下载XDelBox1.7)删除以下文件
http://www.dodudou.com/down/index.phpC:\WINDOWS\system32\hllntx.dll
C:\WINDOWS\system32\waflaj.dll
C:\WINDOWS\system32\zubhyy.dll
C:\WINDOWS\system32\sujfug.dll
C:\WINDOWS\system32\jxsmjx.dll
C:\WINDOWS\system32\sqomvx.dll
C:\WINDOWS\system32\mzdfhy.dll
C:\WINDOWS\system32\agfhlbvgix.dll
C:\WINDOWS\system32\dhtfdhvagz.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2115.dll
C:\WINDOWS\system32\drivers\2wp4tdomq.sys
C:\WINDOWS\system32\DRIVERS\440q.sys
C:\Program Files\Microsoft Office\SYSTEM\apcdli.sys
C:\WINDOWS\system32\drivers\cnprov.sys
C:\WINDOWS\system32\drivers\hapdrv2.sys
C:\WINDOWS\system32\drivers\idnaux.sys
C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys
C:\WINDOWS\system32\DRIVERS\sqjcns33.sys
C:\WINDOWS\system32\Nessery.sys
C:\WINDOWS\system32\GSLECowEFVjfYM.dll
C:\Program Files\Common Files\Microsoft Shared\MSINFO\chenzhengxinshow.exe
c:\windows\system32\comr3260.dll
C:\WINDOWS\system32\1800.exe
C:\WINDOWS\system\lljy080426.exe
C:\WINDOWS\system32\gain.exe
C:\WINDOWS\system32\sichost.exe
C:\WINDOWS\system32\mzdfhy.dll
C:\WINDOWS\system32\MMSHYLQE1060.dll
C:\WINDOWS\system32\MMDABLUU1076.dll
C:\WINDOWS\system32\MMBAIKOK1071.dll
C:\WINDOWS\system32\MMKAFNFW1075.dll
C:\WINDOWS\system32\MMDLQJER1010.dll
C:\WINDOWS\system32\MMCBDKTK1059.dll
打开SRE
启动项目--注册表--删除
<lljy_df><C:\WINDOWS\system\lljy080426.exe> [N/A]
<wscripte><C:\WINDOWS\system32\gain.exe> [N/A]
<{D621F721-F961-48A4-919C-749DE7A2C2D2}><C:\WINDOWS\system32\mzdfhy.dll> []
<{13809333-dffe-4bcc-9284-df679af4ec3f}><C:\WINDOWS\system32\MMSHYLQE1060.dll> [N/A]
<{4211ec0a-2f8b-4140-ad1b-a1b07e0ab4a5}><MMDABLUU1076.dll> [N/A]
<{75308caa-9a15-491a-9535-3cba0d617f5b}><MMBAIKOK1071.dll> [N/A]
<{27326302-f5f0-4f9d-a8ff-24a62328ef38}><MMKAFNFW1075.dll> [N/A]
<{8B3D2463-816D-436D-AD5A-701FBB75B2D3}><C:\WINDOWS\system32\hllntx.dll> [N/A]
<{DF2429B8-AE44-4C2C-932A-7BC9ED67F4FC}><C:\WINDOWS\system32\waflaj.dll> []
<{6DC46609-5FF8-4AF6-A365-656174D26927}><C:\WINDOWS\system32\zubhyy.dll> []
<{E58EB77D-12B0-48E7-82B6-390F4E98D375}><C:\WINDOWS\system32\sujfug.dll> [N/A]
<{100321F3-7D04-48E6-B495-AA9D62AC6B79}><C:\WINDOWS\system32\jxsmjx.dll> []
<{AD9CD638-8691-4B0D-8D57-82AC0888D7A3}><C:\WINDOWS\system32\sqomvx.dll> []
<{8472766e-ee81-412c-91f9-7454ca6b9e15}><MMDLQJER1010.dll> [N/A]
<{3cc8055b-912f-4f72-8fea-fc8c163be08c}><MMCBDKTK1059.dll> [N/A]
编辑<Userinit><C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sichost.exe>
为<Userinit><C:\WINDOWS\system32\userinit.exe,>
==================================
SREng-在"启动项目->服务->"Win32服务应用程序"选中"隐藏已认证的微软项目" 然后将下面名称的服务删除(选中有问题的服务后,点"删除服务",点“设置”按钮即可。注意弹出的窗口中要点 "否NO"才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置):
[Windows Presentation Foundation (WPF) / applications][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k applications-->C:\WINDOWS\system32\GSLECowEFVjfYM.dll><N/A>
[chenzhengxinshow / chenzhengxinshow][Stopped/Auto Start]
<C:\Program Files\Common Files\Microsoft Shared\MSINFO\chenzhengxinshow.exe><N/A>
[Security Control / secctrl][Stopped/Auto Start]
<c:\windows\system32\rundll32.exe comr3260.dll,scan><Microsoft Corporation>
[Windows Accounts Driver / windows_0][Running/Auto Start]
<C:\WINDOWS\system32\1800.exe><N/A>
[Dell Wireless WLAN Tray Service / wltrysvc][Running/Auto Start]
<C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe><N/A>
==================================
SREng-》启动项目->服务->驱动程序--删除以下项目
[2wp4tdomq / 2wp4tdomq][Stopped/Boot Start]
<\SystemRoot\system32\drivers\2wp4tdomq.sys><N/A>
[440 / 440q][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\440q.sys><N/A>
[apcdli / apcdli][Running/Auto Start]
<\??\C:\Program Files\Microsoft Office\SYSTEM\apcdli.sys><N/A>
[cnprov / cnprov][Running/Boot Start]
<\SystemRoot\system32\drivers\cnprov.sys><中国互联网络信息中心(CNNIC)>
[HapDrv32 / HapDrv32][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\hapdrv2.sys><N/A>
[idnaux / idnaux][Running/Auto Start]
<system32\drivers\idnaux.sys><中国互联网络信息中心(CNNIC)>
[ntptdb / ntptdb][Running/Auto Start]
<\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>
[Secdrv / Secdrv][Stopped/]
<2 - 系统找不到指定的文件。
><N/A>
[sqjcns3 / sqjcns33][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\sqjcns33.sys><N/A>
[Nessery / Nessery][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Nessery.sys><N/A>
==================================
SREng-系统修复-浏览器加载项中删除下列项:
[IEAux Class]
{7605CC7C-00FD-4A5F-BAFD-828342DE6279} <C:\PROGRA~1\OCINS\ieaux.dll, 中国互联网络信息中心(CNNIC)>
[]
{7F76F60B-FF04-4E59-8C6B-B9B53B6EA368} <C:\WINDOWS\system32\agfhlbvgix.dll, N/A>
[Browser Enhanced Objects]
{986488AF-13D5-9DDF-4FEF-9FB88698CFC1} <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2115.dll, Hangzhou Travel Inc.>
[]
{FB3412B6-6D67-4650-B3B4-C2A90191A80F} <C:\WINDOWS\system32\dhtfdhvagz.dll, N/A>
[]
{7F76F60B-FF04-4E59-8C6B-B9B53B6EA368} <C:\WINDOWS\system32\agfhlbvgix.dll, N/A>
[]
{FB3412B6-6D67-4650-B3B4-C2A90191A80F} <C:\WINDOWS\system32\dhtfdhvagz.dll, N/A>
==================================
下载windows清理助手清理下
http://www.arswp.com/download.html还有问题,再扫个日志上来