1.从c:\windows\system32\dllcache\下复制Explorer.exe文件替换c:\windows\下原文件
2,用SRE修复以下:
启动项目 -- 服务 -- Win32服务应用程序之如下项禁用:
[B302EC43 / B302EC43]
[TSECleanUpAssist / TSECleanUpAssist]
[Windows Driver Foundation - User-mode Driver Framework / WudfSvc]
[MPSVC Service / MPSVCService]
启动项目 -- 服务-- 驱动程序之如下项禁用:
[XDva019 / XDva019]
[pop / pop]
[npkycryp / npkycryp]
[msskye / msskye]
[mseqsy / mseqsy]
[ADProt / ADProt]
3.用XDelBox以抑制再生方式删除以下文件:(
XDelBox1.6下载)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
c:\windows\fonts\avzxomn.dll
c:\windows\fonts\rsjzbpm.dll
c:\windows\fonts\rarjfpi.dll
c:\windows\kvsc3.exe
c:\windows\upxdnd.exe
c:\windows\49400m.exe
c:\windows\wsockdrv32.exe
c:\windows\msprint32d.exe
c:\windows\dbghlp32.exe
c:\windows\ptsshell.exe
c:\windows\lotushlp.exe
c:\windows\system32\75d23be4.exe -d
c:\windows\system32\6a98.com
c:\windows\system32\wudfsvc.dll
c:\windows\system32\xdva019.sys
c:\windows\system32\drivers\pop.sys
c:\windows\system32\npkycryp.sys
c:\windows\system32\drivers\msaclue.sys
c:\windows\system32\drivers\msacpe.sys
c:\windows\system32\atspy.sys
c:\windows\system32\drivers\adprot.sys
c:\program files\internet explorer\plugins\nvsys_55.sys
c:\windows\system32\tdc.ocx
c:\windows\wiasoisao.exe
c:\windows\system32\f0d78d11.dll
c:\windows\system32\gamelink.dll
c:\windows\kiefncol.dll
c:\windows\mdgvrhlm.dll
c:\windows\system32\kizqnz.dll
c:\windows\system32\kqnkeh.dll
c:\windows\system32\lxjiip.dll
c:\windows\system32\niqwli.dll
c:\windows\system32\quryrn.dll
c:\windows\system32\yxtgct.dll
c:\windows\dmgdmgqv.dll
c:\windows\system32\kvsc3.dll
C:\WINDOWS\MDGVRHLM.EXE
4.删除重启后使用SREng修复下面各项:
启动项目 -- 注册表之如下项删除:
[{F859245F-345D-BC13-AC4F-145D47DA34FF}]
[{22FAACDE-34DA-CCD4-AB4D-DA34485A3422}]
[{6598FF45-DA60-F48A-BC43-10AC47853D56}]
[wiasoisao]
[Kvsc3]
[upxdnd]
[WinSysM]
[WSockDrv32]
[MsPrint32D]
[DbgHlp32]
[PTSShell]
[LotusHlp]
编辑注册表项<SHELL>的值为Explorer.exe
系统修复-- 浏览器加载项之如下项删除:
[] <C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Sys>
[] <C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Sys>
[Tabular Data Control] <C:\WINDOWS\system32\tdc.ocx>
系统修复-- Winsock 供应者之如下删除:
Easy2Game-TCPChain
C:\WINDOWS\system32\gamelink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-UDPChain
C:\WINDOWS\system32\gamelink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-UDPChain
C:\WINDOWS\system32\gamelink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-TCPChain
C:\WINDOWS\system32\gamelink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-TCPFilter
C:\WINDOWS\system32\gamelink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-UDPFilter
C:\WINDOWS\system32\gamelink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-UDPFilter
C:\WINDOWS\system32\gamelink.dll(www.Easy2Game.com, Easy2Game Service Provider)
Easy2Game-TCPFilter
C:\WINDOWS\system32\gamelink.dll(www.Easy2Game.com, Easy2Game Service Provider)
5,更新杀毒软件至最新,进行全盘杀毒