1.建议使用XDelBox删除以下文件
c:\windows\system32\gdipro.dll
c:\windows\system32\sys07006.dll
3474a8c2.dll
b3721c07.dll
4efddebe.dll
08223b03.dll
1b1d8534.dll
e4814792.dll
53360697.dll
d91bc61e.dll
nwiz.exe /install
c:\windows\system32\tqcthdgt.dll
c:\windows\system32\jkbefbyj.dll
c:\windows\system32\nevxtrzq.dll
c:\windows\system32\ravext.dll
c:\windows\system32\4c70249.sys
c:\windows\system32\8882fa1.sys
c:\program files\qq2006\npkcrypt.sys
c:\windows\system32\drivers\aliimz.sys
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[rdaegdxs.dll] <>
[hjntffsg.dll] <>
[xxaimpvu.dll] <>
[fundefje.dll] <>
[vahslhmt.dll] <>
[lhuhsjqh.dll] <>
[hlmiikak.dll] <>
[uhfkwtln.dll] <>
[cesngjgp.dll] <>
[ssecnlbm.dll] <>
[iyrruvfa.dll] <>
[xkmlgcmi.dll] <>
[nqyaoehw.dll] <>
[hurkcnsz.dll] <>
[ngkabcvr.dll] <>
[duwpiezf.dll] <>
[pqpyxocr.dll] <>
[cnnvwamr.dll] <>
[xohorpxi.dll] <>
[mfbnprju.dll] <>
[kibfojht.dll] <>
[qdijcvgv.dll] <>
[tfnaygvv.dll] <>
[lhcmobhs.dll] <>
[ndukwxhd.dll] <>
[pohirand.dll] <>
[vignfnuf.dll] <>
[krbllpos.dll] <>
[jinrxxoy.dll] <>
[bazzlinn.dll] <>
[qkmyjkzs.dll] <>
[fvjquodx.dll] <>
[ylcvxcnl.dll] <>
[qnqinezj.dll] <>
[oqyseeqz.dll] <>
[ukxwsjxk.dll] <>
[axfahvwu.dll] <>
[pozhepqz.dll] <>
[{3474A8C2-BEF9-46C8-983A-A26A0030EC30}] <3474A8C2.dll>
[{B3721C07-62B3-411A-9DC7-F5F27E3E21FF}] <B3721C07.dll>
[{4EFDDEBE-303C-4D1A-8C9E-E4F215C43651}] <4EFDDEBE.dll>
[{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}] <08223B03.dll>
[{1B1D8534-8B2E-4DF0-B92B-C878E4DB0F0B}] <1B1D8534.dll>
[{E4814792-EFA3-4C20-93D0-8B130A59F9A8}] <E4814792.dll>
[{53360697-E270-4F80-AD5D-6FB518F03D24}] <53360697.dll>
[{D91BC61E-7D78-4A2A-A336-7B97E8E52F0B}] <D91BC61E.dll>
[nwiz] <nwiz.exe /install>
[glurbeks.dll] <C:\WINDOWS\system32\tqcthdgt.dll>
[{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}] <C:\WINDOWS\system32\jkbefbyj.dll>
[hiuzkntu.dll] <C:\WINDOWS\system32\nevxtrzq.dll>
[ksrezssy.dll] <C:\WINDOWS\system32\tqcthdgt.dll>
[ifpgqzjx.dll] <C:\WINDOWS\system32\nevxtrzq.dll>
[akryftkn.dll] <C:\WINDOWS\system32\tqcthdgt.dll>
[xaezjpwo.dll] <C:\WINDOWS\system32\nevxtrzq.dll>
[{EA4D8F95-8F2E-4658-A234-E8F4C9AC21C5}] <C:\WINDOWS\system32\tqcthdgt.dll>
[ovtqacyq.dll] <C:\WINDOWS\system32\jkbefbyj.dll>
[{432BDC7C-DE5B-43f4-AA81-E7F8AFB0182D}] <C:\WINDOWS\system32\nevxtrzq.dll>
[kvoogqxh.dll] <C:\WINDOWS\system32\jkbefbyj.dll>
[{32CD708B-60A7-4C00-9377-D73EAA495F0F}] <C:\WINDOWS\system32\RavExt.dll>
[myxyzhcb.dll] <C:\WINDOWS\system32\tqcthdgt.dll>
[glpuluwr.dll] <C:\WINDOWS\system32\nevxtrzq.dll>
[icadchfq.dll] <C:\WINDOWS\system32\jkbefbyj.dll>
[tqcthdgt.dll] <C:\WINDOWS\system32\tqcthdgt.dll>
[nevxtrzq.dll] <C:\WINDOWS\system32\nevxtrzq.dll>
[jkbefbyj.dll] <C:\WINDOWS\system32\jkbefbyj.dll>
[nzyrdpgx.dll] <C:\WINDOWS\system32\jkbefbyj.dll>
[IFEO[RSTray.exe]] <svchost.exe>
启动项目 -- 服务 -- Win32服务应用程序之如下项删除:
[Remote Procedure Call (RPC) / RpcSs] <C:\WINDOWS\system32\svchost -k rpcss-->c:\windows\system32\rpcss.dll>
[DCOM Server Process Launcher / DcomLaunch] <C:\WINDOWS\system32\svchost -k DcomLaunch-->%SystemRoot%\system32\rpcss.dll>
启动项目 -- 服务-- 驱动程序之如下项删除:
[4c70249 / 4c70249] <\??\C:\WINDOWS\system32\4c70249.sys>
[8882fa1 / 8882fa1] <\??\C:\WINDOWS\system32\8882fa1.sys>
[npkcrypt / npkcrypt] <\??\C:\Program Files\QQ2006\npkcrypt.sys>
[aliimz / aliimz] <System32\Drivers\aliimz.sys>
到同系统里下载一个rpcss.dll替换下面
c:\windows\system32\rpcss.dll