进入安全模式,
打开SRE
启动项目--注册表--删除
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgrefg.dll> [N/A]
<{1DB3C525-5271-46F7-887A-D4E1ADAA7632}><C:\WINDOWS\system32\hfrdzx.dll> [N/A]
<{D29DCEE0-457B-45A2-A92D-741B95B7723B}><C:\Program Files\Internet Explorer\PLUGINS\Ns_Sys55.Sys> [N/A]
==================================
启动项目--注册表--服务--Win32服务应用程序--删除
[bbia / bbia][Running/Auto Start]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\wwdv\ggnf.dll,Service -s><Microsoft Corporation>
[COM+ Windows System / WinCOM][Running/Auto Start]
<C:\WINDOWS\system32\wincom.exe><Microsoft Corporation>
==================================
启动项目--注册表--服务--驱动程序--删除
[y006 / y006k][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\y006k.sys><N/A>
==================================
SRE--系统修复--浏览器加载项--删除
[]
{00723EB0-3450-4D7B-8356-E3FD0E48E020} <C:\WINDOWS\system32\qivauksjfz.dll, N/A>
[Promote Class]
{0FA24E3E-422C-4D94-A125-104F32352C90} <C:\WINDOWS\system32\promote.dll, N/A>
[]
{9A568672-D437-469E-86C2-F6E4A1156071} <C:\WINDOWS\system32\udyzdekowo.dll, N/A>
[]
{D29DCEE0-457B-45A2-A92D-741B95B7723B} <C:\Program Files\Internet Explorer\PLUGINS\Ns_Sys55.Sys, N/A>
[]
{00723EB0-3450-4D7B-8356-E3FD0E48E020} <C:\WINDOWS\system32\qivauksjfz.dll, N/A>
[Promote Class]
{0FA24E3E-422C-4D94-A125-104F32352C90} <C:\WINDOWS\system32\promote.dll, N/A>
[]
{9A568672-D437-469E-86C2-F6E4A1156071} <C:\WINDOWS\system32\udyzdekowo.dll, N/A>
[]
{D29DCEE0-457B-45A2-A92D-741B95B7723B} <C:\Program Files\Internet Explorer\PLUGINS\Ns_Sys55.Sys, N/A>
==================================
显示隐藏文件后删除以下文件
C:\WINDOWS\system32\udyzdekowo.dll
C:\PROGRA~1\wwdv\jjqi.dll
C:\PROGRA~1\wwdv\oovn.dll
C:\WINDOWS\system32\qivauksjfz.dll
C:\PROGRA~1\wwdv\ggnf.dll
C:\PROGRA~1\wwdv\llsk.dll
C:\PROGRA~1\wwdv\ccjb.dll
C:\WINDOWS\system32\sgrefg.dll
C:\WINDOWS\system32\hfrdzx.dll
C:\Program Files\Internet Explorer\PLUGINS\Ns_Sys55.Sys
C:\WINDOWS\system32\promote.dll
C:\WINDOWS\system32\DRIVERS\y006k.sys
C:\WINDOWS\system32\wincom.exe
C:\PROGRA~1\wwdv\删除这个文件夹