用Killbox,删除:
C:\Program Files\Common Files\SYSTEM\56182285.dll
C:\Documents and Settings\冯金荣\「开始」菜单\程序\启动\185228.exe
C:\WINDOWS\system32\tufupb50.dll
关闭所有杀软,运行regedit,删除下列值:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{56155252-2528-2825-8615-888865252815}><C:\Program Files\Common Files\SYSTEM\56182285.dll> [N/A]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<tufupb50><; C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\tufupb50.dll,DllCanUnloadNow> [N/A]
[185228]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\185228.exe --> [N/A]><N>
[185228]
<C:\Documents and Settings\冯金荣\「开始」菜单\程序\启动\185228.exe --> [N/A]><N>
修复HOSTS 文件
不用的杀软卸载干净,只保留一个