下载xdelbox删除以下文件
http://www.dodudou.com/down/index.php?dirpath=./01.原创软件&order=0
C:\WINDOWS\system32\winlib .dll
C:\WINDOWS\anistio.exE
C:\WINDOWS\kzdoqhwj.exe
C:\WINDOWS\Fonts\92190f07b28bb48ff659b63da52457ba\system\svchost.exe
C:\WINDOWS\huifitc.exe
C:\WINDOWS\ticisms.exe
C:\WINDOWS\bincdwsa.exe
C:\WINDOWS\system32\msosmhfp01.dll
C:\WINDOWS\system32\msosdohs01.dll
C:\WINDOWS\system32\nicozftp00.dll
C:\WINDOWS\system32\msosping00.dll
C:\WINDOWS\system32\msosmnsf00.dll
C:\WINDOWS\system32\msosfmsq00.dll
C:\WINDOWS\system32\ypcqdhlp.dll
C:\WINDOWS\system32\mpmydapi.dll
C:\WINDOWS\system32\zptlbsys.dll
C:\WINDOWS\system32\zptlcsys.dll
C:\WINDOWS\system32\hhrdxd.dll
C:\WINDOWS\system32\sgrefg.dll
C:\WINDOWS\system32\ztiudy.dll
C:\WINDOWS\system32\jfrwdh.dll
C:\WINDOWS\system32\zycbbime.dll
C:\WINDOWS\system32\yxcschlp.dll
C:\WINDOWS\system32\wrqszl.dll
C:\WINDOWS\system32\zyzxfime.dll
C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys
C:\WINDOWS\system32\mndscsrv.dll
C:\WINDOWS\system32\MMFKKLJK1075.dll
C:\WINDOWS\system32\ttNNBNNB1047.dll
C:\WINDOWS\system32\lofsajbo.dll
C:\WINDOWS\system32\zxmsbwin.dll
C:\WINDOWS\system32\zywmdime.dll
C:\WINDOWS\system32\MMWLVAHB1017.dll
C:\WINDOWS\system32\MMSADZFB1048.dll
C:\WINDOWS\system32\zyzxeime.dll
C:\WINDOWS\system32\zxptejpg.dll
C:\WINDOWS\system32\ptjhchlp.dll
C:\Documents and Settings\All Users\「开始」菜单\程序\启动\update.exe
C:\WINDOWS\system32\GrxhjKsBMxwXPHvBFR.dll
C:\WINDOWS\system32\21.exe
C:\WINDOWS\system32\winini.exe
C:\WINDOWS\system32\msosdohs01.dll
C:\WINDOWS\system32\msosping00.dll
C:\WINDOWS\system32\msosmnsf00.dll
C:\WINDOWS\system32\msosfmsq00.dll
C:\WINDOWS\system32\MMFKKLJK1075.dll
C:\WINDOWS\system32\ttNNBNNB1047.dll
C:\WINDOWS\system32\MMWLVAHB1017.dll
C:\WINDOWS\system32\MMSADZFB1048.dll
C:\WINDOWS\system32\ptjhchlp.dll
C:\WINDOWS\system32\winini.exe
C:\WINDOWS\system32\21.exe
c:\net.exe
C:\WINDOWS\system32\DRIVERS\9zp9z1bu51.sys
C:\WINDOWS\system32\drivers\acpidisk.sys
C:\Program Files\Microsoft Office\SYSTEM\apcdli.sys
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp2B.tmp
C:\WINDOWS\TEMP\tmp57.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp24.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp36.tmp
C:\WINDOWS\system32\drivers\msosmsfpfis64.sys
C:\WINDOWS\system32\drivers\msosmsp2p32.sys
C:\WINDOWS\system32\Nessery.sys
C:\WINDOWS\system32\drivers\3C.tmp
C:\WINDOWS\TEMP\tmp54.tmp
C:\WINDOWS\system32\drivers\qpp5v5t.sys
C:\WINDOWS\system32\Drivers\Ryg41.sys
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\25.tmp
C:\WINDOWS\System32\drivers\tcpsr.sys
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp2F.tmp
C:\WINDOWS\system32\lofsajbo.dll
C:\WINDOWS\system32\zycbbime.dll
C:\WINDOWS\system32\ptjhchlp.dll
C:\WINDOWS\system32\yxcschlp.dll
C:\WINDOWS\system32\mndscsrv.dll
C:\WINDOWS\system32\zptlbsys.dll
C:\WINDOWS\system32\zywmdime.dll
C:\WINDOWS\system32\mpmydapi.dll
C:\WINDOWS\system32\zptlcsys.dll
C:\WINDOWS\system32\ypcqdhlp.dll
C:\WINDOWS\system32\zxmsbwin.dll
C:\WINDOWS\system32\zyzxeime.dll
C:\WINDOWS\system32\zyzxfime.dll
C:\WINDOWS\system32\zxptejpg.dll
C:\WINDOWS\system32\lofsajbo.dll
C:\WINDOWS\system32\hhrdxd.dll
C:\WINDOWS\system32\sgrefg.dll
C:\WINDOWS\system32\jfrwdh.dll
C:\WINDOWS\system32\wrqszl.dll
C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys
==================================
启动项目
注册表
<anistio><C:\WINDOWS\anistio.exE> []
<okwzwdto><C:\WINDOWS\kzdoqhwj.exe> []
<TBMExe><C:\WINDOWS\Fonts\92190f07b28bb48ff659b63da52457ba\system\svchost.exe> []
<huifitc><C:\WINDOWS\huifitc.exe> []
<ticisms><C:\WINDOWS\ticisms.exe> []
<bincdwsa><C:\WINDOWS\bincdwsa.exe> []
<{50AF1289-F140-A140-D012-C1458759FC05}><C:\WINDOWS\system32\ypcqdhlp.dll> []
<{4629FF4F-ACDB-5C90-A098-FACB3456A264}><C:\WINDOWS\system32\mpmydapi.dll> []
<{40940F85-F015-14F1-A05F-F69858AC6D04}><C:\WINDOWS\system32\zptlbsys.dll> []
<{50940F85-F015-14F1-A05F-F69858AC6D05}><C:\WINDOWS\system32\zptlcsys.dll> [N/A]
<{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}><C:\WINDOWS\system32\hhrdxd.dll> []
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgrefg.dll> []
<{43C89BF6-6165-4B55-9602-11346DB571DA}><C:\WINDOWS\system32\ztiudy.dll> [N/A]
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> []
<{2A698102-5904-AFD0-20DF-CD1A65829CA2}><C:\WINDOWS\system32\zycbbime.dll> [N/A]
<{35671234-7890-ABCD-CDEF-567801237653}><C:\WINDOWS\system32\yxcschlp.dll> [N/A]
<{F99DEFDD-200B-4410-B572-E90883D527D2}><C:\WINDOWS\system32\wrqszl.dll> []
<{6A59145F-315D-BC23-AC1F-145DF81A34A6}><C:\WINDOWS\system32\zyzxfime.dll> [N/A]
<{1AB1F65A-964F-4AE7-B254-05146A0E602E}><C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys> []
<{37FD640A-158F-48AC-FD14-1597F14A9773}><C:\WINDOWS\system32\mndscsrv.dll> []
<{bae58dbb-1a79-4e18-ac84-07fe296d81c5}><C:\WINDOWS\system32\MMFKKLJK1075.dll> []
<{c4bf46a2-1c05-427d-992f-4e24f7d57f68}><C:\WINDOWS\system32\ttNNBNNB1047.dll> []
<{170165F1-9F65-569F-F895-F14F58F41071}><C:\WINDOWS\system32\lofsajbo.dll> []
<{5A041F13-A111-12A3-B0CF-F99818AA68A5}><C:\WINDOWS\system32\zxmsbwin.dll> []
<{4319A1F1-9410-9654-3201-345FFA349134}><C:\WINDOWS\system32\zywmdime.dll> []
<{42c395b4-2de7-4f52-8020-bf84ff9a66ce}><C:\WINDOWS\system32\MMWLVAHB1017.dll> []
<{b1ffa6d9-4c1f-4b5c-8f22-62b97de67656}><C:\WINDOWS\system32\MMSADZFB1048.dll> []
<{5A59145F-315D-BC23-AC1F-145DF81A34A5}><C:\WINDOWS\system32\zyzxeime.dll> []
<{91698482-6555-3666-1222-954784129019}><C:\WINDOWS\system32\zxptejpg.dll> []
<{328DF602-9541-A985-210A-984A698C6F23}><C:\WINDOWS\system32\ptjhchlp.dll> []
编辑<AppInit_DLLs>的值为空
==================================
删除启动文件夹
[update]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\update.exe --> [N/A]><N>
==================================
删除服务
[Windows Presentation Foundation (WPF) / applications][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k applications-->C:\WINDOWS\system32\GrxhjKsBMxwXPHvBFR.dll><N/A>
[Windows Accounts Driver / windows_2][Running/Auto Start]
<C:\WINDOWS\system32\21.exe><N/A>
[COM+ Windows System / WinINI][Running/Auto Start]
<C:\WINDOWS\system32\winini.exe><Microsoft Corporation>
==================================
删除驱动程序
[9zp9z1bu5 / 9zp9z1bu51][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\9zp9z1bu51.sys><N/A>
[acpidisk / acpidisk][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[apcdli / apcdli][Running/Auto Start]
<\??\C:\Program Files\Microsoft Office\SYSTEM\apcdli.sys><N/A>
[dohs / dohs][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp2B.tmp><N/A>
[fmsq / fmsq][Stopped/Auto Start]
<\??\C:\WINDOWS\TEMP\tmp57.tmp><N/A>
[mhfp / mhfp][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp24.tmp><N/A>
[mnsf / mnsf][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp36.tmp><N/A>
[msfpfis64 / msfpfis64][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosmsfpfis64.sys><N/A>
[msp2p32 / msp2p32][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosmsp2p32.sys><N/A>
[Nessery / Nessery][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Nessery.sys><N/A>
[NPF / NPF][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\3C.tmp><N/A>
[ping / ping][Stopped/Auto Start]
<\??\C:\WINDOWS\TEMP\tmp54.tmp><N/A>
[qpp5v5t / qpp5v5t][Stopped/Boot Start]
<\SystemRoot\system32\drivers\qpp5v5t.sys><N/A>
[Ryg41 / Ryg41][Running/Boot Start]
<\SystemRoot\System32\Drivers\Ryg41.sys><N/A>
[snpshot / snpshot][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\25.tmp><N/A>
[tcpsr / tcpsr][Stopped/Manual Start]
<\??\C:\WINDOWS\System32\drivers\tcpsr.sys><N/A>
[zftp / zftp][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp2F.tmp><N/A>
==================================
删除浏览器加载项
[]
{170165F1-9F65-569F-F895-F14F58F41071} <C:\WINDOWS\system32\lofsajbo.dll, N/A>
[]
{1AB1F65A-964F-4AE7-B254-05146A0E602E} <C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys, N/A>
[]
{2A698102-5904-AFD0-20DF-CD1A65829CA2} <C:\WINDOWS\system32\zycbbime.dll, N/A>
[]
{328DF602-9541-A985-210A-984A698C6F23} <C:\WINDOWS\system32\ptjhchlp.dll, N/A>
[]
{35671234-7890-ABCD-CDEF-567801237653} <C:\WINDOWS\system32\yxcschlp.dll, N/A>
[]
{37FD640A-158F-48AC-FD14-1597F14A9773} <C:\WINDOWS\system32\mndscsrv.dll, N/A>
[]
{40940F85-F015-14F1-A05F-F69858AC6D04} <C:\WINDOWS\system32\zptlbsys.dll, N/A>
[]
{4319A1F1-9410-9654-3201-345FFA349134} <C:\WINDOWS\system32\zywmdime.dll, N/A>
[]
{4629FF4F-ACDB-5C90-A098-FACB3456A264} <C:\WINDOWS\system32\mpmydapi.dll, N/A>
[]
{50940F85-F015-14F1-A05F-F69858AC6D05} <C:\WINDOWS\system32\zptlcsys.dll, N/A>
[]
{50AF1289-F140-A140-D012-C1458759FC05} <C:\WINDOWS\system32\ypcqdhlp.dll, N/A>
[]
{5A041F13-A111-12A3-B0CF-F99818AA68A5} <C:\WINDOWS\system32\zxmsbwin.dll, N/A>
[]
{5A59145F-315D-BC23-AC1F-145DF81A34A5} <C:\WINDOWS\system32\zyzxeime.dll, N/A>
[]
{6A59145F-315D-BC23-AC1F-145DF81A34A6} <C:\WINDOWS\system32\zyzxfime.dll, N/A>
[]
{91698482-6555-3666-1222-954784129019} <C:\WINDOWS\system32\zxptejpg.dll, N/A>
[]
{170165F1-9F65-569F-F895-F14F58F41071} <C:\WINDOWS\system32\lofsajbo.dll, N/A>
[]
{1AB1F65A-964F-4AE7-B254-05146A0E602E} <C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys, N/A>
[]
{2A698102-5904-AFD0-20DF-CD1A65829CA2} <C:\WINDOWS\system32\zycbbime.dll, N/A>
[]
{328DF602-9541-A985-210A-984A698C6F23} <C:\WINDOWS\system32\ptjhchlp.dll, N/A>
[]
{35671234-7890-ABCD-CDEF-567801237653} <C:\WINDOWS\system32\yxcschlp.dll, N/A>
[]
{37FD640A-158F-48AC-FD14-1597F14A9773} <C:\WINDOWS\system32\mndscsrv.dll, N/A>
[]
{40940F85-F015-14F1-A05F-F69858AC6D04} <C:\WINDOWS\system32\zptlbsys.dll, N/A>
[]
{4319A1F1-9410-9654-3201-345FFA349134} <C:\WINDOWS\system32\zywmdime.dll, N/A>
[]
{4629FF4F-ACDB-5C90-A098-FACB3456A264} <C:\WINDOWS\system32\mpmydapi.dll, N/A>
[]
{50940F85-F015-14F1-A05F-F69858AC6D05} <C:\WINDOWS\system32\zptlcsys.dll, N/A>
[]
{50AF1289-F140-A140-D012-C1458759FC05} <C:\WINDOWS\system32\ypcqdhlp.dll, N/A>
[]
{5A041F13-A111-12A3-B0CF-F99818AA68A5} <C:\WINDOWS\system32\zxmsbwin.dll, N/A>
[]
{5A59145F-315D-BC23-AC1F-145DF81A34A5} <C:\WINDOWS\system32\zyzxeime.dll, N/A>
[]
{6A59145F-315D-BC23-AC1F-145DF81A34A6} <C:\WINDOWS\system32\zyzxfime.dll, N/A>
[]
{91698482-6555-3666-1222-954784129019} <C:\WINDOWS\system32\zxptejpg.dll, N/A>
==================================
操作完后用Windows清理助手清理下
再扫个日志上来