1.建议使用XDelBox删除以下文件:(
XDelBox1.6下载)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
c:\windows\driver..\daemon.exe
c:\windows\system32\zywmiime.dll
c:\windows\system32\yxcsdhlp.dll
c:\windows\system32\zywldime.dll
c:\windows\system32\mnmhhsrv.dll
c:\windows\system32\detxeiua.dll
c:\windows\system32\mndsisrv.dll
c:\windows\system32\apzhdtde.dll
c:\windows\system32\apsghjba.dll
c:\windows\system32\hdf453d1.dll
c:\windows\downlo~1\e86b.dll
c:\windows\system32\tisqdtyu.dll
c:\windows\system32\ypdjhbmp.dll
c:\windows\system32\arjrkler.dll
c:\windows\system32\ypcqhhlp.dll
c:\windows\system32\ietzdpaq.dll
c:\windows\system32\midimappt.dll
c:\windows\system32\yzztnmsn.dll
c:\windows\system32\dispexcb.dll
c:\windows\system32\wmpuiqhx.dll
c:\windows\system32\catsrvwl.dll
c:\windows\system32\ksuserfy.dll
c:\windows\system32\cliconfgzx.dll
c:\windows\system32\adsntzt.dll
c:\windows\system32\dpvvoxmh.dll
c:\windows\system32\tscfgwmijxsj.dll
c:\windows\wuauclt.exe
c:\windows\avtapit.dll
c:\windows\system32\drivers\7of7ng.sys
c:\windows\system32\drivers\beep.sys
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[{4A698102-5904-AFD0-20DF-CD1A65829CA4}] <>
[{8A041F13-A111-12A3-B0CF-F99818AA68A8}] <>
[{6A908760-8000-4000-A000-9000322145A6}] <>
[{57AC9076-C898-B098-D098-A18319080975}] <>
[{528DF602-9541-A985-210A-984A698C6F25}] <>
[{AA59145F-315D-BC23-AC1F-145DF81A34AA}] <>
[{6C648541-1025-9650-9057-6541258720C6}] <>
[{14698742-2059-3025-9058-954023874141}] <>
[{2B69874A-C58C-458D-69F0-698F874E41B2}] <>
[{7C954872-1230-6541-9548-6541025884C7}] <>
[{55694105-5108-9405-3695-954187462155}] <>
[{91698482-6555-3666-1222-954784129019}] <>
[{50940F85-F015-14F1-A05F-F69858AC6D05}] <>
[{2A698452-C5D8-C584-C256-C264C987C5A2}] <>
[{5D098345-6785-1098-5413-678067AE03D5}] <>
[{32596546-2036-9451-6058-658402589723}] <>
[{25FD6584-698F-BCD2-602C-698745210352}] <>
[user] <C:\WINDOWS\Driver..\daemon.exe>
[load] <C:\WINDOWS\system\rundll32.exe>
[{9319A1F1-9410-9654-3201-345FFA349139}] <C:\WINDOWS\system32\zywmiime.dll>
[{45671234-7890-ABCD-CDEF-567801237654}] <C:\WINDOWS\system32\yxcsdhlp.dll>
[360Safetray] <; >
[{47A924AF-1A5F-CF21-AB1D-1D5CF82A8A74}] <C:\WINDOWS\system32\zywldime.dll>
[{8C8D1401-A58D-A81C-CD24-A5915C4517C8}] <C:\WINDOWS\system32\mnmhhsrv.dll>
[{50618412-C528-C784-C056-C164D1F7C505}] <C:\WINDOWS\system32\detxeiua.dll>
[{97FD640A-158F-48AC-FD14-1597F14A9779}] <C:\WINDOWS\system32\mndsisrv.dll>
[{4D698451-2015-6358-9871-2015987452D4}] <C:\WINDOWS\system32\apzhdtde.dll>
[{8FD45A54-9875-698F-E56E-65102358FDF8}] <C:\WINDOWS\system32\apsghjba.dll>
[{C629FF4F-ACDB-5C90-A098-FACB3456A26C}] <C:\WINDOWS\system32\hdf453d1.dll>
[e86b] <rundll32 "C:\WINDOWS\Downlo~1\e86b.dll",Run>
[{48093456-9012-4568-9076-908765467184}] <C:\WINDOWS\system32\tisqdtyu.dll>
[{A1954FAC-1023-154F-895A-1458258AD81A}] <C:\WINDOWS\system32\ypdjhbmp.dll>
[{DC69134A-F15F-D14D-A31A-C31C4D124FCD}] <C:\WINDOWS\system32\arjrkler.dll>
[{90AF1289-F140-A140-D012-C1458759FC09}] <C:\WINDOWS\system32\ypcqhhlp.dll>
[{49109876-7619-9101-7012-901938475194}] <C:\WINDOWS\system32\ietzdpaq.dll>
[{4F4F0064-71E0-4f0d-0021-708476C7815F}] <C:\WINDOWS\system32\midimappt.dll>
注意该项[Userinit]修改:把<C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system\rundll32.exe,>修改为<C:\WINDOWS\system32\userinit.exe,>逗号不可省略
[{E490415F-65F8-B5C5-D8BA-9405FB12054E}] <C:\WINDOWS\system32\yzztnmsn.dll>
[{00060006-0006-0006-0006-00060006BB15}] <C:\WINDOWS\system32\dispexcb.dll>
[{00270027-0027-0027-0027-00270027BB15}] <C:\WINDOWS\system32\wmpuiqhx.dll>
[{00040004-0004-0004-0004-00040004BB15}] <C:\WINDOWS\system32\catsrvwl.dll>
[{00130013-0013-0013-0013-00130013BB15}] <C:\WINDOWS\system32\ksuserfy.dll>
[{00050005-0005-0005-0005-00050005BB15}] <C:\WINDOWS\system32\cliconfgzx.dll>
[{00010001-0001-0001-0001-00010001BB15}] <C:\WINDOWS\system32\adsntzt.dll>
[{00070007-0007-0007-0007-00070007BB15}] <C:\WINDOWS\system32\dpvvoxmh.dll>
[{00330033-0033-0033-0033-00330033BB15}] <C:\WINDOWS\system32\tscfgwmijxsj.dll>
[midimappt] <C:\WINDOWS\system32\midimappt.dll>
[dispexcb.dll] <C:\WINDOWS\system32\dispexcb.dll>
[wmpuiqhx.dll] <C:\WINDOWS\system32\wmpuiqhx.dll>
[catsrvwl.dll] <C:\WINDOWS\system32\catsrvwl.dll>
[ksuserfy.dll] <C:\WINDOWS\system32\ksuserfy.dll>
[cliconfgzx.dll] <C:\WINDOWS\system32\cliconfgzx.dll>
[adsntzt.dll] <C:\WINDOWS\system32\adsntzt.dll>
[dpvvoxmh.dll] <C:\WINDOWS\system32\dpvvoxmh.dll>
[tscfgwmijxsj.dll] <C:\WINDOWS\system32\tscfgwmijxsj.dll>
[Load] <; C:\WINDOWS\system\rundll32.exe>
启动项目 -- 服务 -- Win32服务应用程序之如下项禁用:
[NvnwWkf / NvnwWkf] <C:\WINDOWS\wuauclt.exe>
[MszbKdq / MszbKdq] <C:\WINDOWS\wuauclt.exe>
[LlqiEoz / LlqiEoz] <C:\WINDOWS\wuauclt.exe>
[WbWin / WbWin] <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\avtapit.dll>
[Remote Procedure Call Locator / RpcUsnsvc] <>
启动项目 -- 服务-- 驱动程序之如下项禁用:
[7of7ng / 7of7ng] <\SystemRoot\System32\DRIVERS\7of7ng.sys>
[Beep / Beep] <\??\C:\WINDOWS\system32\Drivers\Beep.sys>