开始-运行
dllcache
找到ctfmon.exe
复制,替换System32,windos文件夹下其同名文件
修改注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)(HBmhly.dll) []
为<AppInit_DLLs><>
删除启动项
(HBService)(Rundll32.exe HBmhly.dll,StartService) []
({AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A})() [N/A]
({383D0D27-789F-4543-9760-D4E199623476})() [N/A]
({5A1247C1-53DA-FF43-ABD3-345F323A48D5})(C:\WINNT\system32\avwgemn.dll) [File is missing]
({09F8A0EB-ED61-4714-B0AD-7EAFF5361A8B})(C:\WINNT\system32\zhjtrx.dll) [File is missing]
({B0E4D1E9-3CE5-48A1-8DF0-6463E046E7EF})(C:\WINNT\system32\ucjsyflqwc.dll) [File is missing]
({5859245F-345D-BC13-AC4F-145D47DA34F5})(C:\WINNT\system32\avzxemn.dll) [File is missing]
({DC3D30AE-0380-4151-8934-EE98A34B0370})(C:\WINNT\system32\mfdesy.dll) [File is missing]
({28EB3777-3E23-4E72-8449-A992D09D24C3})(C:\WINNT\system32\zefdst.dll) [File is missing]
({28766E1C-74B0-4417-8C75-F12AE309EF35})(C:\WINNT\system32\wzcfsw.dll) [File is missing]
({18e64250-19a8-4d10-828f-30e101a22291})(C:\WINNT\system32\MMBAIKOK1092.dll) [File is missing]
({461D2AB4-29A5-45C2-9134-D52272D3DE38})(C:\WINNT\system32\rfdswc.dll) [File is missing]
({8c3dd05d-a6a1-4cb5-a714-94be3c3b4cd0})(C:\WINNT\system32\MMHADPQG1091.dll) [File is missing]
({8AD0F1B1-990D-4F52-A33D-2837E43CEF58})(C:\Program Files\Internet Explorer\PLUGINS\DosSys08.Sys) [File is missing]
({d592daa6-9b5e-416d-973a-d76c53183e7e})(C:\WINNT\system32\MMMHXGGD1062.dll) [File is missing]
({E8A3B193-77E3-4FB3-986D-F4FA4828BAFC})(C:\WINNT\system32\wklsdd.dll) [File is missing]
({6E6CA8A1-81BC-4707-A54C-F4903DD70BAD})(C:\WINNT\system32\zgxfdx.dll) [File is missing]
({84143967-B645-4BFF-B873-DA1DC886E9A7})(C:\WINNT\system32\cedafb.dll) [File is missing]
({F99DEFDD-200B-4410-B572-E90883D527D2})(C:\WINNT\system32\wrqszl.dll) [File is missing]
({011DB9B9-44B4-44D9-B17E-BC7608F2E549})(C:\WINNT\system32\cdwqfs.dll) [File is missing]
({841529CB-7F77-4B99-A895-B5441E0D302F})(C:\WINNT\system32\jfrwdh.dll) [File is missing]
({17DFD111-BF3A-4CB4-ADB0-88FCBFE69821})(C:\WINNT\system32\hhrdxd.dll) [File is missing]
({4D165A2A-4BC1-4CA8-8299-08E05AAAB5A4})(C:\WINNT\system32\tdggrz.dll) [File is missing]
({189F087F-4378-405F-85FA-37D955AD7A8C})(C:\WINNT\system32\mtewdh.dll) [File is missing]
({8C41B7F7-3168-400D-A702-0E7EFE0BA304})(C:\WINNT\system32\sgdewg.dll) [File is missing]
({81AF1CF6-D1C9-4C6A-AC01-EDE54E71945B})(C:\WINNT\system32\jfdses.dll) [File is missing]
({C362D1C3-313C-41C8-A0C7-45458CD8D9A9})(C:\WINNT\system32\mghefy.dll) [File is missing]
({C0595A7E-2E2F-4B34-A83A-019270A0A464})(C:\WINNT\system32\tdffdl.dll) [File is missing]
({A9895933-6636-4281-BC58-EE6DE2AF96E3})(C:\WINNT\system32\ddserh.dll) [File is missing]
({0B846B26-BFE6-4E8E-A948-1DB17B77B483})(C:\WINNT\system32\tdfhex.dll) [File is missing]
({EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6})(C:\WINNT\system32\fsrgeb.dll) [File is missing]
({45AADFAA-DD36-42AB-83AD-0521BBF58C24})(C:\WINNT\system32\zycdex.dll) [File is missing]
({50A8A8C4-EDC9-4ABD-A0A2-2E2418982189})(C:\WINNT\system32\kgfghd.dll) [File is missing]
({259BF3CF-194D-4FE6-9ADB-DE6544B098B6})(C:\WINNT\system32\dndsaf.dll) [File is missing]
({5E907A48-400E-4EA8-9792-FFAE052D59E9})(C:\WINNT\system32\pedadt.dll) [File is missing]
({0086DD39-EB8E-4504-A085-AC8A433E34D0})(C:\WINNT\system32\ydggsx.dll) [File is missing]
({73AE86E6-7F03-4C3B-8980-FB1DA157D3C7})(C:\WINNT\system32\fmcvxy.dll) [File is missing]
({00070007-0007-0007-0007-00070007BB15})(C:\WINNT\system32\dpvvoxmh.dll) [File is missing]
({74381DEC-D78B-43E4-BA5D-5244F669EBE4})(C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys) [File is missing]
({AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A})() [N/A]
({383D0D27-789F-4543-9760-D4E199623476})() [N/A]
({5A1247C1-53DA-FF43-ABD3-345F323A48D5})(C:\WINNT\system32\avwgemn.dll) [File is missing]
({09F8A0EB-ED61-4714-B0AD-7EAFF5361A8B})(C:\WINNT\system32\zhjtrx.dll) [File is missing]
({B0E4D1E9-3CE5-48A1-8DF0-6463E046E7EF})(C:\WINNT\system32\ucjsyflqwc.dll) [File is missing]
({5859245F-345D-BC13-AC4F-145D47DA34F5})(C:\WINNT\system32\avzxemn.dll) [File is missing]
(kbdswjr)(C:\WINNT\system32\kbdswjr.dll) [File is missing]
(adsntzt)(C:\WINNT\system32\adsntzt.dll) [File is missing]
(cliconfgzx)(C:\WINNT\system32\cliconfgzx.dll) [File is missing]
(rasmanqn3)(C:\WINNT\system32\rasmanqn3.dll) [File is missing]
(dpvvoxmh.dll)(C:\WINNT\system32\dpvvoxmh.dll) [File is missing]
删除服务
[E2379CDF / E2379CDF][Stopped/Auto Start]
(C:\WINNT\system32\53D6D4B2.EXE -d)((File is missing))
删除驱动及对应文件
[adaadb8095287398 / adaadb8095287398][Stopped/Manual Start]
(\??\C:\adaadb8095287398.dat)(N/A)
[dohs / dohs][Stopped/Auto Start]
(\??\E:\Temp\tmp609.tmp)(N/A)
(\SystemRoot\System32\DRIVERS\lc498.sys)(N/A)
[mnsf / mnsf][Stopped/Auto Start]
(\??\E:\Temp\tmp619.tmp)(N/A)
[pqnkg / pqnkg][Stopped/Manual Start]
(\??\E:\Temp\_tmp.bat)(N/A)
[tqnkl / tqnkl][Stopped/Manual Start]
(\??\E:\Temp\_tmp.bat)(N/A)
[zctp / zctp][Stopped/Auto Start]
(\??\E:\Temp\tmp629.tmp)(N/A)
[R2A / R2A][Stopped/Disabled]
(\??\C:\WINNT\system32a2.sys)(N/A)
删除浏览器加载项
[]
{74381DEC-D78B-43E4-BA5D-5244F669EBE4} (C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys, N/A)
[]
{7C8D1401-A58D-A81C-CD24-A5915C4517C7} (C:\WINNT\system32\mnmhgsrv.dll, N/A)
并用Windos清理助手,完美卸载清理计算机
用附件清除映像劫持