点击下载雨林木风PE安装包进行安装以防止误操作删除系统文件无法进入系统时的修复,并在安装完成后重起一次确认可以正常进入PE系统后继续以下操作。http://bbs.ikaka.com/showtopic-8502100.aspx参考这里下载PE、“费尔……助手”、大蜘蛛后安装PE重起进入PE删除以下文件,并复制c:\windows\system32\dllcache\explorer.exe粘贴到c:\windows\
c:\windows\system32\msoscqit00.dll
c:\windows\system32\msosdohs00.dll
c:\windows\system32\msosdrop00.dll
c:\windows\system32\msosfmsq00.dll
c:\windows\system32\msosjtio00.dll
c:\windows\system32\msosmnsf00.dll
c:\windows\system32\msosping00.dll
c:\windows\system32\msosptfs00.dll
c:\windows\system32\oohxbbyt.dll
c:\windows\system32\crugd.dll
c:\windows\system32\hfjg.dll
c:\progra~1\3721\helper.dll
c:\windows\downlo~1\cnsio.dll
c:\windows\downlo~1\cnsmin.dll
c:\windows\downlo~1\cnsminex.dll
c:\windows\downlo~1\cnsminio.dll
c:\windows\system32\mxavpw0.dll
c:\windows\system32\ptshell.dll
c:\windows\system32\rgfjj.dll
c:\windows\system32\sperls.dll
c:\windows\system32\ydgn.dll
c:\windows\system32\zjydcx.dll
c:\windows\system32\zptlbsys.dll
c:\windows\soundman.exe
c:\windows\system32\explorer.exe
c:\progra~1\3721\alrex.dll
c:\progra~1\3721\autolive.dll
c:\windows\downlo~1\cnshook.dll
c:\windows\system32\anistio.dll
c:\windows\system32\bincdwsa.dll
c:\windows\system32\cinfonmc.dll
c:\windows\system32\dbhlp32.dll
c:\windows\system32\dionpis.dll
c:\windows\system32\dndsioc.dll
c:\windows\system32\fiosectc.dll
c:\windows\system32\fmbiost.dll
c:\windows\system32\fmsbbqi.dll
c:\windows\system32\fmsiocps.dll
c:\windows\system32\fmsjhif.dll
c:\windows\system32\gjcscyc.dll
c:\windows\system32\hefxxxy.dll
c:\windows\system32\huifitc.dll
c:\windows\system32\issms32.dll
c:\windows\system32\mfchlp64.dll
c:\windows\system32\mqjkpz.dll
c:\windows\system32\rzysdhbx.dll
c:\windows\system32\tciocp64.dll
c:\windows\system32\winsvr64.dll
c:\windows\system32\wsockdrv32.dll
c:\windows\system32\yuiabct.dll
c:\windows\system32\hbkrnl.dll
c:\progra~1\3721\scrblock.dll
c:\windows\downlo~1\cnshint.dll
c:\windows\downlo~1\cnsplus.dll
c:\program files\tencent\ssplus\saddr1.dll
c:\program files\internet explorer\plugins\nt_sys32.sys
c:\windows\system32\msosdohs00.dll
c:\windows\system32\msosmhfp00.dll
c:\windows\cinfonmc.exe
c:\windows\fmbiost.exe
c:\windows\winsvr64.exe
c:\windows\dndsioc.exe
c:\windows\mfchlp64.exe
c:\windows\yuiabct.exe
c:\windows\ptshell.exe
c:\windows\gwsmhxuq.exe
c:\windows\fmsjhif.exe
c:\windows\dbhlp32.exe
c:\windows\bincdwsa.exe
c:\windows\fmsbbqi.exe
c:\windows\tciocp64.exe
c:\windows\hefxxxy.exe
c:\windows\dionpis.exe
c:\windows\issms32.exe
c:\windows\anistio.exe
c:\windows\fmsiocps.exe
c:\windows\fiosectc.exe
c:\windows\system32\hbkrnl.dll
c:\windows\wsockdrv32.exe
c:\progra~1\tencent\ssplus\splus.dll
c:\windows\downlo~1\cnsmin.dll,rundll32
c:\windows\system32\interne.exe
c:\windows\\systemroot\system32\drivers\6651375.sys
c:\docume~1\new\locals~1\temp\tmp1a.tmp
c:\docume~1\new\locals~1\temp\tmp17.tmp
c:\docume~1\new\locals~1\temp\tmp14.tmp
c:\docume~1\new\locals~1\temp\tmp12.tmp
c:\docume~1\new\locals~1\temp\tmpf.tmp
c:\docume~1\new\locals~1\temp\tmpa.tmp
c:\docume~1\new\locals~1\temp\tmp7.tmp
c:\docume~1\new\locals~1\temp\tmp4.tmp
c:\windows\system32\drivers\zdpbyti.sys
c:\windows\\systemroot\system32\drivers\kakcpco.sys
c:\windows\system32\drivers\hbkernel.sys
c:\windows\system32\drivers\cnsminkp.sys
d:\thunder network\thunder\comdlls\tdatonce_now.dll
c:\windows\system32\ssup.dll
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[{3FA10261-B890-F432-A453-69F1023513F3}]
[{40940F85-F015-14F1-A05F-F69858AC6D04}]
[{3E387664-C799-4D62-B196-25776EF35C51}]
[{45AADFAA-DD36-42AB-83AD-0521BBF58C24}]
[{398C9B84-4EF7-47B5-9862-DE29543B3C42}]
[{3B1AEF69-DDAE-FDAD-DCAB-698F026ABDB3}]
[{4BAB150F-DD97-476D-9C1E-41B6CDC0CA7A}]
注意该项[AppInit_DLLs]修改:把<msosdohs00.dll,msosmhfp00.dll>修改为<>即清空
[cinfonmc]
[fmbiost]
[WINSvr64]
[dndsioc]
[mfchlp64]
[yuiabct]
[ptshell]
[igzwzslm]
[fmsjhif]
[dbhlp32]
[bincdwsa]
[fmsbbqi]
[tciocp64]
[hefxxxy]
[dionpis]
[issms32]
[anistio]
[fmsiocps]
[fiosectc]
[HB Kernel]
[WSockDrv32]
[{D157330A-9EF3-49F8-9A67-4141AC41ADD4}]
[stup.exe]
[SoundMan]
[CnsMin]
[IFEO[360Loader.exe]]
[IFEO[360Safe.exe]]
[IFEO[360tray.exe]]
[IFEO[ctfmon.exe]]
[IFEO[IceSword]]
[IFEO[Iparmor.exe]]
[IFEO[kmailmon.exe]]
[IFEO[ras]]
[IFEO[runiep]]
启动项目 -- 服务 -- Win32服务应用程序之如下项删除:
[Help and Support / helpsvc]
启动项目 -- 服务-- 驱动程序之如下项删除:
[00 / 00]
[jtio / jtio]
[drop / drop]
[fmsq / fmsq]
[ping / ping]
[ptfs / ptfs]
[mnsf / mnsf]
[cqit / cqit]
[dohs / dohs]
[msfpfis64 / msfpfis64]
[msfpfis64 / msfpfis64]
[zdpbyti / zdpbyti]
[kakcpco / kakcpco]
[HBKernel Driver / HBKernel]
[CnsMinKP / CnsMinKP]
系统修复-- 浏览器加载项之如下项删除:
[] <C:\WINDOWS\system32\zptlbsys.dll>
[] <C:\WINDOWS\system32\oohxbbyt.dll>
[] <C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys>
[] <C:\WINDOWS\system32\zptlbsys.dll>
[] <C:\WINDOWS\system32\oohxbbyt.dll>
[ThunderAtOnce Class] <d:\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll>
[] <C:\Program Files\Internet Explorer\PLUGINS\Nt_Sys32.Sys>
[CnsHook Class] <C:\WINDOWS\downlo~1\CnsHook.dll>
[AutoLive] <C:\PROGRA~1\3721\autolive.dll>
[CnsHook Class] <C:\WINDOWS\downlo~1\CnsHook.dll>
[] <C:\WINDOWS\system32\SSup.dll>
[] <C:\WINDOWS\system32\SSup.dll>
最后下载以下软件清理一次并更新杀毒软件至最新,进行全盘杀毒
清理系统临时文件和IE临时文件夹
http://www.atribune.org/public-beta/ATF-Cleaner.exe 用金山清理专家清理恶意软件
http://www.duba.net/zt/ksc/down.shtml 下载 windows清理助手清理一遍
http://www.arswp.com/download/arswp2/arswp2.zip