运行SREng2,使用“启动项目”--注册表--删除
C:\PROGRA~1\svhost32.exe
C:\WINDOWS\Intel\rundll32.exe> [N/A]
<down.exe><C:\WINDOWS\System32\down.exe> [N/A]
<xy><C:\WINDOWS\Download\svhost32.exe> [N/A]
<wl><C:\WINDOWS\Download\svhost32.exe>
C:\WINDOWS\System32\uumpln.exe>
}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe
1> [N/A]
红色的不要
重启按F8进入安全模式下
显示隐藏文件
删除:
C:\PROGRA~1\svhost32.exe
C:\WINDOWS\Intel\rundll32.exe> [N/A]
<down.exe><C:\WINDOWS\System32\down.exe> [N/A]
<xy><C:\WINDOWS\Download\svhost32.exe> [N/A]
<wl><C:\WINDOWS\Download\svhost32.exe>
C:\WINDOWS\System32\uumpln.exe>
}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp
:\WINDOWS\System32\uumpln.dll] [N/A, N/A]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp] [N/A, N/A]
[C:\WINDOWS\System32\wldll.dll] [N/A, N/A]
[C:\WINDOWS\System32\xydll.dll] [N/A, N/A]
[C:\WINDOWS\System32\ztdll.dll] [N/A, N/A]
[C:\WINDOWS\System32\dllwm.dll] [N/A, N/A]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
c:\program files\internet explorer\fuwztaet.dll
右键打开,不要双击,删除D盘的隐藏文件
D:\Autorun.inf
D:\pagefile.pif