1.C:\WINDOWS\upxdnd.exe
C:\WINDOWS\LotusHlp.exe
C:\WINDOWS\NVDispDRV.EXE
C:\WINDOWS\SHAProc.exe
C:\WINDOWS\wiasoisao.exe
C:\WINDOWS\system32\Drivers\dtscsi.sys
C:\WINDOWS\system32\drivers\msyecp.sys
C:\WINDOWS\system32\msacpe.sys
C:\WINDOWS\system32\KAB-KAB-1031.dll
C:\WINDOWS\system32\BAA_BAA_1023.dll
C:\WINDOWS\Fonts\gjcsdyc.dll
C:\WINDOWS\system32\HAB-HAB-1034.dll
C:\WINDOWS\system32\IGB_JZ_1028.dll
C:\WINDOWS\system32\QAB_QAB_1011.dll
C:\WINDOWS\system32\JAA-JAA-1032.dll
C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys
C:\WINDOWS\kfnrthoh.dll
C:\WINDOWS\kiefncol.dll
C:\WINDOWS\system32\WinForm.dll
C:\WINDOWS\system32\iemnaw.dll
C:\WINDOWS\system32\oadnew.dll
C:\WINDOWS\frhhusyk.dll
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\system32\LotusHlp.dll
C:\WINDOWS\system32\NVDispDrv.dll
C:\WINDOWS\system32\SHAProc.dll
C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys
C:\WINDOWS\system32\KAB-KAB-1031.dll
C:\WINDOWS\system32\BAA_BAA_1023.dll
C:\WINDOWS\system32\HAB-HAB-1034.dll
C:\WINDOWS\system32\IGB_JZ_1028.dll
C:\WINDOWS\system32\QAB_QAB_1011.dll
C:\WINDOWS\system32\JAA-JAA-1032.dll
C:\WINDOWS\kiefncol.dll
C:\WINDOWS\Fonts\gjcsdyc.dll
C:\WINDOWS\system32\oadnew.dll
C:\WINDOWS\kfnrthoh.dll
C:\WINDOWS\system32\hjiq.dll
C:\WINDOWS\System32\xhqq.dll
C:\WINDOWS\System32\uohsom.dll
C:\WINDOWS\System32\niluw.dll
C:\WINDOWS\System32\iqnauhc.dll
C:\WINDOWS\System32\ijougiemnaw.dll
C:\WINDOWS\System32\iemnaw.dll
C:\WINDOWS\System32\vlihzouhgnfe.dll
C:\WINDOWS\System32\hjxr.dll
C:\WINDOWS\System32\3auhad.dll
C:\WINDOWS\System32\oadnew.dll
C:\WINDOWS\System32\hjiq.dll
C:\WINDOWS\WinForm.exE
用XDelBox一次性删除
(enao.ys168.com 下载)
复制上面所有要删除的文件,打开XDelBox,在待删除列表点 右键==>选择 剪贴版导入不检查路径==>勾选上 抑制再生==>点 右键==>选择==>立刻重启执行删除
2.删除注册表项目
WinForm><C:\WINDOWS\WinForm.exE> []
<upxdnd><C:\WINDOWS\upxdnd.exe> []
<LotusHlp><C:\WINDOWS\LotusHlp.exe> []
<NVDispDrv><C:\WINDOWS\NVDispDRV.EXE> []
<SHAProc><C:\WINDOWS\SHAProc.exe> []
<wiasoisao><wiasoisao.exe> []
<{1dd79acb-7617-4c72-ac5f-fdd8f278975e}><C:\WINDOWS\system32\KAB-KAB-1031.dll> []
<{2267b45e-59ff-467a-bc3f-3b289cbf5f71}><C:\WINDOWS\system32\BAA_BAA_1023.dll> []
<{4FA10261-B890-F432-A453-69F1023513F4}><C:\WINDOWS\Fonts\gjcsdyc.dll> []
<{7d8e3ea6-f389-41ae-a066-de5ebdd70610}><C:\WINDOWS\system32\HAB-HAB-1034.dll> []
<{19e83df9-18c4-4fca-8fa4-b70035681dc1}><C:\WINDOWS\system32\IGB_JZ_1028.dll> []
<{94f833b0-726d-4d09-b715-6352f632ece7}><C:\WINDOWS\system32\QAB_QAB_1011.dll> []
<{2f32e793-9263-4aa5-862f-da2480554715}><C:\WINDOWS\system32\JAA-JAA-1032.dll> []
<{9963387B-212E-4643-B207-82DAEA0E713D}><C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys> []
删除驱动服务
[dtscsi / dtscsi][Running/Manual Start]
<\SystemRoot\System32\Drivers\dtscsi.sys><N/A>
[msertk / msertk][Running/Auto Start]
<system32\drivers\msyecp.sys><N/A>
[mseqsy / mseqsy][Running/Auto Start]
<system32\DRIVERS\msacpe.sys><N/A>
3.下载瑞星机器狗专杀,修复被修改的Explorer.exe
http://it.rising.com.cn/Channels/Service/2008-02/1201952872d45281.shtml