建议断网操作:使用XDelBox(下载地址:
http://bbs.ikaka.com/attachment.aspx?attachmentid=446806)
删除以下文件:(使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择剪贴板导入.在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储设备
C:\WINDOWS\fonts\CtmRes.dll
C:\1ca868d8a5dafcfb.dat
C:\3bd72eec9ed4b964.dat
C:\519d4ca4c3104d91.dat
C:\6452f6b0fe050cc8.dat
C:\7f1537acb20503b8.dat
C:\93a5fa1c1b79b53b.dat
C:\ab523fb0f7f71bcc.dat
C:\ae6dc2d44b023f0b.dat
C:\WINDOWS\System32\DRIVERS\atlpx.sys
C:\bb87143c06e2cec6.dat
C:\WINDOWS\system32\drivers\bcajagdb.sys
C:\WINDOWS\System32\Drivers\bootdrv.sys
C:\d829f5586ab706da.dat
C:\e2c271407e4c98f8.dat
C:\DOCUME~1\shz\LOCALS~1\Temp\tmp7.tmp
C:\WINDOWS\system32\drivers\MSJDrvr.sys
C:\WINDOWS\system32\3362C1EE.dat
C:\WINDOWS\fonts\CtmRes.dll
C:\WINDOWS\fonts\ctm01025.ttf
C:\WINDOWS\fonts\ctm11008.ttf
C:\Program Files\Internet Explorer\PowerNeNt.Onz
C:\DOCUME~1\shz\LOCALS~1\Temp\474069
C:\WINDOWS\system32\ctfmon.exe
删除重启后使用SREng修复下面各项:
启动项目 -- 注册表之如下项删除:
<VoipStunt>
<{EB781514-4C32-4585-B074-C24E9E4AD9A6}><C:\WINDOWS\system32\ebnohlhk.dll> [File is missing]
<{41BF2D49-A759-4E9C-AF5A-172B90B35595}><C:\WINDOWS\system32\khbfidkp.dll> [File is missing]
<{E1485F63-9D39-4B26-9C04-A3CD917B79EF}><C:\WINDOWS\system32\ehkolfmj.dll> [File is missing]
<{93311E7E-0C89-4676-A73A-DD2212EF6346}><C:\WINDOWS\system32\pjjhhene.dll> [File is missing]
<{40D712CE-CA87-4726-8830-D3E8D1299E00}><C:\WINDOWS\system32\kgdnhice.dll> [File is missing]
<{6440A0AE-9CDE-41B7-9E80-58DA3AC8B84B}><C:\WINDOWS\system32\mkkgagae.dll> [File is missing]
<{1C479604-30AA-488B-B31A-7971E2D47087}><C:\WINDOWS\system32\hcknpmgk.dll> [File is missing]
<{1E8FAB7B-BB8C-48C5-A004-6EC6669424BF}><C:\WINDOWS\system32\heofabnb.dll> [File is missing]
<{BB025276-4396-4977-90FC-F02C532FE856}><C:\WINDOWS\system32\bbgilinm.dll> [File is missing]
<{6A8D34D7-08D7-421F-AFF6-956A0BD6F0BF}><C:\Program Files\Internet Explorer\PowerNeNt.Onz> []
<6440A0AE><C:\WINDOWS\system32\mkkgagae.dll> [File is missing]
<BB025276><C:\WINDOWS\system32\bbgilinm.dll> [File is missing]
<41BF2D49><C:\WINDOWS\system32\khbfidkp.dll> [File is missing]
<1C479604><C:\WINDOWS\system32\hcknpmgk.dll> [File is missing]
<93311E7E><C:\WINDOWS\system32\pjjhhene.dll> [File is missing]
<40D712CE><C:\WINDOWS\system32\kgdnhice.dll> [File is missing]
<EB781514><C:\WINDOWS\system32\ebnohlhk.dll> [File is missing]
<1E8FAB7B><C:\WINDOWS\system32\heofabnb.dll> [File is missing]
<E1485F63><C:\WINDOWS\system32\ehkolfmj.dll> [File is missing]
<AppInit_DLLs><C:\WINDOWS\fonts\CtmRes.dll kmon.dll> [File is missing]
编辑为 <AppInit_DLLs>< kmon.dll>
启动项目 -- 服务-- 驱动程序之如下项删除:
SREng-在"启动项目->服务->驱动程序中"选中"隐藏已认证的微软项目"然后删除下面名称的驱动程序(选中有问题的驱动后,点"删除服务",点“设置”按钮即可。注意弹出的窗口中要点 "否NO"才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置):
[1ca868d8a5dafcfb / 1ca868d8a5dafcfb][Stopped/Manual Start]
<\??\C:\1ca868d8a5dafcfb.dat><N/A>
[3bd72eec9ed4b964 / 3bd72eec9ed4b964][Stopped/Manual Start]
<\??\C:\3bd72eec9ed4b964.dat><N/A>
[519d4ca4c3104d91 / 519d4ca4c3104d91][Stopped/Manual Start]
<\??\C:\519d4ca4c3104d91.dat><N/A>
[6452f6b0fe050cc8 / 6452f6b0fe050cc8][Stopped/Manual Start]
<\??\C:\6452f6b0fe050cc8.dat><N/A>
[7f1537acb20503b8 / 7f1537acb20503b8][Stopped/Manual Start]
<\??\C:\7f1537acb20503b8.dat><N/A>
[93a5fa1c1b79b53b / 93a5fa1c1b79b53b][Stopped/Manual Start]
<\??\C:\93a5fa1c1b79b53b.dat><N/A>
[ab523fb0f7f71bcc / ab523fb0f7f71bcc][Stopped/Manual Start]
<\??\C:\ab523fb0f7f71bcc.dat><N/A>
ae6dc2d44b023f0b / ae6dc2d44b023f0b][Stopped/Manual Start]
<\??\C:\ae6dc2d44b023f0b.dat><N/A>
[atlp / atlpx][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\atlpx.sys><N/A>
[bb87143c06e2cec6 / bb87143c06e2cec6][Stopped/Manual Start]
<\??\C:\bb87143c06e2cec6.dat><N/A>
[bcajagdb / bcajagdb][Stopped/Boot Start]
<\SystemRoot\system32\drivers\bcajagdb.sys><N/A>
[bootdrv / bootdrv][Stopped/Boot Start]
<\SystemRoot\System32\Drivers\bootdrv.sys><N/A>
[d829f5586ab706da / d829f5586ab706da][Stopped/Manual Start]
<\??\C:\d829f5586ab706da.dat><N/A>
[e2c271407e4c98f8 / e2c271407e4c98f8][Stopped/Manual Start]
<\??\C:\e2c271407e4c98f8.dat><N/A>
[GJ / GJ][Stopped/Manual Start]
<\??\C:\DOCUME~1\shz\LOCALS~1\Temp\tmp7.tmp><N/A>
[MSJDrvr / MSJDrvr][Running/System Start]
<system32\drivers\MSJDrvr.sys><N/A>
[Safe Mon 360 / SafeMon0][Running/System Start]
<\??\C:\WINDOWS\system32\3362C1EE.dat><N/A>
系统修复——浏览器加载项之如下项删除
[]
{6A8D34D7-08D7-421F-AFF6-956A0BD6F0BF} <C:\Program Files\Internet Explorer\PowerNeNt.Onz, N/A>
[]
{6A8D34D7-08D7-421F-AFF6-956A0BD6F0BF} <C:\Program Files\Internet Explorer\PowerNeNt.Onz, N/A>
系统目录外的其他各软件程序同目录内的usp10.dll文件,以及QQ目录内的psapi.dll文件,找到压缩上传 ,之后在本机删除(搜索时勾选系统文件和隐藏文件)http://bbs.ikaka.com/showtopic-8417665.aspx#3508975这里下载ctfmon.exe放到C:\WINDOWS\system32里
用下载的“清理临时文件工具ATF-Cleaner-cn”,全选所有项目,点击“立即清理”
下载:
http://bbs.ikaka.com/attachment.aspx?attachmentid=447126用W i n d o w s 清理助手 ,清理系统。
W i n d o w s 清理助手 下载:
http://www.arswp.com/