原来你已经搞过了,不是原装的了,呵呵
没有测试过,不知道能不能行吧,你按下面的操作试试:
删除注册表里的IFEO劫持:
<IFEO[ArSwp.exe]><C:\Program Files\Common Files\Microsoft Shared\hopjuhc.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AST.exe]
<IFEO[AST.exe]><C:\Program Files\Common Files\Microsoft Shared\hopjuhc.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe]
<IFEO[rstrui.exe]><C:\Program Files\Common Files\Microsoft Shared\hopjuhc.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USBCleaner.exe]
<IFEO[USBCleaner.exe]><C:\Program Files\Common Files\Microsoft Shared\hopjuhc.exe> [N/A]
在C:\WINDOWS\system32下找出文件:
<{B12BC423-3713-224D-3F55-32B35C62B11B}><C:\WINDOWS\system32\WinFormA7.dll> []
<{74123FF1-8371-9834-9021-184518451FA7}><C:\WINDOWS\system32\qjgpri.dll> [N/A]
<{42311A42-AC1B-158F-FD32-5674345F23A4}><C:\WINDOWS\system32\dhdpri.dll> [N/A]
<{52311A42-AC1B-158F-FD32-5674345F23A5}><C:\WINDOWS\system32\dhepri.dll> [N/A]
<{84123FF1-8371-9834-9021-184518451FA8}><C:\WINDOWS\system32\qjhpri.dll> [N/A]
<{158A147F-1FC4-24FC-BC43-FA5B345D45D1}><C:\WINDOWS\system32\pjaman.dll> [N/A]
<{5182C1EB-375C-573D-1F5E-234552345215}><C:\WINDOWS\system32\wlhpri.dll> [N/A]
<{1D47B341-43DF-4563-753F-345FFA3157D1}><C:\WINDOWS\system32\kvmxama.dll> [N/A]
<{1859245F-345D-BC13-AC4F-145D47DA34F1}><C:\WINDOWS\system32\avzxamn.dll> [N/A]
<{959AFD5B-159F-ACD8-954C-ACD545FA6589}><C:\WINDOWS\system32\jzipri.dll> [N/A]
<{E1351752-5628-1547-FFAB-BADC13512AFE}><C:\WINDOWS\system32\ztaman.dll> [N/A]
<{352D2432-37A2-324F-2A54-21BF5CF2F1A3}><C:\WINDOWS\system32\jhbpri.dll> [N/A]
<{66368135-64FA-BC34-DA32-DCF4FD431C96}><C:\WINDOWS\system32\qhfpri.dll> [N/A]
<{4F12545B-1212-1314-5679-4512ACEF8904}><C:\WINDOWS\system32\wddpri.dll> [N/A]
<{12FAACDE-34DA-CCD4-AB4D-DA34485A3421}><C:\WINDOWS\system32\rsjzapm.dll> [N/A]
<{2D47B341-43DF-4563-753F-345FFA3157D2}><C:\WINDOWS\system32\kvmxbma.dll> [N/A]
依次改名为1.DLL 2.DLL
再找出
C:\Program Files\Common Files\Microsoft Shared\MSINFO\atmQQ2.dll> [N/A]
C:\Program Files\Common Files\Microsoft Shared\hopjuhc.exe
删除(用冰刃找,或者WINRAR找出删除)(不行就改了名字再删除)
用SRENG删除服务:
[Application Management / AppMgmt][Stopped/Disabled]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>(这个随便你删不删)
[systems / systems][Stopped/Auto Start]
<C:\WINDOWS\system32\13.exe><N/A>
(这个要删了)
驱动删除:
[mimjsin / mimjsin][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\mimjsin.sys><N/A>
[mssock / mssock][Running/Manual Start]
<\??\C:\WINDOWS\system32\mssock.sys><N/A>
重起,删除文件:
C:\WINDOWS\system32\mssock.sys
C:\WINDOWS\system32\drivers\mimjsin.sys
C:\WINDOWS\system32\13.exe
删除改了名字的:
<{B12BC423-3713-224D-3F55-32B35C62B11B}><C:\WINDOWS\system32\WinFormA7.dll> []
<{74123FF1-8371-9834-9021-184518451FA7}><C:\WINDOWS\system32\qjgpri.dll> [N/A]
<{42311A42-AC1B-158F-FD32-5674345F23A4}><C:\WINDOWS\system32\dhdpri.dll> [N/A]
<{52311A42-AC1B-158F-FD32-5674345F23A5}><C:\WINDOWS\system32\dhepri.dll> [N/A]
<{84123FF1-8371-9834-9021-184518451FA8}><C:\WINDOWS\system32\qjhpri.dll> [N/A]
<{158A147F-1FC4-24FC-BC43-FA5B345D45D1}><C:\WINDOWS\system32\pjaman.dll> [N/A]
<{5182C1EB-375C-573D-1F5E-234552345215}><C:\WINDOWS\system32\wlhpri.dll> [N/A]
<{1D47B341-43DF-4563-753F-345FFA3157D1}><C:\WINDOWS\system32\kvmxama.dll> [N/A]
<{1859245F-345D-BC13-AC4F-145D47DA34F1}><C:\WINDOWS\system32\avzxamn.dll> [N/A]
<{959AFD5B-159F-ACD8-954C-ACD545FA6589}><C:\WINDOWS\system32\jzipri.dll> [N/A]
<{E1351752-5628-1547-FFAB-BADC13512AFE}><C:\WINDOWS\system32\ztaman.dll> [N/A]
<{352D2432-37A2-324F-2A54-21BF5CF2F1A3}><C:\WINDOWS\system32\jhbpri.dll> [N/A]
<{66368135-64FA-BC34-DA32-DCF4FD431C96}><C:\WINDOWS\system32\qhfpri.dll> [N/A]
<{4F12545B-1212-1314-5679-4512ACEF8904}><C:\WINDOWS\system32\wddpri.dll> [N/A]
<{12FAACDE-34DA-CCD4-AB4D-DA34485A3421}><C:\WINDOWS\system32\rsjzapm.dll> [N/A]
<{2D47B341-43DF-4563-753F-345FFA3157D2}><C:\WINDOWS\system32\kvmxbma.dll> [N/A]
清除注册表项目:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{B12BC423-3713-224D-3F55-32B35C62B11B}><C:\WINDOWS\system32\WinFormA7.dll> []
<{91B1E846-2BEF-4345-8848-7699C7C9935F}><> [N/A]
<{D544C22D-1F70-4B1E-873D-D8DABEB26695}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\atmQQ2.dll> [N/A]
<{74123FF1-8371-9834-9021-184518451FA7}><C:\WINDOWS\system32\qjgpri.dll> [N/A]
<{42311A42-AC1B-158F-FD32-5674345F23A4}><C:\WINDOWS\system32\dhdpri.dll> [N/A]
<{52311A42-AC1B-158F-FD32-5674345F23A5}><C:\WINDOWS\system32\dhepri.dll> [N/A]
<{84123FF1-8371-9834-9021-184518451FA8}><C:\WINDOWS\system32\qjhpri.dll> [N/A]
<{158A147F-1FC4-24FC-BC43-FA5B345D45D1}><C:\WINDOWS\system32\pjaman.dll> [N/A]
<{5182C1EB-375C-573D-1F5E-234552345215}><C:\WINDOWS\system32\wlhpri.dll> [N/A]
<{1D47B341-43DF-4563-753F-345FFA3157D1}><C:\WINDOWS\system32\kvmxama.dll> [N/A]
<{1C87A354-ABC3-DEDE-FF33-3213FD7447C1}><> [N/A]
<{1859245F-345D-BC13-AC4F-145D47DA34F1}><C:\WINDOWS\system32\avzxamn.dll> [N/A]
<{959AFD5B-159F-ACD8-954C-ACD545FA6589}><C:\WINDOWS\system32\jzipri.dll> [N/A]
<{E1351752-5628-1547-FFAB-BADC13512AFE}><C:\WINDOWS\system32\ztaman.dll> [N/A]
<{352D2432-37A2-324F-2A54-21BF5CF2F1A3}><C:\WINDOWS\system32\jhbpri.dll> [N/A]
<{66368135-64FA-BC34-DA32-DCF4FD431C96}><C:\WINDOWS\system32\qhfpri.dll> [N/A]
<{4F12545B-1212-1314-5679-4512ACEF8904}><C:\WINDOWS\system32\wddpri.dll> [N/A]
<{12FAACDE-34DA-CCD4-AB4D-DA34485A3421}><C:\WINDOWS\system32\rsjzapm.dll> [N/A]
<{2D47B341-43DF-4563-753F-345FFA3157D2}><C:\WINDOWS\system32\kvmxbma.dll> [N/A]
你试试看看