下载文件批量提取工具提取下面文件
http://bbs.ikaka.com/attachment.aspx?attachmentid=486266C:\WINDOWS\Sminst\Recguard.exe
C:\WINDOWS\Creator\Remind_XP.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\WINDOWS\Tasks\JJX5r8wnsqUnNxGwpwn.inf
C:\Program Files\Internet Explorer\sdk.dll
C:\WINDOWS\Fonts\kb02075826.dll
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Expert2.Dll
C:\PROGRA~1\快捷方式\KKjie.exe
C:\WINDOWS\system32\msinet32d.dll
C:\WINDOWS\Fonts\kb02074234.dll
上传病毒样本到可疑文件交流区,地址为:
http://bbs.ikaka.com/showforum-20002.aspx或者直接发送给瑞星的邮件服务中心【病毒样本】地址为:
http://mailcenter.rising.com.cn/uploadnew.aspx进入注册表编辑器,删除HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options键值。