First, ask questions:
IE has been hijacked, Userinit.exe has been changed (log slightly)
Second, analysis
1. Turn off System Restore before antivirus (Win2000 system can be ignored): Right button My Computer, properties, System Restore, turn off System Restore tick on all drives.
Clear IE Temporary files: Open IE point tool-->internet option: Internet temporary files, click the "Delete Files" button, will delete all offline content tick, click OK Delete.
Close applications such as QQ. Do not do any double-click to open the disk until you do the following. All downloaded tools are placed directly on the desktop.
2. Delete the files listed below using the Force Removal Tool Xdelbox (file deletion terminator).
"Copy all the paths to delete files when you delete them, right-click on the file list you want to delete, and select Import from Clipboard. After the import to delete the file on the right click, choose to restart the deletion immediately, the computer will restart into the DOS interface for deletion, delete the completion will automatically restart into your installed operating system. Remember to save the document you are opening on your computer before you operate. For more information on Xdelbox, please see Help.chm in the xdelbox1.2 directory. 】
"There is no hint to find, please file a file in the input" file path ", the absence of the ignore can be"
C:\WINDOWS\system32\winsys16_070307.dll
G:\program Files\tencent\qq\hgtghrgp.dll
C:\Program Files\Internet Explorer\xsgcilqf.dll
C:\WINDOWS\WindowsUpdate.exe
3. After restarting the computer, use the tool Sreng to do the following operations
The contents of the "Sreng reminder after opening" function do not match the expected value they may be modified by some malicious software "Please ignore the error, install the normal modification after the soft." 】
Also: Please pay special attention to some items mentioned in the link above are edited and cannot be deleted.
==================================
(1) Start Project--> the registry of the following key edit [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
<userinit><c:\windows\system32\userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_070307.dll Start > [n/A]
For initial point <Userinit><C:\WINDOWS\System32\userinit.exe,> note commas cannot be omitted
(2) Startup item--> the registry with the following deletion
==================================
Start the project--> service-->win32 The following item deletion of the service application
[Windowsupdate/windowsupdate] [Stopped/auto Start]
<C:\WINDOWS\WindowsUpdate.exe><N/A>
QQ is best to reload after unloading. Pay attention to the change of QQ password.
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service