用xdelbox删除以下文件
C:\WINDOWS\system32\kiluw.dll
C:\WINDOWS\system32\jemnaw.dll
C:\WINDOWS\system32\cuhad.dll
C:\WINDOWS\system32\laixuhz.dll
C:\WINDOWS\system32\duygnef.dll
C:\WINDOWS\system32\tsqc.dll
C:\WINDOWS\system32\pahzij.dll
C:\WINDOWS\system32\xptyj.dll
C:\Program Files\Internet Explorer\PLUGINS\NewSys55.Sys
C:\WINDOWS\system32\fmcvxy.dll
C:\WINDOWS\SoundMan.exe
C:\WINDOWS\system32\mswmgog32.dll
C:\WINDOWS\system32\HHHCompress.dll
C:\WINDOWS\popo.exe
C:\winsysupd12.exe
C:\WINDOWS\system32\csrssX.exe
C:\WINDOWS\system32\hfrdzx.dll
C:\WINDOWS\system32\wrqszl.dll
C:\WINDOWS\system32\jfrwdh.dll
C:\WINDOWS\system32\zgxfdx.dll
C:\WINDOWS\system32\hhrdxd.dll
C:\WINDOWS\system32\mfdesy.dll
C:\WINDOWS\system32\jhfrxz.dll
C:\WINDOWS\system32\sgrefg.dll
C:\WINDOWS\system32\wyrsdj.dll
C:\WINDOWS\system32\fmcvxy.dll
C:\WINDOWS\system32\fedadh.dll
C:\WINDOWS\system32\msosiocp.dll
C:\WINDOWS\WSockDrv32.exe
C:\WINDOWS\MsIMMs32.exE
C:\WINDOWS\AVPSrv.exE
C:\WINDOWS\upxdnd.exe
C:\WINDOWS\SHAProc.exe
C:\WINDOWS\Kvsc3.exE
C:\WINDOWS\msccrt.exe
C:\WINDOWS\DbgHlp32.exe
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\arwgptjx.exe
C:\WINDOWS\PTSShell.exe
C:\WINDOWS\LotusHlp.exe
C:\WINDOWS\WINSvr32.exE
C:\WINDOWS\sniffer.exe
C:\WINDOWS\System32\QQ.exe
C:\WINDOWS\system32\drivers\00005053.SYS
C:\DOCUME~1\lenovo\LOCALS~1\Temp\tmp8E.tmp
C:\DOCUME~1\lenovo\LOCALS~1\Temp\tmp7F.tmp
C:\WINDOWS\system32\drivers\msosfpids32.sys
C:\Program Files\Rising\Rfw\HookUrl.sys
C:\DOCUME~1\lenovo\LOCALS~1\Temp\2.sys
C:\DOCUME~1\lenovo\LOCALS~1\Temp\tmp6F.tmp
C:\DOCUME~1\lenovo\LOCALS~1\Temp\tmp1F.tmp
C:\DOCUME~1\lenovo\LOCALS~1\Temp\tmp1E8.tmp
C:\WINDOWS\System32\new.sys
C:\WINDOWS\system32\drivers\qcrcsal.sys
打开SREng->启动项目->注册表->删除以下启动项目
<winsysupd><C:\\winsysupd12.exe> [N/A]
<SoundMan><SOUNDMAN.EXE> [1]
<Microsoft CSRSS Service><csrssX.exe> [N/A]
<{1DB3C525-5271-46F7-887A-D4E1ADAA7632}><C:\WINDOWS\system32\hfrdzx.dll> [N/A]
<{F99DEFDD-200B-4410-B572-E90883D527D2}><C:\WINDOWS\system32\wrqszl.dll> [N/A]
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> [N/A]
<{6E6CA8A1-81BC-4707-A54C-F4903DD70BAD}><C:\WINDOWS\system32\zgxfdx.dll> [N/A]
<{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}><C:\WINDOWS\system32\hhrdxd.dll> [N/A]
<{DC3D30AE-0380-4151-8934-EE98A34B0370}><C:\WINDOWS\system32\mfdesy.dll> [N/A]
<{7914E0AA-ECCB-4311-B584-C49538227824}><C:\WINDOWS\system32\jhfrxz.dll> [N/A]
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgrefg.dll> [N/A]
<{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}><C:\WINDOWS\system32\wyrsdj.dll> [N/A]
<{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7}><C:\WINDOWS\system32\fmcvxy.dll> []
<{27D89EDA-2197-4DFC-B3DC-AF22C6CA23BB}><C:\WINDOWS\system32\fedadh.dll> [N/A]
<{D29DCEE0-457B-45A2-A92D-741B95B7723B}><C:\Program Files\Internet Explorer\PLUGINS\NewSys55.Sys> []
<{50632D5C-B71B-4ba0-B012-3DC6F15C011B}><C:\WINDOWS\system32\msosiocp.dll> []
<WSockDrv32><C:\WINDOWS\WSockDrv32.exe> []
<MsIMMs32><C:\WINDOWS\MsIMMs32.exE> []
<AVPSrv><C:\WINDOWS\AVPSrv.exE> []
<upxdnd><C:\WINDOWS\upxdnd.exe> []
<SHAProc><C:\WINDOWS\SHAProc.exe> []
<Kvsc3><C:\WINDOWS\Kvsc3.exE> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<DbgHlp32><C:\WINDOWS\DbgHlp32.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<paaruwdg><C:\WINDOWS\arwgptjx.exe> []
<PTSShell><C:\WINDOWS\PTSShell.exe> []
<LotusHlp><C:\WINDOWS\LotusHlp.exe> []
<WINSvr32><C:\WINDOWS\WINSvr32.exE> []
<N/A><C:\WINDOWS\sniffer.exe 2> [N/A]
<IFEO[360Loader.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
<IFEO[ctfmon.exe]><SoundMan.exe> [1]
<IFEO[IceSword]><svchost.exe> [(Verified)Microsoft Windows Publisher]
<IFEO[ras]><svchost.exe> [(Verified)Microsoft Windows Publisher]
<IFEO[runiep]><svchost.exe> [(Verified)Microsoft Windows Publisher]
<IFEO[taskmgr.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
SREng->启动项目->启动文件夹->删除
[explorer]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\explorer.exe --> [N/A]><N>
打开SREng-在"启动项目->服务->"Win32服务应用程序-》删除
[windows media player center / windows media player center][Stopped/Auto Start]
<C:\WINDOWS\System32\QQ.exe><N/A>
打开SREng-在"启动项目->服务->驱动程序"选中"隐藏已认证的微软服务" 然后将下面名称的服务删除(选中有问题的服务后,点“删除服务”,点“设置”按钮即可。 注意弹出的窗口中要点 “NO 否”才是确认删除服务)(不能删除的就禁用:启动类型改为disabled,点中修改启动类型,点设置):
[00005053 / 00005053][Stopped/Boot Start]
<\SystemRoot\system32\drivers\00005053.SYS><N/A>
[cqit / cqit][Stopped/Auto Start]
<\??\C:\DOCUME~1\lenovo\LOCALS~1\Temp\tmp8E.tmp><N/A>
[dohs / dohs][Stopped/Auto Start]
<\??\C:\DOCUME~1\lenovo\LOCALS~1\Temp\tmp7F.tmp><N/A>
[fpids32 / fpids32][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosfpids32.sys><N/A>
[HookUrl / HookUrl][Stopped/Auto Start]
<\??\C:\Program Files\Rising\Rfw\HookUrl.sys><N/A>
[internet service / internet service][Stopped/Manual Start]
<\??\C:\DOCUME~1\lenovo\LOCALS~1\Temp\2.sys><N/A>
[mhfp / mhfp][Stopped/Auto Start]
<\??\C:\DOCUME~1\lenovo\LOCALS~1\Temp\tmp6F.tmp><N/A>
[mnsf / mnsf][Stopped/Auto Start]
<\??\C:\DOCUME~1\lenovo\LOCALS~1\Temp\tmp1F.tmp><N/A>
[mytq / mytq][Stopped/Auto Start]
<\??\C:\DOCUME~1\lenovo\LOCALS~1\Temp\tmp1E8.tmp><N/A>
[New0 / New0][Running/Auto Start]
<\??\C:\WINDOWS\System32\new.sys><N/A>
[qcrcsal / qcrcsal][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\qcrcsal.sys><N/A>
浏览器加载项--删除
[]
{D29DCEE0-457B-45A2-A92D-741B95B7723B} <C:\Program Files\Internet Explorer\PLUGINS\NewSys55.Sys, N/A>
[]
{D29DCEE0-457B-45A2-A92D-741B95B7723B} <C:\Program Files\Internet Explorer\PLUGINS\NewSys55.Sys, N/A>
下载arswp(Windows清理助手)清理下
http://www.arswp.com/download/arswp/arswp.rar
还有问题,再扫个SRE日志上来