1、关闭IE后,拔掉网线;
2、用XDELBOX1.7的“重启执行删除”+“抑制再生”,删除以下文件:
C:\WINDOWS\system32\Drivers\001e9ae6.sys
C:\WINDOWS\system32\Drivers\0061456d.sys
C:\WINDOWS\system32\drivers\Hdv32_c.sys
C:\WINDOWS\system32\d32dx9.sys
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1.tmp
C:\WINDOWS\System32\DRIVERS\h56zu1b.sys
3、进入注册表编辑器,删除以下注册表值项:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{4F4F0064-71E0-4f0d-0005-708476C7815F}>
<{4F4F0064-71E0-4f0d-0015-708476C7815F}>
<{5A069845-2036-6084-9054-6087502480A5}>
<{6A041F13-A111-12A3-B0CF-F99818AA68A6}>
<{5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5}>
<{5FD45A54-9875-698F-E56E-65102358FDF5}>
<{189F087F-4378-405F-85FA-37D955AD7A8C}>
<{81954FAC-1023-154F-895A-1458258AD818}>
<{4F4F0064-71E0-4f0d-0004-708476C7815F}>
<{4F4F0064-71E0-4f0d-0017-708476C7815F}>
<{37AC9076-C898-B098-D098-A18319080973}>
<{22596546-2036-9451-6058-658402589722}>
<{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6}>
<{9490415F-65F8-B5C5-D8BA-9405FB120549}>
<{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}>
<{528DF602-9541-A985-210A-984A698C6F25}>
<{4F4F0064-71E0-4f0d-0006-708476C7815F}>
<{4F4F0064-71E0-4f0d-0012-708476C7815F}>
<{4F4F0064-71E0-4f0d-0021-708476C7815F}>
<{7C8D1401-A58D-A81C-CD24-A5915C4517C7}>
<{DC3D30AE-0380-4151-8934-EE98A34B0370}>
<{4D165A2A-4BC1-4CA8-8299-08E05AAAB5A4}>
<{55694105-5108-9405-3695-954187462155}>
<{00010001-0001-0001-0001-00010001BB15}>
<{031B7024-4FC5-49B3-98EF-6B810FF12678}>
<{3D698451-2015-6358-9871-2015987452D3}>
<{4F4F0064-71E0-4f0d-0003-708476C7815F}>
<{00050005-0005-0005-0005-00050005BB15}>
<{7A041F13-A111-12A3-B0CF-F99818AA68A7}>
<{32023698-6984-8541-9654-698745012523}>
<{eaa21495-29ae-4e50-8ad9-a4f877c1ab85}>
<{77FD640A-158F-48AC-FD14-1597F14A9777}>
<{6FD45A54-9875-698F-E56E-65102358FDF6}>
<{37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73}>
<{54FAE856-AD58-20CB-A025-CD4895FA6E45}>
<{35671234-7890-ABCD-CDEF-567801237653}>
<{00120012-0012-0012-0012-00120012BB15}>
<{43512378-9874-5641-1025-985420368734}>
<{50940F85-F015-14F1-A05F-F69858AC6D05}>
<{A629FF4F-ACDB-5C90-A098-FACB3456A26A}>
<{4F4F0064-71E0-4f0d-0023-708476C7815F}>
<{74381DEC-D78B-43E4-BA5D-5244F669EBE4}>
<{25FD6584-698F-BCD2-602C-698745210352}>
<{B490415F-65F8-B5C5-D8BA-9405FB12054B}>
<{B629FF4F-ACDB-5C90-A098-FACB3456A26B}>
<{87FD640A-158F-48AC-FD14-1597F14A9778}>
<{7FD45A54-9875-698F-E56E-65102358FDF7}>
<{47AC9076-C898-B098-D098-A18319080974}>
<{90AF1289-F140-A140-D012-C1458759FC09}>
<{4D698451-2015-6358-9871-2015987452D4}>
<{00030003-0003-0003-0003-00030003BB15}>
<{8A041F13-A111-12A3-B0CF-F99818AA68A8}>
<{C629FF4F-ACDB-5C90-A098-FACB3456A26C}>
<{97FD640A-158F-48AC-FD14-1597F14A9779}>
<{8FD45A54-9875-698F-E56E-65102358FDF8}>
<{006CA8A1-61BC-4774-A54C-F49034270BAD}>
<{00170017-0017-0017-0017-00170017BB15}>
<{2A698452-C5D8-C584-C256-C264C987C5A2}>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<midimapzx>
<midimapmy>
<midimapwl>
<midimaptl>
<midimapcb>
<midimapjr>
<midimappt>
<adsntzt>
<midimapgj>
<cliconfgzx>
<kbdswjr>
<midimapcq>
<adsntzt.dll>
<cliconfgzx.dll>
<kbdswjr.dll>
<bootvidgj.dll>
<msobjstl.dll>
4、用SRENG扫描工具删除如下驱动程序项目:
[001e9ae6 / 001e9ae6]
[0061456d / 0061456d]
[Hdv32 / Hdv32]
[HiddFldy / HiddFldy]
[IIS Manager / IIS Manager ]
[h56zu1 / h56zu1b]
5、重启电脑,卸载瑞星杀软;手工删除瑞星杀软安装目录,之后重装瑞星杀软;
6、联网,到置顶找FLASH漏洞补丁安装,然后升级杀软到最新版本,全盘杀毒