\windows\system32\文件夹里 提示替换 选是(在替换之前,请先将c:\windows\system32\svchost.exe打包上传到“可疑文件交流”版块。
上面的全正确处理完后重起按F8选择进入安全模式继续下面的修复
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[WinlogonNotify: tphotkey]
[WinlogonNotify: tpfnf2]
[{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}]
注意该项[AppInit_DLLs]修改:把<SysDaJHv.dll,hiwave.dll,msosdohs05.dll,nfrpna.dll>修改为<>即清空
[cinfonmc]
[huifitc]
[ticisms]
[fmsbbqi]
[dbhlp32]
[ptshell]
[fmsiocps]
[issms32]
[mfchlp64]
[tciocp64]
[bqipncyx]
[{C0595A7E-2E2F-4B34-A83A-019270A0A464}]
[{6E6CA8A1-81BC-4707-A54C-F4903DD70BAD}]
[{633BA449-FE3D-4F3D-B8B8-BD8E0C2FBAE6}]
[{F3A687FE-AFEB-4418-B82C-753093D3A5AD}]
[{875E07B1-0614-43D9-A76E-D76A28AB3D7B}]
[{CAED0F3B-DF8B-4DBF-BB20-8DFBC3199068}]
[{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}]
[{7FA4A83B-F99A-4bfc-A8E2-6A62B05D2C82}]
[fmsjhif]
启动项目 -- 服务 -- Win32服务应用程序之如下项删除:
[126D25E7 / 126D25E7]
[NTPDate Service / NTPDate Service]
[Windows Manager MicroSoft IMM / SogouService]
[126D25E7 / 126D25E7]
启动项目 -- 服务-- 驱动程序之如下项删除:
[8nev / 8nev1]
[acpidisk / acpidisk]
[msfpfis64 / msfpfis64]
[zftp / zftp]
[ptfs / ptfs]
[ping / ping]
[ojmiphs / ojmiphs]
[msp2p32 / msp2p32]
[mnsf / mnsf]
[mhfp / mhfp]
[fmsq / fmsq]
[drop / drop]
[dohs / dohs]
系统修复-- 浏览器加载项之如下项删除:
[] <C:\WINDOWS\system32\izyajddadh.dll>
[IASRunner Class] <C:\WINDOWS\Downloaded Program Files\acpir2.dll>
[acpRunner Class] <C:\WINDOWS\Downloaded Program Files\acpcontroller2.dll>
[Info cache] <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll>
[CAdLogic Object] <C:\Program Files\Common Files\CPUSH\cpush1.dll>
[VqqSpeedDlProxy Class] <C:\WINDOWS\vqqsdl10.dll>
全部做完下载以下软件清理一次并更新杀毒软件至最新进行全盘杀毒
清理系统临时文件和IE临时文件夹
http://www.atribune.org/public-beta/ATF-Cleaner.exe 用金山清理专家清理恶意软件
http://www.duba.net/zt/ksc/down.shtml 下载 windows清理助手清理一遍
http://www.arswp.com/download/arswp2/arswp2.zip