操作前强烈要求先断网1.建议使用XDelBox删除以下文件:(Xdelbox1.7下载地址:
http://www.qispace.com.cn/read.php/1.htm 的工具19或
http://www.dodudou.com/down/index.php?dirpath=./01.原创软件&order=0)
使用说明:
先勾选抑制再生,
删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入不检查路径,导入后在要删除文件上点击右键,选择立刻重启删除(不论文件是否存在,继续操作重启删除
),电脑会重启进入DOS界面进行删除操作。
运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。c:\windows\system32\wdcrwv.dll
c:\windows\system32\hbinject.exe
c:\windows\system32\avzxlmn.dll
c:\windows\system32\rsmyjpm.dll
c:\windows\system32\rarjepi.dll
c:\program files\internet explorer\plugins\wn_sys8x.sys
c:\windows\system32\avwghmn.dll
c:\docume~1\admini~1\locals~1\temp\17lt.dll
c:\windows\fonts\hookhelp.dll
c:\windows\system32\wsmsezx.dll
c:\windows\system32\kaqhlzy.dll
c:\windows\system32\ratbopi.dll
c:\windows\system32\swrcfzc.dll
c:\windows\system32\kvdxslma.dll
c:\windows\system32\kvdxkma.dll
c:\windows\system32\kawdhzy.dll
c:\windows\system32\gjcscyc.dll
c:\windows\system32\wszjdzx.dll
c:\windows\system32\tdffdl.dll
c:\windows\system32\swjqbzc.dll
c:\windows\system32\ddserh.dll
c:\windows\system32\wzcfsw.dll
c:\windows\system32\wklsdd.dll
c:\windows\system32\wrqszl.dll
c:\windows\system32\zgtwfx.dll
c:\windows\system32\hhrdxd.dll
c:\windows\system32\drivers\rrrrrrrr.sys
c:\docume~1\admini~1\locals~1\temp\tmp7a.tmp
c:\docume~1\admini~1\locals~1\temp\tmp7a.tmp
c:\docume~1\admini~1\locals~1\temp\tmp74.tmp
c:\docume~1\admini~1\locals~1\temp\tmp81.tmp
c:\windows\system32\drivers\hbkernel.sys
c:\docume~1\admini~1\locals~1\temp\tmp80.tmp
c:\docume~1\admini~1\locals~1\temp\_tmp.bat
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[HBService] <; HBInject.exe>
[HBService] <HBInject.exe>
[{C859245F-345D-BC13-AC4F-145D47DA34FC}] <C:\WINDOWS\system32\avzxlmn.dll>
[{AE32FA58-3453-FA2D-BC49-F340348ACCEA}] <C:\WINDOWS\system32\rsmyjpm.dll>
[{5598FF45-DA60-F48A-BC43-10AC47853D55}] <C:\WINDOWS\system32\rarjepi.dll>
[{9963387B-212E-4643-B207-82DAEA0E713D}] <C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys>
[{8A1247C1-53DA-FF43-ABD3-345F323A48D8}] <C:\WINDOWS\system32\avwghmn.dll>
[{00B9CF76-E519-4187-ADF4-B4E313A99947}] <C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\17lt.dll>
[{E159854F-6971-3456-6941-10235412974E}] <C:\WINDOWS\Fonts\hookhelp.dll>
[{792FADFA-BCDE-ACDF-CDEF-21054865CBA7}] <C:\WINDOWS\system32\wsmsezx.dll>
[{C7D81718-1314-5200-2597-58790101807C}] <C:\WINDOWS\system32\kaqhlzy.dll>
[{F6650011-3344-6688-4899-345FABCD156F}] <C:\WINDOWS\system32\ratbopi.dll>
[{778A7521-FA87-34AB-34C2-4893F3AD34C7}] <C:\WINDOWS\system32\swrcfzc.dll>
[{CD561258-45F3-A451-F908-A258458226DC}] <C:\WINDOWS\system32\kvdxslma.dll>
[{BC87A354-ABC3-DEDE-FF33-3213FD7447CB}] <C:\WINDOWS\system32\kvdxkma.dll>
[{88907901-1416-3389-9981-372178569988}] <C:\WINDOWS\system32\kawdhzy.dll>
[{3FA10261-B890-F432-A453-69F1023513F3}] <C:\WINDOWS\system32\gjcscyc.dll>
[{45679330-4034-9021-7012-909856721374}] <C:\WINDOWS\system32\wszjdzx.dll>
[{C0595A7E-2E2F-4B34-A83A-019270A0A464}] <C:\WINDOWS\system32\tdffdl.dll>
[{24909874-8982-F344-A322-7898787FA742}] <C:\WINDOWS\system32\swjqbzc.dll>
[{A9895933-6636-4281-BC58-EE6DE2AF96E3}] <C:\WINDOWS\system32\ddserh.dll>
[{A9895933-6636-4281-BC58-EE6DE2AF96E3}] <C:\WINDOWS\system32\ddserh.dll>
[{28766E1C-74B0-4417-8C75-F12AE309EF35}] <C:\WINDOWS\system32\wzcfsw.dll>
[{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}] <C:\WINDOWS\system32\wklsdd.dll>
[{F99DEFDD-200B-4410-B572-E90883D527D2}] <C:\WINDOWS\system32\wrqszl.dll>
[{006CA8A1-61BC-4774-A54C-F49034270BAD}] <C:\WINDOWS\system32\zgtwfx.dll>
[{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}] <C:\WINDOWS\system32\hhrdxd.dll>
启动项目 -- 服务-- 驱动程序之如下项禁用:
[rrrrrrrr / rrrrrrrr] <\??\C:\WINDOWS\system32\drivers\rrrrrrrr.sys>
[QQHX / QQHX] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp7A.tmp>
[QQHX / QQHX] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp7A.tmp>
[QJ / QJ] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp74.tmp>
[MS / MS] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp81.tmp>
[HBKernel Driver / HBKernel] <\SystemRoot\system32\DRIVERS\HBKernel.sys>
[DJ / DJ] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp80.tmp>
[avpjc / avpjc] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_tmp.bat>
附件清除映像劫持!!!!!!!!!