断开网络
删除以下注册表项目
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HBmhly><"C:\WINDOWS\system32\HBmhly.exe" -r> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{DC3D30AE-0380-4151-8934-EE98A34B0370}><C:\WINDOWS\system32\mfdesy.dll> []
<{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}><C:\WINDOWS\system32\wklsdd.dll> []
<{00170017-0017-0017-0017-00170017BB15}><C:\WINDOWS\system32\msobjstl.dll> [File is missing]
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgdewg.dll> []
<{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}><C:\WINDOWS\system32\hhrdxd.dll> []
<{45AADFAA-DD36-42AB-83AD-0521BBF58C24}><C:\WINDOWS\system32\zycdex.dll> [File is missing]
<{461D2AB4-29A5-45C2-9134-D52272D3DE38}><C:\WINDOWS\system32\rfdswc.dll> []
<{A9895933-6636-4281-BC58-EE6DE2AF96E3}><C:\WINDOWS\system32\ddserh.dll> []
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> []
<{B29583D8-033A-4B9F-8553-7C5458F3FB8E}><C:\WINDOWS\system32\jdsaex.dll> [File is missing]
<{7914E0AA-ECCB-4311-B584-C49538227824}><C:\WINDOWS\system32\jhfrxz.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<cliconfgzx.dll><> [N/A]
<dpvvoxmh.dll><> [N/A]
<kbdswjr.dll><C:\WINDOWS\system32\kbdswjr.dll> [File is missing]
<catsrvwl.dll><> [N/A]
<adsntzt.dll><> [N/A]
<ksuserfy.dll><C:\WINDOWS\system32\ksuserfy.dll> [File is missing]
<tscfgwmijxsj.dll><> [N/A]
<midimappt><> [N/A]
<msobjstl.dll><C:\WINDOWS\system32\msobjstl.dll> [File is missing]
<imgutilhx2.dll><C:\WINDOWS\system32\imgutilhx2.dll> [File is missing]
删除以下驱动项目
[2gkf6 / 2gkf67][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\2gkf67.sys><>
[9dcf4a6429e9a9fc / 9dcf4a6429e9a9fc][Stopped/Manual Start]
<\??\C:\9dcf4a6429e9a9fc.dat><N/A>
[bpqcxby / bpqcxby][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\bpqcxby.sys><N/A>
[byoprxa / byoprxa][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\byoprxa.sys><N/A>
[cabyopr / cabyopr][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\cabyopr.sys><N/A>
[cxbyqpr / cxbyqpr][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\cxbyqpr.sys><N/A>
[cxyqr / cxyqr][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\cxyqr.sys><N/A>
[hxgo6gtuz / hxgo6gtuz7][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\hxgo6gtuz7.sys><N/A>
[kc1 / kc1w][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\kc1w.sys><N/A>
[qrxabzp / qrxabzp][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\qrxabzp.sys><N/A>
[rxabzpc / rxabzpc][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\rxabzpc.sys><N/A>
[turol / turol][Stopped/Manual Start]
<\??\C:\DOCUME~1\Owner\LOCALS~1\Temp\_tmp.bat><N/A>
[xayzpqa / xayzpqa][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\xayzpqa.sys><N/A>
[xboqpxa / xboqpxa][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\xboqpxa.sys><N/A>
[ybpqcxb / ybpqcxb][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\ybpqcxb.sys><N/A>
[ybzqcab / ybzqcab][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\ybzqcab.sys><N/A>
[yqprayb / yqprayb][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\yqprayb.sys><N/A>
[yzpqaxb / yzpqaxb][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\yzpqaxb.sys><N/A>
[zpqaxbo / zpqaxbo][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\zpqaxbo.sys><N/A>
[zpqcxbo / zpqcxbo][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\zpqcxbo.sys><N/A>
[zqcab / zqcab][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\zqcab.sys><N/A>
[zqcabyo / zqcabyo][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\zqcabyo.sys><N/A>
[raybp / raybp][Running/Manual Start]
<\??\C:\WINDOWS\system32\drivers\raybp.sys><N/A>
[yqrab / yqrab][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\yqrab.sys><N/A>
[pcxyq / pcxyq][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\pcxyq.sys><N/A>
清理注册表加载项
[]
{74381DEC-D78B-43E4-BA5D-5244F669EBE4} <C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys, N/A>
[]
{74381DEC-D78B-43E4-BA5D-5244F669EBE4} <C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys, N/A>
删除以下项目
[C:\WINDOWS\system32\tdfhex.dll]
[C:\WINDOWS\system32\wrqszl.dll]
[C:\WINDOWS\system32\wyhesm.dll]
[C:\WINDOWS\system32\zefdst.dll]
[C:\WINDOWS\system32\rfdswc.dll]
[C:\WINDOWS\system32\hhrdxd.dll]
[C:\WINDOWS\system32\sgdewg.dll]
[C:\WINDOWS\system32\ddserh.dll]
[C:\WINDOWS\system32\fsrgeb.dll]
[C:\WINDOWS\system32\mfdesy.dll]
[C:\WINDOWS\system32\jfrwdh.dll]
[C:\WINDOWS\system32\jggtsr.dll]
[C:\WINDOWS\system32\tdggrz.dll]
[C:\WINDOWS\system32\tdffdl.dll]
[C:\WINDOWS\system32\pedadt.dll]
[C:\WINDOWS\system32\jhfrxz.dll]
[C:\WINDOWS\system32\dndsaf.dll]
[C:\WINDOWS\system32\fmcvxy.dll]
下载附件 清理被ifeo劫持项
重启计算机 使用清理助手清理
联网 升级杀毒软件 全盘查杀