【回复“白天睡”的帖子】
1、用附件中的XDELBOX删除下列文件:
C:\WINDOWS\SYSTEM32\WBEM\SACH0ST.EXE
C:\WINDOWS\Winhelp.dll
C:\WINDOWS\WinHttp.dll
C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll
C:\WINDOWS\system32\avzxemn.dll
C:\WINDOWS\system32\rarjbpi.dll
C:\WINDOWS\system32\kapjbzy.dll
C:\WINDOWS\system32\FE83FA95.EXE
C:\WINDOWS\system32\803C8CFC.EXE
C:\WINDOWS\system32\433042B2.EXE
c:\windows\system32\eventrep.dll
2、重启后,用SRENG删除下列启动项、服务项:
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><avzxemn.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{6B3FCDC8-E5C7-477a-817E-72865A7758AE}><C:\WINDOWS\Winhelp.dll> [N/A]
<{36CD708B-6077-4C02-9377-D73EAA495A0F}><C:\WINDOWS\WinHttp.dll> [N/A]
<{0EA66AD2-CF26-2E23-532B-B292E22F3266}><C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll> [N/A]
<{5859245F-345D-BC13-AC4F-145D47DA34F5}><C:\WINDOWS\system32\avzxemn.dll> []
<{2598FF45-DA60-F48A-BC43-10AC47853D52}><C:\WINDOWS\system32\rarjbpi.dll> [N/A]
<{2A321487-4977-D98A-C8D5-6488257545A2}><C:\WINDOWS\system32\kapjbzy.dll> [N/A]
服务
[B4B04E4D / B4B04E4D][Stopped/Auto Start]
<C:\WINDOWS\system32\FE83FA95.EXE -B4B04E4D><Microsoft Corporation>
[E33C6DEC / E33C6DEC][Stopped/Auto Start]
<C:\WINDOWS\system32\803C8CFC.EXE -a><N/A>
[F6393144 / F6393144][Stopped/Auto Start]
<C:\WINDOWS\system32\433042B2.EXE -k><N/A>
[VisPlug and Play Removable Storage / tmsscvl][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k tmsscvl-->c:\windows\system32\eventrep.dll><N/A>