1.用帖子里提供的工具删除以下文件(http://bbs.ikaka.com/showtopic-8442813.aspx)c:\windows\system32\fhdoor0.dll
c:\documents and settings\administrator\「开始」菜单\程序\启动\qq.lnk
c:\windows\system32\drivers\winsys.sys
c:\windows\system32\drivers\msaclue.sys
c:\program files\common files\fjos0r.dll
c:\program files\internet explorer\plugins\nvsys_55.sys
c:\windows\system32\csavpw1.dll
c:\program files\internet explorer\plugins\wn_sys8x.sys
c:\windows\fonts\gjcsdyc.dll
c:\windows\system32\igb_wd_1026.dll
c:\windows\fonts\avzxomn.dll
c:\windows\system32\qsdoor0.dll
c:\windows\system32\qzdoor0.dll
c:\windows\system32\qhdoor0.dll
c:\windows\system32\mndoor0.dll
c:\program files\internet explorer\onlo0r.dll
c:\windows\system\qq.exe
c:\windows\system\sitaplugin.dll
2.不管删除是否成功,请重启,然后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[{80F15C30-5E9D-4CB9-BE85-F3D5564C6F83}] <C:\WINDOWS\system32\fhdoor0.dll>
[{471B15AD-7A9C-491D-9C19-4E15B12DCE00}] <C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Sys>
[{8DFA2904-9664-43AE-8929-4347554D24B6}] <C:\WINDOWS\system32\csavpw1.dll>
[{9963387B-212E-4643-B207-82DAEA0E713D}] <C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys>
[{4FA10261-B890-F432-A453-69F1023513F4}] <C:\WINDOWS\Fonts\gjcsdyc.dll>
[{76255dcf-d686-4d89-82d1-78fef7b3dc00}] <C:\WINDOWS\system32\IGB_WD_1026.dll>
[{F859245F-345D-BC13-AC4F-145D47DA34FF}] <C:\WINDOWS\Fonts\avzxomn.dll>
[{C26A8AB5-B935-400C-A152-0488714725B1}] <C:\WINDOWS\system32\qsdoor0.dll>
[{49C496E9-732D-4F5D-BEE9-EC113FAA1C97}] <C:\WINDOWS\system32\qzdoor0.dll>
[{ABD0935D-B35A-47BD-BA9A-81678DDE74DD}] <C:\WINDOWS\system32\qhdoor0.dll>
[{61C1B9CE-1A6F-4994-B4A4-0E7C99AD4C28}] <C:\WINDOWS\system32\mndoor0.dll>
[{CC3596CB-D6C1-ECA1-AE51-DEEA63F6C21C}] <C:\Program Files\Internet Explorer\OnlO0r.dll>
[QQ] <C:\WINDOWS\system\QQ.exe>
注意该项[Userinit]修改:把<userinit.exe,>修改为<C:\WINDOWS\system32\userinit.exe,>逗号不可省略
启动项目 -- 启动文件夹之如下项删除:
[QQ] <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\QQ.lnk>
启动项目 -- 服务-- 驱动程序之如下项禁用:
[Network Monitor Protocol Driver / Ndisprot] <system32\DRIVERS\winsys.sys>
[msskye / msskye] <system32\DRIVERS\msaclue.sys>
系统修复-- 浏览器加载项之如下项删除:
[] <C:\Program Files\Common Files\fjOs0r.dll>
[] <C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys>
[] <C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Sys>
[EyeOnIE Class] <C:\windows\system\SitaPlugin.dll>