用sreng
删除启动项目=>注册表
<{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}><C:\WINDOWS\system32\hhrdxd.dll> []
<{33512378-9874-5641-1025-985420368733}><C:\WINDOWS\system32\oswxcttb.dll> []
<{1DB3C525-5271-46F7-887A-D4E1ADAA7632}><C:\WINDOWS\system32\hfrdzx.dll> []
<{28EB3777-3E23-4E72-8449-A992D09D24C3}><C:\WINDOWS\system32\zgfdet.dll> []
<{7C8D1401-A58D-A81C-CD24-A5915C4517C7}><C:\WINDOWS\system32\mnmhgsrv.dll> []
<{DC3D30AE-0380-4151-8934-EE98A34B0370}><C:\WINDOWS\system32\mfdesy.dll> []
<{4F4F0064-71E0-4f0d-0014-708476C7815F}><C:\WINDOWS\system32\midimapms.dll> [File is missing]
<{C0595A7E-2E2F-4B34-A83A-019270A0A464}><C:\WINDOWS\system32\tdffdl.dll> []
<{4F4F0064-71E0-4f0d-0005-708476C7815F}><C:\WINDOWS\system32\midimapzx.dll> [File is missing]
<{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}><C:\WINDOWS\system32\wklsdd.dll> []
<{4C648541-1025-9650-9057-6541258720C4}><C:\WINDOWS\system32\mndhddwd.dll> []
<{4F4F0064-71E0-4f0d-0022-708476C7815F}><C:\WINDOWS\system32\midimapqn3.dll> [File is missing]
<{81954FAC-1023-154F-895A-1458258AD818}><C:\WINDOWS\system32\ypdjfbmp.dll> []
<{2D698451-2015-6358-9871-2015987452D2}><C:\WINDOWS\system32\apzhbtde.dll> []
<{4F4F0064-71E0-4f0d-0003-708476C7815F}><C:\WINDOWS\system32\midimapgj.dll> [File is missing]
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> []
<{4F4F0064-71E0-4f0d-0004-708476C7815F}><C:\WINDOWS\system32\midimapwl.dll> [File is missing]
<{35671234-7890-ABCD-CDEF-567801237653}><C:\WINDOWS\system32\yxcschlp.dll> []
<{84143967-B645-4BFF-B873-DA1DC886E9A7}><C:\WINDOWS\system32\cedafb.dll> []
<{4F4F0064-71E0-4f0d-0023-708476C7815F}><C:\WINDOWS\system32\midimapcq.dll> [File is missing]
<{4F4F0064-71E0-4f0d-0012-708476C7815F}><C:\WINDOWS\system32\midimapjr.dll> [File is missing]
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgrefg.dll> []
<{18093456-9012-4568-9076-908765467181}><C:\WINDOWS\system32\tisqatyu.dll> []
<{37AC9076-C898-B098-D098-A18319080973}><C:\WINDOWS\system32\nhmxcjkl.dll> []
<{B29583D8-033A-4B9F-8553-7C5458F3FB8E}><C:\WINDOWS\system32\jdsaex.dll> []
<{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}><C:\WINDOWS\system32\wyrsdj.dll> []
<{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6}><C:\WINDOWS\system32\fsrgeb.dll> []
<{5A069845-2036-6084-9054-6087502480A5}><C:\WINDOWS\system32\ozfyebyt.dll> []
<{4F4F0064-71E0-4f0d-0024-708476C7815F}><C:\WINDOWS\system32\midimapcqsj.dll> [File is missing]
<{461D2AB4-29A5-45C2-9134-D52272D3DE38}><C:\WINDOWS\system32\rfdswc.dll> []
<midimapms><C:\WINDOWS\system32\midimapms.dll> [File is missing]
<midimapzx><C:\WINDOWS\system32\midimapzx.dll> [File is missing]
<midimapqn3><C:\WINDOWS\system32\midimapqn3.dll> [File is missing]
<midimapgj><C:\WINDOWS\system32\midimapgj.dll> [File is missing]
<midimapwl><C:\WINDOWS\system32\midimapwl.dll> [File is missing]
<midimapcq><C:\WINDOWS\system32\midimapcq.dll> [File is missing]
<midimapjr><C:\WINDOWS\system32\midimapjr.dll> [File is missing]
<midimapcqsj><C:\WINDOWS\system32\midimapcqsj.dll> [File is missing]
删除启动项目=>服务
[Plug and Play / PlugPlay][Running/Auto Start]
<C:\WINDOWS\system32\services.exe><Microsoft Corporation>
[IPSEC Services / PolicyAgent][Running/Auto Start]
<C:\WINDOWS\system32\lsass.exe><Microsoft Corporation>
[Protected Storage / ProtectedStorage][Running/Auto Start]
<C:\WINDOWS\system32\lsass.exe><Microsoft Corporation>
[QoS RSVP / RSVP][Stopped/Manual Start]
<C:\WINDOWS\system32\rsvp.exe><Microsoft Corporation>
[Security Accounts Manager / SamSs][Running/Auto Start]
<C:\WINDOWS\system32\lsass.exe><Microsoft Corporation>
[Smart Card / SCardSvr][Stopped/Manual Start]
<C:\WINDOWS\System32\SCardSvr.exe><Microsoft Corporation>
[MS Software Shadow Copy Provider / SwPrv][Stopped/Manual Start]
<C:\WINDOWS\system32\dllhost.exe /Processid:{D29F5BED-E853-426F-8011-64FBD4FAFC14}><Microsoft Corporation>
[Performance Logs and Alerts / SysmonLog][Stopped/Manual Start]
<C:\WINDOWS\system32\smlogsvc.exe><Microsoft Corporation>
[Telnet / TlntSvr][Stopped/Disabled]
<C:\WINDOWS\system32\tlntsvr.exe><Microsoft Corporation>
[Windows User Mode Driver Framework / UMWdf][Stopped/Manual Start]
<C:\WINDOWS\system32\wdfmgr.exe><Microsoft Corporation>
[Volume Shadow Copy / VSS][Stopped/Manual Start]
<C:\WINDOWS\System32\vssvc.exe><Microsoft Corporation>
删除启动项目=>服务=>驱动
[HiddFldy / HiddFldy][Running/Auto Start]
<\??\C:\WINDOWS\system32\d32dx9.sys><N/A>
[IIS Manager / IIS Manager ][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1.tmp><N/A>
删除系统修复=>浏览器加载项
[]
{18093456-9012-4568-9076-908765467181} <C:\WINDOWS\system32\tisqatyu.dll, N/A>
[]
{2D698451-2015-6358-9871-2015987452D2} <C:\WINDOWS\system32\apzhbtde.dll, N/A>
[]
{33512378-9874-5641-1025-985420368733} <C:\WINDOWS\system32\oswxcttb.dll, N/A>
[]
{35671234-7890-ABCD-CDEF-567801237653} <C:\WINDOWS\system32\yxcschlp.dll, N/A>
[]
{37AC9076-C898-B098-D098-A18319080973} <C:\WINDOWS\system32\nhmxcjkl.dll, N/A>
[]
{4C648541-1025-9650-9057-6541258720C4} <C:\WINDOWS\system32\mndhddwd.dll, N/A>
[]
{5A069845-2036-6084-9054-6087502480A5} <C:\WINDOWS\system32\ozfyebyt.dll, N/A>
[]
{7C8D1401-A58D-A81C-CD24-A5915C4517C7} <C:\WINDOWS\system32\mnmhgsrv.dll, N/A>
[]
{81954FAC-1023-154F-895A-1458258AD818} <C:\WINDOWS\system32\ypdjfbmp.dll, N/A>
[]
{18093456-9012-4568-9076-908765467181} <C:\WINDOWS\system32\tisqatyu.dll, N/A>
[]
{2D698451-2015-6358-9871-2015987452D2} <C:\WINDOWS\system32\apzhbtde.dll, N/A>
[]
{33512378-9874-5641-1025-985420368733} <C:\WINDOWS\system32\oswxcttb.dll, N/A>
[]
{35671234-7890-ABCD-CDEF-567801237653} <C:\WINDOWS\system32\yxcschlp.dll, N/A>
[]
{37AC9076-C898-B098-D098-A18319080973} <C:\WINDOWS\system32\nhmxcjkl.dll, N/A>
[]
{4C648541-1025-9650-9057-6541258720C4} <C:\WINDOWS\system32\mndhddwd.dll, N/A>
[]
{5A069845-2036-6084-9054-6087502480A5} <C:\WINDOWS\system32\ozfyebyt.dll, N/A>
[]
{7C8D1401-A58D-A81C-CD24-A5915C4517C7} <C:\WINDOWS\system32\mnmhgsrv.dll, N/A>
[]
{81954FAC-1023-154F-895A-1458258AD818} <C:\WINDOWS\system32\ypdjfbmp.dll, N/A>
启动项目=>注册表
<AppInit_DLLs> 编辑为空值..
重启,删除文件
C:\WINDOWS\system32\hhrdxd.dll
C:\WINDOWS\system32\oswxcttb.dll
C:\WINDOWS\system32\hfrdzx.dll
C:\WINDOWS\system32\zgfdet.dll
C:\WINDOWS\system32\mnmhgsrv.dll
C:\WINDOWS\system32\mfdesy.dll
C:\WINDOWS\system32\midimapms.dll
C:\WINDOWS\system32\tdffdl.dll
C:\WINDOWS\system32\midimapzx.dll
C:\WINDOWS\system32\wklsdd.dll
C:\WINDOWS\system32\mndhddwd.dll
C:\WINDOWS\system32\midimapqn3.dll
C:\WINDOWS\system32\ypdjfbmp.dll
C:\WINDOWS\system32\apzhbtde.dll
C:\WINDOWS\system32\midimapgj.dll
C:\WINDOWS\system32\jfrwdh.dll
C:\WINDOWS\system32\midimapwl.dll
C:\WINDOWS\system32\yxcschlp.dll
C:\WINDOWS\system32\cedafb.dll
C:\WINDOWS\system32\midimapcq.dll
C:\WINDOWS\system32\midimapjr.dll
C:\WINDOWS\system32\sgrefg.dll
C:\WINDOWS\system32\tisqatyu.dll
C:\WINDOWS\system32\nhmxcjkl.dll
C:\WINDOWS\system32\jdsaex.dll
C:\WINDOWS\system32\wyrsdj.dll
C:\WINDOWS\system32\fsrgeb.dll
C:\WINDOWS\system32\ozfyebyt.dll
C:\WINDOWS\system32\midimapcqsj.dll
C:\WINDOWS\system32\rfdswc.dll
C:\WINDOWS\system32\midimapms.dll
C:\WINDOWS\system32\midimapzx.dll
C:\WINDOWS\system32\midimapqn3.dll
C:\WINDOWS\system32\midimapgj.dll
C:\WINDOWS\system32\midimapwl.dll
C:\WINDOWS\system32\midimapcq.dll
C:\WINDOWS\system32\midimapjr.dll
C:\WINDOWS\system32\midimapcqsj.dll
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\rsvp.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\smlogsvc.exe
C:\WINDOWS\system32\tlntsvr.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\d32dx9.sys
C:\WINDOWS\system32\tisqatyu.dll
C:\WINDOWS\system32\apzhbtde.dll
C:\WINDOWS\system32\oswxcttb.dll
C:\WINDOWS\system32\yxcschlp.dll
C:\WINDOWS\system32\nhmxcjkl.dll
C:\WINDOWS\system32\mndhddwd.dll
C:\WINDOWS\system32\ozfyebyt.dll
C:\WINDOWS\system32\mnmhgsrv.dll
C:\WINDOWS\system32\ypdjfbmp.dll
C:\WINDOWS\system32\tisqatyu.dll
C:\WINDOWS\system32\apzhbtde.dll
C:\WINDOWS\system32\oswxcttb.dll
C:\WINDOWS\system32\yxcschlp.dll
C:\WINDOWS\system32\nhmxcjkl.dll
C:\WINDOWS\system32\mndhddwd.dll
C:\WINDOWS\system32\ozfyebyt.dll
C:\WINDOWS\system32\mnmhgsrv.dll
C:\WINDOWS\system32\ypdjfbmp.dll