用附件的XDELBOX删除文件
C:\WINDOWS\system32\wipicdec.dll
C:\WINDOWS\system32\vtpanw.dll
C:\WINDOWS\system32\mdhcyz.dll
C:\WINDOWS\system32\qmzhca.dll
C:\WINDOWS\system32\msosdrop02.dll
C:\WINDOWS\system32\msosping02.dll
C:\WINDOWS\system32\msosjtio02.dll
C:\WINDOWS\system32\msoscqit02.dll
C:\WINDOWS\system32\fmsiocps.dll
C:\WINDOWS\system32\pibvab.dll
C:\WINDOWS\system32\bincdwsa.dll
C:\WINDOWS\system32\dbhlp32.dlL
C:\WINDOWS\system32\fmsjhif.dll
C:\WINDOWS\system32\rzysdhbx.dll
C:\WINDOWS\system32\ptshell.dll
C:\WINDOWS\system32\ticisms.dll
C:\WINDOWS\system32\isndntio.dll
C:\WINDOWS\system32\dkrvrv.dll
C:\WINDOWS\system32\WINSvr64.dll
C:\WINDOWS\system32\mfchlp64.dll
C:\WINDOWS\system32\fmsbbqi.dll
C:\WINDOWS\system32\dndsioc.dll
C:\WINDOWS\system32\huifitc.dll
C:\WINDOWS\system32\yuiabct.dll
C:\WINDOWS\system32\msosdrop02.dll
C:\WINDOWS\system32\msosping02.dll
C:\WINDOWS\system32\msosjtio02.dll
C:\WINDOWS\system32\msoscqit02.dll
C:\WINDOWS\system32\drivers\msosmsp2p32.sys
C:\WINDOWS\system32\drivers\msosmsfpfis64.sys
复制他们,从剪贴板导入,点上抑制再生,右键点击要删除的文件列表,选择立即重起删除
重起以后进入XDELBOX工具,执行删除~
删除过后,打开SRENG
注册表中删除
<fmsiocps><C:\WINDOWS\fmsiocps.exe> []
<bincdwsa><C:\WINDOWS\bincdwsa.exe> []
<dbhlp32><C:\WINDOWS\dbhlp32.exe> []
<fmsjhif><C:\WINDOWS\fmsjhif.exe> []
<igzwzslm><C:\WINDOWS\gwsmhxuq.exe> []
<ptshell><C:\WINDOWS\ptshell.exe> []
<ticisms><C:\WINDOWS\ticisms.exe> []
<WINSvr64><C:\WINDOWS\WINSvr64.exe> []
<wipicdec><C:\WINDOWS\wipicdec.exe> []
<isndntio><C:\WINDOWS\isndntio.exe> []
<mfchlp64><C:\WINDOWS\mfchlp64.exe> []
<fmsbbqi><C:\WINDOWS\fmsbbqi.exe> []
<huifitc><C:\WINDOWS\huifitc.exe> []
<dndsioc><C:\WINDOWS\dndsioc.exe> []
<yuiabct><C:\WINDOWS\yuiabct.exe> []
编辑<AppInit_DLLs><wipicdec.dll,vtpanw.dll,mdhcyz.dll,qmzhca.dll,dkrvrv.dll,fmsiocps.dll,pibvab.dll,nicozftp00.dll,msoscqit02.dll,msosjtio02.dll,msosping02.dll,msosmnsf02.dll,msosdrop02.dll> []
为<AppInit_DLLs><> []
删除[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwProxy.exe]
<IFEO[rfwProxy.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwstub.exe]
<IFEO[rfwstub.exe]><TASKMAN.EXE> [(Verified)Microsoft Windows Publisher]
删除驱动
[cqit / cqit][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp7.tmp><N/A>
[dohs / dohs][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp1D.tmp><N/A>
[drop / drop][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp13.tmp><N/A>
[fmsq / fmsq][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpF.tmp><N/A>
[IIS Manager / IIS Manager ][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1.tmp><N/A>
[jtio / jtio][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp11.tmp><N/A>
[mhfp / mhfp][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp2D.tmp><N/A>
[mnsf / mnsf][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp9.tmp><N/A>
[msfpfis64 / msfpfis64][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosmsfpfis64.sys><N/A>
[msp2p32 / msp2p32][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosmsp2p32.sys><N/A>
[ping / ping][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpD.tmp><N/A>
[ptfs / ptfs][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmpB.tmp><N/A>
修复文件关联
清理临时文件夹:
打开我的电脑-工具-文件夹选项-查看-显示隐藏文件-隐藏受保护的系统文件(勾去掉)-确定
重起进入安全模式(开机不停的按F8,选择安全模式启动) 清空下列临时文件夹中所有内容:
C:\Documents and Settings\用户名\Local Settings\Temporary Internet Files
C:\Documents and Settings\用户名\Local Settings\Temp
C:\WINDOWS\TEMP
把c:\windows\win.ini 文件中如图类似的内容删除
再用附件中的系统文件,把被更改的系统文件修复下
