建议使用xdelbox删除以下文件
复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,重启删除
c:\windows\ghkt.exe
mmhadpqg1097.dll
c:\windows\system32\tdggrz.dll
c:\windows\system32\jfdses.dll
skqncbib.dll,yzztkmsn.dll,nhmxcjkl.dll
c:\windows\system32\rfdswc.dll
c:\windows\system32\cliconfgzx.dll
c:\windows\system32\zxmsdwin.dll
c:\windows\system32\jfrwdh.dll
c:\windows\system32\kbdswjr.dll
c:\windows\system32\sgrefg.dll
c:\windows\system32\jhfrxz.dll
c:\windows\system32\msobjstl.dll
c:\windows\system32\mnmhgsrv.dll
c:\windows\system32\mfdesy.dll
c:\windows\system32\hhrdxd.dll
c:\windows\system32\ddserh.dll
c:\windows\system32\ozfyebyt.dll
c:\windows\system32\mpwdeapi.dll
c:\windows\system32\yzztkmsn.dll
c:\windows\system32\opshcbty.dll
c:\windows\system32\apzhctde.dll
c:\windows\system32\midimapgj.dll
c:\windows\system32\cedafb.dll
c:\windows\system32\s2da2f323.dll
c:\windows\system32\rijxbkin.dll
c:\windows\system32\skqncbib.dll
c:\windows\system32\mndshsrv.dll
c:\windows\system32\tdffdl.dll
c:\windows\system32\apsggjba.dll
c:\windows\system32\pjjxedwd.dll
c:\windows\system32\yxcschlp.dll
c:\windows\system32\mtewdh.dll
c:\windows\system32\oswxdttb.dll
c:\windows\system32\zptlcsys.dll
c:\windows\system32\nhmxcjkl.dll
c:\program files\internet explorer\plugins\unixsys08.sys
c:\windows\system32\drivers\hdv32_c.sys
2.删除重启后使用sreng修复下面各项: 启动项目 -- 注册表之如下项删除:
[midimapwl] <>
[{4f4f0064-71e0-4f0d-0004-708476c7815f}] <>
[{eaa21495-29ae-4e50-8ad9-a4f877c1ab85}] <mmhadpqg1097.dll>
[{4d165a2a-4bc1-4ca8-8299-08e05aaab5a4}] <c:\windows\system32\tdggrz.dll>
[{81af1cf6-d1c9-4c6a-ac01-ede54e71945b}] <c:\windows\system32\jfdses.dll>
注意该项[appinit_dlls]修改:把<skqncbib.dll,yzztkmsn.dll,nhmxcjkl.dll>修改为<>即清空
[{461d2ab4-29a5-45c2-9134-d52272d3de38}] <c:\windows\system32\rfdswc.dll>
[{00050005-0005-0005-0005-00050005bb15}] <c:\windows\system32\cliconfgzx.dll>
[{7a041f13-a111-12a3-b0cf-f99818aa68a7}] <c:\windows\system32\zxmsdwin.dll>
[{841529cb-7f77-4b99-a895-b5441e0d302f}] <c:\windows\system32\jfrwdh.dll>
[{00120012-0012-0012-0012-00120012bb15}] <c:\windows\system32\kbdswjr.dll>
[{8c41b7f7-3168-400d-a702-0e7efe0ba304}] <c:\windows\system32\sgrefg.dll>
[{7914e0aa-eccb-4311-b584-c49538227824}] <c:\windows\system32\jhfrxz.dll>
[{00170017-0017-0017-0017-00170017bb15}] <c:\windows\system32\msobjstl.dll>
[{7c8d1401-a58d-a81c-cd24-a5915c4517c7}] <c:\windows\system32\mnmhgsrv.dll>
[{dc3d30ae-0380-4151-8934-ee98a34b0370}] <c:\windows\system32\mfdesy.dll>
[{17dfd111-bf3a-4cb4-adb0-88fcbfe69821}] <c:\windows\system32\hhrdxd.dll>
[{a9895933-6636-4281-bc58-ee6de2af96e3}] <c:\windows\system32\ddserh.dll>
[{5a069845-2036-6084-9054-6087502480a5}] <c:\windows\system32\ozfyebyt.dll>
[{55694105-5108-9405-3695-954187462155}] <c:\windows\system32\mpwdeapi.dll>
[{b490415f-65f8-b5c5-d8ba-9405fb12054b}] <c:\windows\system32\yzztkmsn.dll>
[{32596546-2036-9451-6058-658402589723}] <c:\windows\system32\opshcbty.dll>
[{3d698451-2015-6358-9871-2015987452d3}] <c:\windows\system32\apzhctde.dll>
[{4f4f0064-71e0-4f0d-0003-708476c7815f}] <c:\windows\system32\midimapgj.dll>
[{84143967-b645-4bff-b873-da1dc886e9a7}] <c:\windows\system32\cedafb.dll>
[{a629ff4f-acdb-5c90-a098-facb3456a26a}] <c:\windows\system32\s2da2f323.dll>
[{25fd6584-698f-bcd2-602c-698745210352}] <c:\windows\system32\rijxbkin.dll>
[{32023698-6984-8541-9654-698745012523}] <c:\windows\system32\skqncbib.dll>
[{87fd640a-158f-48ac-fd14-1597f14a9778}] <c:\windows\system32\mndshsrv.dll>
[{c0595a7e-2e2f-4b34-a83a-019270a0a464}] <c:\windows\system32\tdffdl.dll>
[{7fd45a54-9875-698f-e56e-65102358fdf7}] <c:\windows\system32\apsggjba.dll>
[{54fae856-ad58-20cb-a025-cd4895fa6e45}] <c:\windows\system32\pjjxedwd.dll>
[{35671234-7890-abcd-cdef-567801237653}] <c:\windows\system32\yxcschlp.dll>
[{189f087f-4378-405f-85fa-37d955ad7a8c}] <c:\windows\system32\mtewdh.dll>
[{43512378-9874-5641-1025-985420368734}] <c:\windows\system32\oswxdttb.dll>
[{50940f85-f015-14f1-a05f-f69858ac6d05}] <c:\windows\system32\zptlcsys.dll>
[{37ac9076-c898-b098-d098-a18319080973}] <c:\windows\system32\nhmxcjkl.dll>
[{74381dec-d78b-43e4-ba5d-5244f669ebe4}] <c:\program files\internet explorer\plugins\unixsys08.sys>
[cliconfgzx.dll] <c:\windows\system32\cliconfgzx.dll>
[kbdswjr.dll] <c:\windows\system32\kbdswjr.dll>
[msobjstl.dll] <c:\windows\system32\msobjstl.dll>
[midimapgj] <c:\windows\system32\midimapgj.dll>
启动项目 -- 服务-- 驱动程序之如下项删除:
[hdv32 / hdv32] <\??\c:\windows\system32\drivers\hdv32_c.sys>
系统修复-- 浏览器加载项之如下项删除:
[] <c:\windows\system32\yzztkmsn.dll>
[] <c:\windows\system32\s2da2f323.dll>
[] <c:\windows\system32\mndshsrv.dll>
[] <c:\windows\system32\apsggjba.dll>
[] <c:\windows\system32\mnmhgsrv.dll>
[] <c:\windows\system32\zxmsdwin.dll>
[] <c:\windows\system32\ozfyebyt.dll>
[] <c:\windows\system32\mpwdeapi.dll>
[] <c:\windows\system32\pjjxedwd.dll>
[] <c:\windows\system32\zptlcsys.dll>
[] <c:\windows\system32\oswxdttb.dll>
[] <c:\windows\system32\apzhctde.dll>
[] <c:\windows\system32\nhmxcjkl.dll>
[] <c:\windows\system32\yxcschlp.dll>
[] <c:\windows\system32\opshcbty.dll>
[] <c:\windows\system32\skqncbib.dll>
[] <c:\windows\system32\rijxbkin.dll>
[] <c:\windows\system32\s2da2f323.dll>
[] <c:\windows\system32\mndshsrv.dll>
[] <c:\windows\system32\apsggjba.dll>
[] <c:\windows\system32\mnmhgsrv.dll>
[] <c:\windows\system32\zxmsdwin.dll>
[] <c:\windows\system32\ozfyebyt.dll>
[] <c:\windows\system32\mpwdeapi.dll>
[] <c:\windows\system32\pjjxedwd.dll>
[] <c:\windows\system32\zptlcsys.dll>
[] <c:\windows\system32\oswxdttb.dll>
[] <c:\windows\system32\apzhctde.dll>
[] <c:\windows\system32\nhmxcjkl.dll>
[] <c:\windows\system32\yxcschlp.dll>
[] <c:\windows\system32\opshcbty.dll>
[] <c:\windows\system32\skqncbib.dll>
[] <c:\windows\system32\rijxbkin.dll>
检测到autorun项
[c:\]
[autorun]
open=system.pif
shellexecute=system.pif
shell\auto\command=system.pif
[e:\]
[autorun]
open=system.pif
shellexecute=system.pif
shell\auto\command=system.pif
[f:\]
[autorun]
open=system.pif
shellexecute=system.pif
shell\auto\command=system.pif
搜索并删除system.pif及cef盘的autorun
c:\windows\ghkt.exe隐藏了进程。