使用XDelBox删除以下文件
c:\windows\system32\baidgnkc.dll
c:\windows\system32\bkmegefj.dll
c:\windows\system32\ckihnjio.dll
c:\windows\system32\hokbbakn.dll
c:\windows\system32\ikdmhfho.dll
c:\windows\system32\kioiobcl.dll
c:\windows\system32\lkhdemap.dll
c:\windows\system32\pjlmhglb.dll
c:\windows\system32\1957817a.dll
c:\windows\system32\695c5a80.dll
c:\windows\system32\704c3595.dll
c:\windows\system32\76b9ba7a.dll
c:\windows\system32\a1a6bc2e.dll
c:\windows\system32\c60bc4df.dll
c:\windows\system32\cc80f0b4.dll
c:\windows\system32\e4814792.dll
c:\windows\system32\fa9b58aa.dll
c:\windows\system32\phopdabi.dll
c:\windows\system32\rbwn2dra.dll
c:\windows\system32\skj9prhxkpy.dll
C:\WINDOWS\fonts\3EFEAF36.fon
c:\docume~1\admini~1\locals~1\temp\~25a03.tmp
到正常电脑考呗 替换掉
C:\WINDOWS\system32\userinit.exe
2.删除重启后使用SREng修复下面各项:
启动项目 -- 注册表之如下项删除:
[{BA2D074C-FF80-4C20-BB6C-204D8477A9DC}] <C:\WINDOWS\system32\baidgnkc.dll>
[{9356105B-6FF8-4902-A702-8B70B3425819}] <C:\WINDOWS\system32\pjlmhglb.dll>
[{D7019B3B-ABF8-4D55-AB50-95A110373D54}] <D7019B3B.fon>
[{184BBA47-E6FD-4A70-B55F-F3A92EE3303F}] <C:\WINDOWS\system32\hokbbakn.dll>
[{C4217328-9C7E-4E3B-B964-5C6E81F73E7E}] <C:\WINDOWS\system32\ckihnjio.dll>
[{24D61F18-4D36-4BD9-87AD-14EED5A19D83}] <C:\WINDOWS\system32\ikdmhfho.dll>
[{63C8062F-BA71-44A1-8322-1C9A84783778}] <63C8062F.fon>
把 [AppInit_DLLs]<cahoicii.dll,hepeajep.dll,phopdabi.dll,ikdmhfho.dll,ckihnjio.dll,hokbbakn.dll,pjlmhglb.dll,baidgnkc.dll,kioiobcl.dll,lkhdemap.dll,bkmegefj.dll>修改为<>即清空
[{E4814792-EFA3-4C20-93D0-8B130A59F9A8}] <C:\WINDOWS\system32\E4814792.dll>
[{CC80F0B4-04D7-44D0-8DB9-9109B5B72141}] <C:\WINDOWS\system32\CC80F0B4.dll>
[{1E322963-355E-422F-BE2E-8C4667E31D10}] <C:\WINDOWS\fonts\NtkRM2essN.fon>
[{695C5A80-18A5-4CD2-A911-4DBEBE92F18D}] <C:\WINDOWS\system32\695C5A80.dll>
[{FA9B58AA-6759-4C02-B37F-572FC2F1A231}] <C:\WINDOWS\system32\FA9B58AA.dll>
[{DDFDCED2-075A-4910-986E-B2BDA2B0E916}] <C:\WINDOWS\system32\rBWN2dra.dll>
[{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8}] <C:\WINDOWS\system32\A1A6BC2E.dll>
[{3EFEAF36-B081-4454-9DE0-9023F21B2263}] <C:\WINDOWS\fonts\3EFEAF36.fon>
[{76B9BA7A-81D0-4979-8598-8471F2AB5186}] <C:\WINDOWS\system32\76B9BA7A.dll>
[9189DAB2] <C:\WINDOWS\system32\phopdabi.dll>
[{1957817A-94B2-4CAC-B113-A331809B5730}] <C:\WINDOWS\system32\1957817A.dll>
[{AE8813B0-61B3-4F6D-8F9A-7AF223E2C46E}] <C:\WINDOWS\system32\SKj9pRhxKPy.dll>
[{704C3595-DB85-40F6-A601-8D6F346907BD}] <C:\WINDOWS\system32\704C3595.dll>
[{C60BC4DF-4CAB-4F66-ABED-D3FCCE7910AD}] <C:\WINDOWS\system32\C60BC4DF.dll>
[{5ADD154A-2990-49F7-99D8-922E7D292E61}] <C:\WINDOWS\fonts\fZhqM7YJCa.fon>
[{9189DAB2-73F5-4C4B-AF04-C28C52FC6755}] <C:\WINDOWS\system32\phopdabi.dll>
启动项目 -- 服务-- 驱动程序之如下项禁用:
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~25a03.tmp>
修复 HOSTS文件-
修复映像劫持
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe]
<IFEO[360rpt.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.exe]
<IFEO[360Safe.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe]
<IFEO[360tray.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DrRtp.exe]
<IFEO[DrRtp.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctor.exe]
<IFEO[QQDoctor.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RStray.exe]
<IFEO[RStray.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]