1.删除以下文件:
先将c:\windows\explorer.exe更名为123.exe
c:\windows\system32\msplrct.dll
c:\windows\system32\ratblpi.dll
c:\windows\system32\winlib .dll
c:\windows\system32\e5e1.dll
c:\windows\system32\5ea41.exe
c:\windows\system32\8e1.dll
c:\windows\123.exe
c:\progra~1\tencent\ssplus\splus.dll
c:\windows\system\logogogo.exe
c:\progra~1\yahoo!\assistant\yassistse.exe
c:\progra~1\yahoo!\assist~1\ylive.exe
c:\windows\genprotect.exe
c:\windows\xoaivj.exe
c:\progra~1\cnrn\rnmain.exe
c:\progra~1\cnrn\cnrn.dll
c:\progra~1\cnrn\rnevent.dll
c:\progra~1\cnrn\rnmain.exe c:\progra~1\cnrn\rnhelper.dll,rundll32
c:\windows\system32\792405c6.exe
c:\windows\system32\2dd519ed.exe
c:\documents and settings\all users\application data\microsoft\office\system\sysloader.exe
c:\program files\microsoft office\system\[email]kzdh@webbrowser-lyrics_3102.exe
c:\windows\system32\drivers\9hv06xar.sys
c:\windows\system32a2.sys
c:\windows\system32\drivers\msaclue.sys
c:\windows\system32\drivers\msyecp.sys
c:\windows\system32\drivers\msacpe.sys
c:\windows\system32\drivers\ks6ug1k.sys
c:\windows\system32\drivers\oea8ik0hr.sys
c:\windows\system32\drivers\oc5n.sys
c:\windows\system32\hookhelp.sys
c:\windows\system32\drivers\dewtojn.sys
c:\windows\system32\drivers\bdguard.sys
c:\windows\system32\drivers\acpidisk.sys
c:\windows\system32\drivers\cnrndv.sys
c:\windows\system32\drivers\lvqxukro.sys
c:\windows\system32\drivers\yaskp.sys
c:\progra~1\yahoo!\assist~1\assist\yasbar.dll
c:\progra~1\yahoo!\assist~1\assist\yrss.dll
c:\progra~1\yahoo!\assist~1\assist\yassist.dll
c:\progra~1\yahoo!\assist~1\assist\yflashdl.dll
c:\windows\system32\iebho.dll
c:\windows\system32\ietool.dll
c:\program files\common files\microsoft shared\msinfo\system76.ins
c:\program files\internet explorer\plugins\wn_sys8x.sys
c:\progra~1\yahoo!\assist~1\assist\ydrags~1.dll
c:\progra~1\yahoo!\assist~1\assist\yasbar.dll
c:\progra~1\yahoo!\assist~1\assist\yangling.dll
c:\progra~1\yahoo!\assist~1\assist\yphtb.dll
c:\program files\common files\cpush\cpush.dll
c:\program files\yiqilai\wmp\yiqilailyrics.dll
c:\progra~1\baidu\bar\baidubar.dll
c:\progra~1\cnrn\cnrn.dll
c:\documents and settings\all users\application data\microsoft\office\userdata\p2t5jq5ufg.dll
c:\program files\tencent\ssplus\saddr.dll
c:\documents and settings\all users\application data\microsoft\pctools\pctools.dll
d:\program files\qqdownload\qqiehelper01.dll
2.删除重启后使用SREng修复下面各项:
启动项目 -- 注册表之如下项删除:
[{C6650011-3344-6688-4899-345FABCD156C}] <C:\WINDOWS\system32\ratblpi.dll>
注意该项[AppInit_DLLs]修改:把<ratblpi.dll>修改为<>即清空
[stup.exe] <; Rundll32.exe C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll,Rundll32 R>
[logogogo] <C:\WINDOWS\system\logogogo.exe>
[yassistse] <C:\progra~1\yahoo!\assistant\yassistse.exe>
[YLive.exe] <C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[GenProtect] <C:\WINDOWS\GenProtect.exe>
[MsPrint32D] <C:\WINDOWS\xoaivj.exe>
[CNRN] <C:\PROGRA~1\CNRN\RNMain.exe C:\PROGRA~1\CNRN\CNRN.dll,Rundll32>
[{D7B21266-AA85-44b8-B516-3B1A69827400}] <C:\PROGRA~1\CNRN\RNEvent.dll>
[CNRNRNHelper.dll] <C:\PROGRA~1\CNRN\RNMain.exe C:\PROGRA~1\CNRN\RNHelper.dll,Rundll32>
[IFEO[ACKWIN32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[ANTI-TROJAN.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[APVXDWIN.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AUTODOWN.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVCONSOL.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVE32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVGCTRL.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVKSERV.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVNT.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVP.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVP32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVPCC.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVPDOS32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVPM.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVPTC32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVPUPD.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVSCHED32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVWIN95.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[AVWUPD32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[BLACKD.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[BLACKICE.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[CFIADMIN.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[CFIAUDIT.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[CFINET.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[CFINET32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[CLAW95.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[CLAW95CF.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[CLEANER.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[CLEANER3.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[DVP95.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[DVP95_0.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[ECENGINE.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[EGHOST.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[ESAFE.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[EXPWATCH.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[F-AGNT95.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[F-PROT.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[F-PROT95.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[F-STOPW.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[FESCUE.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[FINDVIRU.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[FP-WIN.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[FPROT.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[FRW.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[IAMAPP.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[IAMSERV.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[IBMASN.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[IBMAVSP.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[ICLOAD95.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[ICLOADNT.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[ICMON.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[ICSUPP95.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[ICSUPPNT.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[IFACE.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[IOMON98.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[IPARMOR.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[JEDI.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[KAV32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[KAVPFW.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[KAVSVC.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[KAVSVCUI.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[KVFW.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[KVMONXP.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[KVMONXP.KXP]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[KVSRVXP.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[KVWSC.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[KVXP.KXP]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[KWATCHUI.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[LOCKDOWN2000.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[Logo1_.exe]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[Logo_1.exe]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[LOOKOUT.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[LUALL.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[MAILMON.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[MOOLIVE.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[MPFTRAY.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[N32SCANW.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[NAVAPSVC.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[NAVAPW32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[NAVLU32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[NAVNT.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[NAVW32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[NAVWNT.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[NISUM.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[NMAIN.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[NORMIST.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[NUPGRADE.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[NVC95.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[PAVCL.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[PAVSCHED.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[PAVW.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[PCCWIN98.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[PCFWALLICON.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[PERSFW.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[PFW.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[RAV7.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[RAV7WIN.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[RAVTIMER.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[RISING.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[SAFEWEB.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[SCAN32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[SCAN95.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[SCANPM.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[SCRSCAN.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[SERV95.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[SMC.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[SPHINX.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[SWEEP95.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[TBSCAN.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[TCA.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[TDS2-98.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[TDS2-NT.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[THGUARD.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[TROJANHUNTER.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[VET95.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[VETTRAY.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[VSCAN40.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[VSECOMR.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[VSHWIN32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[VSSTAT.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[WEBSCANX.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[WFINDV32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[ZONEALARM.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[_AVP32.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[_AVPCC.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[_AVPM.EXE]] <C:\WINDOWS\system\logogogo.exe>
[IFEO[修复工具.EXE]] <C:\WINDOWS\system\logogogo.exe>
启动项目 -- 服务 -- Win32服务应用程序之如下项删除:
[286EE121 / 286EE121] <C:\WINDOWS\system32\792405C6.EXE -k>
[AEA6EAEC / AEA6EAEC] <C:\WINDOWS\system32\2DD519ED.EXE -p>
[MS_2FAX / MS_2FAX] <C:\WINDOWS\system32\5ea41.exe>
[Windows Media Player Network Sharing Service / WMPNetworkSvc] <>
[Windows Media Player Network Sharing Service / WMPNetworkSvc] <>
[System Event loader / SYSLOADER] <"C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\sysloader.exe">
[Windows Advanced Manager / WAMER] <"C:\Program Files\Microsoft Office\SYSTEM\kzdh@webbrowser-lyrics_3102.exe">
启动项目 -- 服务-- 驱动程序之如下项删除:
[9hv06xa / 9hv06xar] <\SystemRoot\System32\DRIVERS\9hv06xar.sys>
[R2A / R2A] <\??\C:\WINDOWS\system32a2.sys>
[msskye / msskye] <system32\drivers\msaclue.sys>
[msertk / msertk] <system32\drivers\msyecp.sys>
[mseqsy / mseqsy] <system32\DRIVERS\msacpe.sys>
[ks6ug1 / KS6UG1K] <\SystemRoot\System32\DRIVERS\ks6ug1k.sys>
[oea8ik0hr / oea8ik0hr] <\??\C:\WINDOWS\system32\drivers\oea8ik0hr.sys>
[OC5N / OC5N] <\??\C:\WINDOWS\system32\drivers\oc5n.sys>
[HookHelp / HookHelp] <\??\C:\WINDOWS\system32\HookHelp.sys>
[DEWTOJN / DEWTOJN] <\SystemRoot\system32\drivers\dewtojn.sys>
[BDGUARD / BDGUARD] <\SystemRoot\system32\drivers\BDGuard.SYS>
[ACPIDISK / ACPIDISK] <\??\C:\WINDOWS\system32\drivers\acpidisk.sys>
[CNRNDV / CNRNDV] <\SystemRoot\system32\drivers\CNRNDV.sys>
[lvqxukro / lvqxukro] <\SystemRoot\System32\DRIVERS\lvqxukro.sys>
[yaskp / yaskp] <\SystemRoot\system32\drivers\yaskp.sys>
系统修复-- 浏览器加载项之如下项删除:
[雅虎搜索] <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/203>
[添加到雅虎订阅(&Y)] <res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT>
[assist] <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll>
[yFlashDl Class] <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yflashdl.dll>
[SrchHook Class] <C:\WINDOWS\system32\IEBHO.dll>
[快捷工具条3.2] <C:\WINDOWS\system32\IETool.dll>
[] <C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins>
[] <C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys>
[DragSearch BHO] <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL>
[Invoke Class] <C:\WINDOWS\system32\e5e1.dll>
[雅虎助手] <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll>
[AntiFish Class] <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll>
[Yahoo!Photo] <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll>
[CAdLogic Object] <C:\Program Files\Common Files\CPUSH\cpush.dll>
[快捷工具条3.2] <C:\WINDOWS\system32\IETool.dll>
[一起来音乐社区] <http://www.yiqilai.com>
[情景 聊天] <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg>
[雅虎 WIDGET] <http://cn.widget.yahoo.com/index.htm?source=Cns>
[雅虎助手] <http://cn.zs.yahoo.com/start.htm ... &btn=yassistnew>
[] <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair>
[Yahoo 3.5G 电邮] <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail>
[名品 折扣] <http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138>
[] <http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean>
[assist] <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll>
[yFlashDl Class] <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yflashdl.dll>
[SrchHook Class] <C:\WINDOWS\system32\IEBHO.dll>
[] <C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins>
[DragSearch BHO] <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL>
[Invoke Class] <C:\WINDOWS\system32\e5e1.dll>
[AntiFish Class] <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll>
[Yahoo!Photo] <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll>
[CAdLogic Object] <C:\Program Files\Common Files\CPUSH\cpush.dll>
[YiqilaiLyrics Class] <C:\Program Files\Yiqilai\wmp\YiqilaiLyrics.dll>
[BandIE Class] <C:\PROGRA~1\baidu\bar\baidubar.dll>
[Tool Class] <C:\PROGRA~1\baidu\bar\baidubar.dll>
[百度超级搜霸] <C:\PROGRA~1\baidu\bar\baidubar.dll>
[BandIE Class] <C:\PROGRA~1\baidu\bar\baidubar.dll>
[] <C:\PROGRA~1\CNRN\RNEvent.dll>
[] <C:\PROGRA~1\CNRN\CNRN.dll>
[Adobe Common Objects] <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\P2T5Jq5Ufg.dll>
[Tencent Browser Helper] <C:\Program Files\TENCENT\SSPlus\SAddr.dll>
[Info cache] <C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll>
[Adobe Common Objects] <C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\P2T5Jq5Ufg.dll>
[] <C:\PROGRA~1\CNRN\RNEvent.dll>
[QQCycloneHelper Class] <D:\Program Files\QQDownload\QQIEHelper01.dll>
[百度超级搜霸] <C:\PROGRA~1\baidu\bar\baidubar.dll>