断网执行如下操作,工具先下好
C:\WINDOWSupdate.dll
C:\WINDOWS\system32\RavMonD.exe
C:\WINDOWS\system32\dbi121.dll
C:\WINDOWS\Fonts\ykhvkgtn.dll
C:\WINDOWS\Fonts\zakpzxlk.dll
C:\WINDOWS\fonts\ftsbtdxo.dll
C:\WINDOWS\fonts\lzdfthyu.dll
C:\WINDOWS\fonts\rewrckri.dll
C:\WINDOWS\fonts\epshtjub.dll
C:\WINDOWS\fonts\hkjgjmvw.dll
C:\WINDOWS\fonts\nqewjioe.dll
C:\WINDOWS\fonts\xyrnkeic.dll
C:\WINDOWS\fonts\twatdoly.dll
C:\WINDOWS\Fonts\tpxnaqur.dll
C:\WINDOWS\fonts\vsqqmevg.dll
C:\WINDOWS\fonts\ynhpkzdb.dll
C:\WINDOWS\fonts\xghctmia.dll
C:\WINDOWS\fonts\phufzjxs.dll
C:\WINDOWS\fonts\phufzjxs.dll
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\P8RATLD5\cc4[1].exe
上面文件用XDelBox一次性删除
(enao.ys168.com 下载)
复制上面所有要删除的文件,打开XDelBox,在待删除列表点 右键==>选择 剪贴版导入不检查路径==>点 右键==>选择==>立刻重启执行删除
将C:\WINDOWS\temp\explorer.exe替换到C:\WINDOWS\Explorer.EXE,替换方法和工具见
http://bbs.ikaka.com/showtopic-8442813-2.aspx 11楼
删除注册表项目
<RavMonD.exe><C:\WINDOWS\system32\RavMonD.exe> [番茄花园]
<{815EDE81-767D-4636-80F5-141578667A98}><C:\WINDOWS\fonts\xghctmia.dll> []
<{5AF04671-190D-4D5C-97AF-D8054F831E27}><C:\WINDOWS\fonts\ynhpkzdb.dll> []
<{C85CB78B-8D31-4C27-8533-149683423BF7}><C:\WINDOWS\fonts\vsqqmevg.dll> []
<{DF12F8AB-9A00-469C-B9D4-425C1BE3E1E6}><C:\WINDOWS\Fonts\tpxnaqur.dll> []
<{7B473157-ABA4-4222-8505-42F5D34EF824}><C:\WINDOWS\fonts\twatdoly.dll> []
<{CCCA2FB9-2D5D-4481-8BFE-1CDDC458A3F4}><CCCA2FB9.dll> [N/A]
<{DFEAF1AB-1B26-4ACF-A97A-BEF452ACBB4F}><C:\WINDOWS\fonts\xyrnkeic.dll> []
<{42CC4CC3-854C-437C-94EC-3E629F656F3F}><C:\WINDOWS\fonts\nqewjioe.dll> []
<{F01CD512-AE66-45BD-B182-EED2D68E9FA2}><C:\WINDOWS\fonts\hkjgjmvw.dll> []
<{DCBC4DF7-09A8-42D0-BCF4-299F72F40EAD}><C:\WINDOWS\fonts\epshtjub.dll> []
<{E58B05EE-6CA5-42E1-A0CE-82169DDEE42C}><C:\WINDOWS\fonts\rewrckri.dll> []
<{4EAA8F86-4217-48D0-A976-389247780A14}><C:\WINDOWS\fonts\lzdfthyu.dll> []
<{7E94C114-C874-4112-9922-054D8E5546E2}><C:\WINDOWS\fonts\ftsbtdxo.dll> []
<{2DF5DA5E-22B9-4936-A652-2C84340181D4}><2DF5DA5E.dll> [N/A]
<{CC0EC2C9-432D-4DCC-91E7-A7C5CEA748D8}><CC0EC2C9.dll> [N/A]
<{01C52313-FF03-413E-A148-665C199D3279}><C:\WINDOWS\Fonts\cvaopsun.dll> [File is missing]
<{3CA7A137-35F8-46CD-B83B-534CD13D5A67}><C:\WINDOWS\Fonts\zakpzxlk.dll> []
<{77AC4257-6781-430B-80C1-BCA6D20C950F}><C:\WINDOWS\fonts\phufzjxs.dll> []
<C:\WINDOWS\Fonts\ftgcwsdi.dll><> [N/A]
<C:\WINDOWS\fonts\yovyopcc.dll><C:\WINDOWS\fonts\xghctmia.dll> []
<C:\WINDOWS\Fonts\emsgbqjn.dll><> [N/A]
<C:\WINDOWS\fonts\xghctmia.dll><C:\WINDOWS\fonts\xghctmia.dll> []
<C:\WINDOWS\fonts\hkjgjmvw.dll><C:\WINDOWS\fonts\hkjgjmvw.dll> []
<C:\WINDOWS\fonts\epshtjub.dll><C:\WINDOWS\fonts\epshtjub.dll> []
<C:\WINDOWS\Fonts\ykhvkgtn.dll><C:\WINDOWS\Fonts\ykhvkgtn.dll> []
<C:\WINDOWS\fonts\rewrckri.dll><C:\WINDOWS\fonts\rewrckri.dll> []
<C:\WINDOWS\fonts\lzdfthyu.dll><C:\WINDOWS\fonts\lzdfthyu.dll> []
<C:\WINDOWS\fonts\ftsbtdxo.dll><C:\WINDOWS\fonts\ftsbtdxo.dll> []
<C:\WINDOWS\fonts\ynhpkzdb.dll><C:\WINDOWS\fonts\ynhpkzdb.dll> []
<C:\WINDOWS\fonts\vsqqmevg.dll><C:\WINDOWS\fonts\vsqqmevg.dll> []
<C:\WINDOWS\Fonts\tpxnaqur.dll><C:\WINDOWS\Fonts\tpxnaqur.dll> []
<C:\WINDOWS\fonts\twatdoly.dll><C:\WINDOWS\fonts\twatdoly.dll> []
<C:\WINDOWS\fonts\xyrnkeic.dll><C:\WINDOWS\fonts\xyrnkeic.dll> []
<C:\WINDOWS\fonts\nqewjioe.dll><C:\WINDOWS\fonts\nqewjioe.dll> []
<C:\WINDOWS\Fonts\cvaopsun.dll><C:\WINDOWS\Fonts\cvaopsun.dll> [File is missing]
<C:\WINDOWS\Fonts\zakpzxlk.dll><C:\WINDOWS\Fonts\zakpzxlk.dll> []
<C:\WINDOWS\fonts\phufzjxs.dll><C:\WINDOWS\fonts\phufzjxs.dll> []
删除服务
[NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
<><(File is missing)>
[Security Control / sectolr][Stopped/Auto Start]
<c:\windows\system32\rundll32.exe dbi121.dll,kutfhjpo><Microsoft Corporation>