请按下面操作完成:1.建议使用XDelBox(下载地址:http://bbs.ikaka.com/attachment.aspx?attachmentid=446806)
删除以下文件:(使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择剪贴板导入不检查路径,导入后记得勾选抑制其再生,在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储设备)C:\WINDOWS\system32\System.exe
C:\WINDOWS\system32\csrss.dll
C:\WINDOWS\system32\sh14024.dll
C:\WINDOWS\system32\sh23012.dll
C:\WINDOWS\system32\sh27012.dll
C:\WINDOWS\system32\HBWOW.dll
C:\WINDOWS\system32\HBJXSJ.dll
C:\WINDOWS\system32\2EF0D734.dll
C:\WINDOWS\system32\08223B03.dll
C:\WINDOWS\system32\DA63E650.dll
C:\WINDOWS\system32\4FBFD5A4.dll
C:\WINDOWS\system32\DFB3DAC5.dll
C:\WINDOWS\system32\122B901E.dll
C:\WINDOWS\system32\5934EA2B.dll
C:\WINDOWS\system32\56BC86C7.dll
C:\Program Files\Internet Explorer\Sys6NtMe.Zys
C:\WINDOWS\system32\A1A6BC2E.dll
C:\WINDOWS\system32\C8FFD223.dll
C:\WINDOWS\system32\E0D39066.dll
C:\WINDOWS\system32\E4814792.dll
C:\WINDOWS\system32\BA7EDF54.dll
C:\WINDOWS\system32\9CA963CA.dll
C:\WINDOWS\system32\E1384213.dll
C:\WINDOWS\system32\HBmhly.dll
C:\WINDOWS\system32\HBCHIBI.dll
C:\WINDOWS\system32\HBDNF.dll
C:\WINDOWS\system32\HBTL.dll
C:\WINDOWS\system32\HBQQSG.dll
C:\WINDOWS\system32\HBQQFFO.dll
C:\WINDOWS\system32\HBWD.dll
C:\WINDOWS\system32\HBXMJ.dll
C:\WINDOWS\system32\A1A6BC2E.dll
C:\WINDOWS\system32\2EF0D734.dll
2.启动项目 -- 注册表之如下项删除:[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<MsnMsgr><"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
<autoclk><autoclk.exe> []
<CnxDslTaskBar><"c:\program files\conexant\accessrunner adsl usb\CnxDslTb.exe" "Conexant\AccessRunner ADSL USB"> [File is missing]
<GEST><m搢\?> [File is missing]
<HBService32><System.exe> []
<ctfmon><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\801298> []
<AppInit_DLLs><HBWOW.dll,HBJXSJ.dll,kmon.dll,HBmhly.dll,HBCHIBI.dll,HBDNF.dll,HBTL.dll,HBQQSG.dll,HBQQFFO.dll,HBWD.dll,HBXMJ.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8}><A1A6BC2E.dll> []
<{FFAE967F-D0FC-4D2B-A0F5-D1BF27F46418}><FFAE967F.dll> [N/A]
<{56BC86C7-0692-4F94-A2C1-6CF1DBF8096C}><56BC86C7.dll> []
<{5934EA2B-B2C4-4BE7-BF7A-FBA781A12E40}><5934EA2B.dll> []
<{16AF66EB-93C8-49F9-BB09-B4F87CEDCE46}><16AF66EB.dll> [N/A]
<{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}><122B901E.dll> []
<{DFB3DAC5-B0B5-4B05-BFCF-FB42737778FA}><DFB3DAC5.dll> []
<{4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96}><4FBFD5A4.dll> []
<{C8FFD223-C0FB-40C5-94A0-FD7891AC18E9}><C8FFD223.dll> []
<{DA63E650-537C-4042-87BB-9D19D844680B}><DA63E650.dll> []
<{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}><08223B03.dll> []
<{E0D39066-96D7-4891-8527-488ADAFCD60F}><E0D39066.dll> []
<{E4814792-EFA3-4C20-93D0-8B130A59F9A8}><E4814792.dll> []
<{BA7EDF54-8408-4B21-B351-7B447B344BA4}><BA7EDF54.dll> []
<{9CA963CA-107C-4089-B0AB-31380F90D7E3}><9CA963CA.dll> []
<{2EF0D734-21FD-4225-A1A2-BCD296182AAF}><2EF0D734.dll> []
<{D9C002DD-EA51-43A2-9009-54EAAAF031A4}><D9C002DD.dll> [N/A]
<{A93061FE-464A-4E95-8E96-A54CD948B0F7}><C:\Program Files\Internet Explorer\Sys6NtMe.Zys> []
<{E1384213-0948-4A60-A9E3-875B191CC2E7}><E1384213.dll> []
将 <AppInit_DLLs><HBWOW.dll,HBJXSJ.dll,kmon.dll,HBmhly.dll,HBCHIBI.dll,HBDNF.dll,HBTL.dll,HBQQSG.dll,HBQQFFO.dll,HBWD.dll,HBXMJ.dll> []
改为
<AppInit_DLLs><kmon.dll>3.启动项目 -- 服务-- 驱动程序之如下项删除:
SREng-在"启动项目->服务->驱动程序中"选中"隐藏已认证的微软项目"然后删除下面名称的驱动程序(选中有问题的驱动后,点"删除服务",点“设置”按钮即可。注意弹出的窗口中要点 "否NO"才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置):[aliimz / aliimz][Stopped/Manual Start]
<System32\Drivers\aliimz.sys><N/A>
[HBKernel32 Driver / HBKernel32][Stopped/Boot Start]
<\SystemRoot\system32\drivers\HBKernel32.sys><N/A>
[b1a18a3e / b1a18a3e][Running/Manual Start]
<\??\C:\WINDOWS\system32\b1a18a3e.sys><N/A>
[Kisstusb / Kisstusb][Running/]
<2 - 系统找不到指定的文件。
><N/A>
4.系统修复——浏览器加载项之如下项删除:(2处)[]
{A93061FE-464A-4E95-8E96-A54CD948B0F7} <C:\Program Files\Internet Explorer\Sys6NtMe.Zys, N/A>
[]
{A93061FE-464A-4E95-8E96-A54CD948B0F7} <C:\Program Files\Internet Explorer\Sys6NtMe.Zys, N/A>
5.运行下载的删除映像劫持工具,清除检测到的所有映像劫持项:http://bbs.ikaka.com/attachment.aspx?attachmentid=4295616.将附件里文件解压后覆盖至C:\WINDOWS\system32\dllcache和C:\WINDOWS\system32\文件夹。7.用下载的“清理临时文件工具ATF-Cleaner-cn”,全选所有项目,点击“立即清理”
下载:
http://bbs.ikaka.com/attachment.aspx?attachmentid=447126用W i n d o w s 清理助手 ,清理系统。W i n d o w s 清理助手 下载:
http://www.arswp.com/hosts文件内容可以忽视掉,具有点小免疫作用。