用sreng
删除启动项目=>注册表
<HTpatch><C:\WINDOWS\htpatch.exe> []
<{A393C2CF-1C26-4309-9765-13B7FDC0F200}><C:\WINDOWS\system32\mypern0.dll> []
<{2598FF45-DA60-F48A-BC43-10AC47853D52}><C:\WINDOWS\system32\rarjbpi.dll> []
<{2960356A-458E-DE24-BD50-268F589A56A2}><C:\WINDOWS\system32\avwlbmn.dll> []
<{334345F1-DACF-3452-CB7D-4620F34A1533}><C:\WINDOWS\system32\rsztcpm.dll> []
<{57D81718-1314-5200-2597-587901018075}><C:\WINDOWS\system32\kaqhezy.dll> []
<{3C87A354-ABC3-DEDE-FF33-3213FD7447C3}><C:\WINDOWS\system32\kvdxcma.dll> []
<{66650011-3344-6688-4899-345FABCD1566}><C:\WINDOWS\system32\ratbfpi.dll> []
<{4859245F-345D-BC13-AC4F-145D47DA34F4}><C:\WINDOWS\system32\avzxdmn.dll> []
<{18847374-8323-FADC-B443-4732ABCD3781}><C:\WINDOWS\system32\sidjazy.dll> []
<{28907901-1416-3389-9981-372178569982}><C:\WINDOWS\system32\kawdbzy.dll> []
<{444D7AB0-639D-445F-9143-3B3FFB2A7F39}><C:\WINDOWS\system32\dh3vpw1.dll> []
<{0F7A277A-4B2A-4673-8CC0-957C72ECFC6E}><C:\Program Files\Internet Explorer\Info_Ms.Sys> []
<{5B681598-AD5F-BC8C-77DC-748FAC8D3FB5}><C:\WINDOWS\system32\kafyezy.dll> []
<{2D561258-45F3-A451-F908-A258458226D2}><C:\WINDOWS\system32\kvdxsbma.dll> []
<{2A321487-4977-D98A-C8D5-6488257545A2}><C:\WINDOWS\system32\kapjbzy.dll> []
<{C5E87A05-F463-4841-B19E-DD3EC3862368}><C:\Program Files\Internet Explorer\IEXPLORE32.Sys> []
<{EE12D60D-AD9A-4095-B839-3BE6862679FD}><C:\Program Files\Internet Explorer\IEXPLORE32.Dat> []
<{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}><C:\Program Files\Internet Explorer\IEXPLORE32.win> []
启动项目=>注册表
<AppInit_DLLs> 编辑为空值
重启进入安全模式.
删除文件
C:\WINDOWS\htpatch.exe
C:\WINDOWS\system32\mypern0.dll
C:\WINDOWS\system32\rarjbpi.dll
C:\WINDOWS\system32\avwlbmn.dll
C:\WINDOWS\system32\rsztcpm.dll
C:\WINDOWS\system32\kaqhezy.dll
C:\WINDOWS\system32\kvdxcma.dll
C:\WINDOWS\system32\ratbfpi.dll
C:\WINDOWS\system32\avzxdmn.dll
C:\WINDOWS\system32\sidjazy.dll
C:\WINDOWS\system32\kawdbzy.dll
C:\WINDOWS\system32\dh3vpw1.dll
C:\Program Files\Internet Explorer\Info_Ms.Sys
C:\WINDOWS\system32\kafyezy.dll
C:\WINDOWS\system32\kvdxsbma.dll
C:\WINDOWS\system32\kapjbzy.dll
C:\Program Files\Internet Explorer\IEXPLORE32.Sys
C:\Program Files\Internet Explorer\IEXPLORE32.Dat
C:\Program Files\Internet Explorer\IEXPLORE32.win
右键 打开 E盘
删除
AutoRun.exe
Autorun.inf