置顶下载killbox,关闭所有应用程序(包括所有杀软),删除:
C:\PROGRA~1\3721\helper.dll
C:\WINDOWS\system32\windhcp.ocx
C:\WINDOWS\system32\xpdhcp.dll
C:\WINDOWS\system32\svch0st.exe
清空:C:\DOCUME~1\user\LOCALS~1\Temp
运行regedit,删除下列值:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<kavshell><C:\WINDOWS\system32\svch0st.exe> [N/A]
<myWl2><C:\DOCUME~1\user\LOCALS~1\Temp\Wl2\lexplore.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<wlzs><C:\DOCUME~1\user\LOCALS~1\Temp\conime.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<NiceMSoft><C:\WINDOWS\system32\retemp.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{06A48AD9-FF57-4E73-937B-B493E72F4226}?><> [N/A]
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
[WinXP DHCP Service / WinXPDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe xpdhcp.dll,start><Microsoft Corporation>