****注意:操作期间切勿双击分区盘符,应使用资源管理器或者右键打开以浏览各分区****


1,用SRE修复以下:
删除服务
[9D90CA7C / 9D90CA7C]
[C58D8536 / C58D8536]
[svchost / svchost]
[ms_2fax / ms_2fax]
删除驱动程序
[94n / 94na]
[acpidisk / acpidisk]
[epvxuj1 / epvxuj11]
[ju8qowhwa / ju8qowhwap]
[kemfshn / kemfshn]
[mxdispdr / mxdispdr]
[w9tgt5ni47 / w9tgt5ni47]
[p2pgasvj / p2pgasvj]


2,用XDelBox软件以抑制再生方式删除以下文件:
删除文件
C:\WINDOWS\DOWNLO~1\CnsMin.dll
C:\PROGRA~1\3721\helper.dll
C:\WINDOWS\SSLDyn.exe
C:\WINDOWS\AVPSrv.exE
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\mppds.exe
C:\WINDOWS\914847L.exe
C:\WINDOWS\914847M.exe
C:\WINDOWS\upxdnd.exe
C:\WINDOWS\msccrt.exe
C:\WINDOWS\LotusHlp.exe
C:\WINDOWS\MsPrint32D.exe
C:\WINDOWS\MsIMMs32.exE
C:\WINDOWS\Kvsc3.exE
C:\WINDOWS\DbgHlp32.exe
C:\WINDOWS\NVDispDRV.EXE
C:\WINDOWS\PTSShell.exe
C:\WINDOWS\system32\LYLoader.exe
C:\WINDOWS\system32\LYLoadbr.exe
C:\WINDOWS\system32\LYLeador.exe
C:\WINDOWS\system32\LYLoador.exe
C:\WINDOWS\system32\LYLoadar.exe
C:\WINDOWS\system32\LYLoadmr.exe
C:\WINDOWS\system32\LYLoadhr.exe
C:\WINDOWS\system32\LYLoadqr.exe
C:\WINDOWS\Downlo~1\j9b0b.dll
C:\WINDOWS\Downlo~1\l01.dll
C:\WINDOWS\DOWNLO~1\CnsHook.dll
C:\WINDOWS\system32\25BF4F5C.EXE
C:\WINDOWS\system32\97198366.EXE
C:\WINDOWS\system32\dllcache\svchost.exe
C:\WINDOWS\system32\cadf1.exe
C:\WINDOWS\System32\DRIVERS\94na.sys
C:\WINDOWS\system32\drivers\acpidisk.sys
C:\WINDOWS\System32\DRIVERS\epvxuj11.sys
C:\WINDOWS\System32\DRIVERS\ju8qowhwap.sys
C:\WINDOWS\System32\drivers\kemfshn.sys
C:\WINDOWS\system32\drivers\mxdispdr.sys
C:\WINDOWS\system32\drivers\w9tgt5ni47.sys
C:\Program Files\Common Files\CPUSH\cpush.dll
C:\WINDOWS\system32\5ca1.dll
C:\WINDOWS\DOWNLO~1\CnsHook.dll
C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL
C:\WINDOWS\system32\l_tax.ocx
C:\WINDOWS\DOWNLO~1\SUBMIT~1.DLL
C:\Program Files\Yiqilai\wmp\YiqilaiLyrics.dll
C:\WINDOWS\system32\2250D3C8.DLL
C:\WINDOWS\system32\winlib .dll
C:\WINDOWS\system32\msplrct.dll
C:\WINDOWS\system32\2C369672.DLL
C:\WINDOWS\system32\LYMANGR.DLL
C:\WINDOWS\system32\p2pgasvj.dll
C:\WINDOWS\system32\y1yhnvse.dll
c:\progra~1\kinn\xvaa.dll
c:\progra~1\kinn\caff.dll
C:\WINDOWS\Downlo~1\jggfe.dll
C:\WINDOWS\Downlo~1\rwunna1w.dll
C:\WINDOWS\system32\svchost.dll
C:\WINDOWS\system32\2C369672.DLL
C:\WINDOWS\system32\u7pfm.dll  ]
C:\WINDOWS\system32\vcshow.dll 
C:\WINDOWS\Downlo~1\j9b0b.dll 
C:\WINDOWS\system32\SHQMANGR.DLL
C:\WINDOWS\system32\wbem\gzsnusvnb.dll
C:\WINDOWS\system32\AVPSrv.dll
C:\WINDOWS\Downlo~1\l01.dll
C:\WINDOWS\system32\dwqysz.dll
C:\WINDOWS\system32\zorfoz.dll
C:\WINDOWS\914847MM.DLL
C:\WINDOWS\system32\pgdmgy.dll
C:\WINDOWS\system32\yqtfxt.dll
C:\WINDOWS\914847WL.DLL
C:\WINDOWS\system32\msccrt.dll
C:\WINDOWS\system32\Kvsc3.dll
C:\WINDOWS\system32\DbgHlp32.dll
C:\WINDOWS\system32\MsIMMs32.dll
C:\WINDOWS\system32\PTSShell.dll
C:\WINDOWS\system32\NVDispDrv.dll
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\SSLDyn.dll
C:\WINDOWS\system32\5ca1.dll
C:\WINDOWS\system32\NVDispDrv.dll
C:\WINDOWS\system32\yqtfxt.dll
C:\WINDOWS\system32\pgdmgy.dll
C:\WINDOWS\system32\Kvsc3.dll
c:\progra~1\kinn\usxx.dll
c:\progra~1\kinn\qott.dll
c:\progra~1\kinn\zxcc.dll
C:\WINDOWS\system32\cadf1.exe
C:\WINDOWS\system32\551.dll
C:\WINDOWS\system32\zorfoz.dll
C:\WINDOWS\system32\msccrt.dll
C:\WINDOWS\system32\5ca1.dll
C:\WINDOWS\system32\AVPSrv.dll
c:\windows\inf\usbdevices.inf
c:\autorun.inf
d:\autorun.inf
e:\autorun.inf
f:\autorun.inf
c:\auto.exe
d:\auto.exe
e:\auto.exe
f:\auto.exe


3,立即重起删除后进入系统,用SRE修复以下:
删除注册表
<CnsMin>
<helper.dll>
<SSLDyn>
<AVPSrv>
<cmdbcs>
<mppds>
<WinSysW>
<WinSysM>
<upxdnd>
<msccrt>
<LotusHlp> 
<MsPrint32D>
<MsIMMs32>
<Kvsc3> 
<DbgHlp32>
<NVDispDrv>
<PTSShell>
<MSDEG32>
<MSDWG32>
<MSDCG32>
<MSDOG32>
<MSDSG32>
<MSDMG32>
<MSDHG32>
<MSDQG32>
<j9b0b>
<l01> 
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}>
编辑<shell><Explorer.exe vchelp.exe>项为<shell><Explorer.exe>


删除浏览器加载项
[CAdLogic Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16}
[Invoke Class]
{5FB8C5D4-929F-4870-89E2-7E3EE26EE701}
[CnsHook Class]
{D157330A-9EF3-49F8-9A67-4141AC41ADD4}
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD}
[L_tax Control]
{34CA3496-FD2D-4B99-B10F-A81D862A0E10}
[AxSubmitControl Class]
{8D9E0B29-563C-4226-86C1-5FF2AE77E1D2}
[YiqilaiLyrics Class]
{7DBC6ADB-5788-4FB9-AEC3-B40A58AC11DF}


4,更新杀毒软件至最新,进行全盘杀毒。(友情提示:卡巴和瑞星一起用会发生冲突)