删除注册表中
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<explorer><`.vbe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{A693A5AB-BDBA-4AE7-A1C8-E41FEE1C020B}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins> [N/A]
<{A7D81718-1314-5200-2597-58790101807A}><C:\WINDOWS\system32\kaqhjzy.dll> [N/A]
<{592FADFA-BCDE-ACDF-CDEF-21054865CBA5}><C:\WINDOWS\system32\wsmsczx.dll> [N/A]
<{8859245F-345D-BC13-AC4F-145D47DA34F8}><C:\WINDOWS\system32\avzxhmn.dll> [N/A]
<{AC87A354-ABC3-DEDE-FF33-3213FD7447CA}><C:\WINDOWS\system32\kvdxjma.dll> [N/A]
<{6A1247C1-53DA-FF43-ABD3-345F323A48D6}><C:\WINDOWS\system32\avwgfmn.dll> [N/A]
<{AD561258-45F3-A451-F908-A258458226DA}><C:\WINDOWS\system32\kvdxsjma.dll> [N/A]
<{48847374-8323-FADC-B443-4732ABCD3784}><C:\WINDOWS\system32\sidjdzy.dll> [N/A]
<{678A7521-FA87-34AB-34C2-4893F3AD34C6}><C:\WINDOWS\system32\swrcezc.dll> [N/A]
<{25679330-4034-9021-7012-909856721372}><C:\WINDOWS\system32\wszjbzx.dll> [N/A]
<{5A321487-4977-D98A-C8D5-6488257545A5}><C:\WINDOWS\system32\kapjezy.dll> [N/A]
打开XDelbox勾选“抑制再生”。
把以下路径添加进去(或者复制下面路径然后点xdelbox右键"从剪贴板导入),然后点右键,立即重启并删除.
C:\WINDOWS\system32\kaqhjzy.dll
C:\WINDOWS\system32\wsmsczx.dll
C:\WINDOWS\system32\avzxhmn.dll
C:\WINDOWS\system32\kvdxjma.dll
C:\WINDOWS\system32\avwgfmn.dll
C:\WINDOWS\system32\kvdxsjma.dll
C:\WINDOWS\system32\sidjdzy.dll
C:\WINDOWS\system32\swrcezc.dll
C:\WINDOWS\system32\wszjbzx.dll
C:\WINDOWS\system32\kapjezy.dll
修复文件关联
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
入口点错误:LoadLibraryExW