我中过,而且成功删除了,我的系统是xp sp1,打开“我的电脑”要等十几秒才显示出内容,USB设备不能使用,电脑也没有了声音,“网络连接”里是空白的,“设备管理器”里也是空白的。
杀毒软件升级到最新版,扫描发现病毒Trojan.PSW.QQGame,杀掉后重起电脑,再扫描还有Trojan.PSW.QQGame。
打开“我的电脑”,工具-文件夹属性-查看,将“隐藏受保护的操作系统文件(推荐)”的对勾去掉,同时选择“显示所有文件和文件夹”,删除C:\WINDOWS\SYSTEM32\MSWDM.EXE。在注册表里找到[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
"CheckFaultKernel"="C:\\WINDOWS\\System32\\mswdm.exe"项,删除。这样处理后再重起电脑就不会有病毒了。
但是打开“我的电脑”要等十几秒才显示出内容,USB设备不能使用,电脑也没有了声音,“网络连接”里是空白的,“设备管理器”里也是空白的等等问题还是存在。把下边的东东做成reg文件导入到注册表里(适用于xpsp1)
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PlugPlay]
"Description"="使计算机在极少或没有用户输入的情况下能识别并适应硬件的更改。终止或禁用此服务会造成系统不稳定。"
"DisplayName"="Plug and Play"
"ErrorControl"=dword:00000001
"Group"="PlugPlay"
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,65,00,72,00,76,00,69,00,63,00,65,00,73,00,2e,00,65,00,78,00,65,00,00,00
"
ObjectName"="LocalSystem"
"PlugPlayServiceType"=dword:00000003
"Start"=dword:00000002
"Type"=dword:00000020
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PlugPlay\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,\
05,0b,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,\
23,02,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
重启系统,万事大吉。