病毒一大大大堆~
操作起来比较烦琐~
你试试看吧,不行就备份下系统盘的资料,然后重装~
不能重装的话,按照以下操作:
用附件的XDELBOX删除文件
C:\WINDOWS\system32\nhmxajkl.dll
C:\WINDOWS\system32\zgfdet.dll
C:\WINDOWS\system32\mtewdh.dll
C:\WINDOWS\system32\zxmscwin.dll
C:\WINDOWS\system32\zyzxhime.dll
C:\WINDOWS\system32\mndhcdwd.dll
C:\WINDOWS\system32\skqnbbib.dll
C:\WINDOWS\system32\oohxdbyt.dll
C:\WINDOWS\system32\wyhesm.dll
C:\WINDOWS\system32\jfrwdh.dll
C:\WINDOWS\system32\wrqszl.dll
C:\WINDOWS\system32\yxcschlp.dll
C:\WINDOWS\system32\cedafb.dll
C:\WINDOWS\system32\rfdswc.dll
C:\WINDOWS\system32\jhrcar.dll
C:\WINDOWS\system32\sgrefg.dll
C:\WINDOWS\system32\mndsesrv.dll
C:\WINDOWS\system32\jkhxaklo.dll
C:\WINDOWS\system32\jdsaex.dll
C:\WINDOWS\system32\ozfydbyt.dll
C:\WINDOWS\twftadfia16_080526.dll
复制他们,从剪贴板导入,点上抑制再生,右键点击要删除的文件列表,选择立即重起删除
重起以后进入XDELBOX工具,执行删除~
删除过后,打开SRENG
注册表中删除
<{28EB3777-3E23-4E72-8449-A992D09D24C3}><C:\WINDOWS\system32\zgfdet.dll> []
<{189F087F-4378-405F-85FA-37D955AD7A8C}><C:\WINDOWS\system32\mtewdh.dll> []
<{4F4F0064-71E0-4f0d-0015-708476C7815F}><C:\WINDOWS\system32\midimapmy.dll> [Microsoft Corporation]
<{6A041F13-A111-12A3-B0CF-F99818AA68A6}><C:\WINDOWS\system32\zxmscwin.dll> []
<{4F4F0064-71E0-4f0d-0017-708476C7815F}><C:\WINDOWS\system32\midimaptl.dll> [Microsoft Corporation]
<{8A59145F-315D-BC23-AC1F-145DF81A34A8}><C:\WINDOWS\system32\zyzxhime.dll> []
<{4F4F0064-71E0-4f0d-0018-708476C7815F}><C:\WINDOWS\system32\midimapwd.dll> [Microsoft Corporation]
<{3C648541-1025-9650-9057-6541258720C3}><C:\WINDOWS\system32\mndhcdwd.dll> []
<{22023698-6984-8541-9654-698745012522}><C:\WINDOWS\system32\skqnbbib.dll> []
<{5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5}><C:\WINDOWS\system32\oohxdbyt.dll> []
<{EB71E0B3-E97D-4D30-8733-E28266467617}><C:\WINDOWS\system32\wyhesm.dll> []
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> []
<{F99DEFDD-200B-4410-B572-E90883D527D2}><C:\WINDOWS\system32\wrqszl.dll> []
<{35671234-7890-ABCD-CDEF-567801237653}><C:\WINDOWS\system32\yxcschlp.dll> []
<{84143967-B645-4BFF-B873-DA1DC886E9A7}><C:\WINDOWS\system32\cedafb.dll> []
<{461D2AB4-29A5-45C2-9134-D52272D3DE38}><C:\WINDOWS\system32\rfdswc.dll> []
<{CAED0F3B-DF8B-4DBF-BB20-8DFBC3199068}><C:\WINDOWS\system32\jhrcar.dll> []
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgrefg.dll> []
<{57FD640A-158F-48AC-FD14-1597F14A9775}><C:\WINDOWS\system32\mndsesrv.dll> []
<{14698742-2059-3025-9058-954023874141}><C:\WINDOWS\system32\jkhxaklo.dll> []
<{17AC9076-C898-B098-D098-A18319080971}><C:\WINDOWS\system32\nhmxajkl.dll> []
<{B29583D8-033A-4B9F-8553-7C5458F3FB8E}><C:\WINDOWS\system32\jdsaex.dll> []
<{4A069845-2036-6084-9054-6087502480A4}><C:\WINDOWS\system32\ozfydbyt.dll> []
<midimapmy><C:\WINDOWS\system32\midimapmy.dll> [Microsoft Corporation]
<midimaptl><C:\WINDOWS\system32\midimaptl.dll> [Microsoft Corporation]
<midimapwd><C:\WINDOWS\system32\midimapwd.dll> [Microsoft Corporation]
编辑<AppInit_DLLs><nhmxajkl.dll> []为空
删除驱动
[IIS Manager / IIS Manager ][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1.tmp><N/A>
禁止驱动
[wxbfileb / wxbfileb][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\wxbfileb.sys><N/A>
[NTGDT / NTGDT][Running/System Start]
<\??\C:\WINDOWS\system32\Drivers\NTGDT.SYS><N/A>
删除浏览器加载
[]
{14698742-2059-3025-9058-954023874141} <C:\WINDOWS\system32\jkhxaklo.dll, N/A>
[]
{17AC9076-C898-B098-D098-A18319080971} <C:\WINDOWS\system32\nhmxajkl.dll, N/A>
[]
{22023698-6984-8541-9654-698745012522} <C:\WINDOWS\system32\skqnbbib.dll, N/A>
[]
{35671234-7890-ABCD-CDEF-567801237653} <C:\WINDOWS\system32\yxcschlp.dll, N/A>
[]
{3C648541-1025-9650-9057-6541258720C3} <C:\WINDOWS\system32\mndhcdwd.dll, N/A>
[]
{4A069845-2036-6084-9054-6087502480A4} <C:\WINDOWS\system32\ozfydbyt.dll, N/A>
[]
{57FD640A-158F-48AC-FD14-1597F14A9775} <C:\WINDOWS\system32\mndsesrv.dll, N/A>
[]
{5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5} <C:\WINDOWS\system32\oohxdbyt.dll, N/A>
[]
{6A041F13-A111-12A3-B0CF-F99818AA68A6} <C:\WINDOWS\system32\zxmscwin.dll, N/A>
[]
{8A59145F-315D-BC23-AC1F-145DF81A34A8} <C:\WINDOWS\system32\zyzxhime.dll, N/A>
修复文件关联
下载arswp(Windows清理助手)清理下..
http://www.arswp.com/download/arswp/arswp.rar清理临时文件夹:
打开我的电脑-工具-文件夹选项-查看-显示隐藏文件-隐藏受保护的系统文件(勾去掉)-确定
重起进入安全模式(开机不停的按F8,选择安全模式启动) 清空下列临时文件夹中所有内容:
C:\Documents and Settings\用户名\Local Settings\Temporary Internet Files
C:\Documents and Settings\用户名\Local Settings\Temp
C:\WINDOWS\TEMP