1.[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(load)(C:\WINDOWS\rundl132.exe) []
删除,先结束进程,在注册表删,后找到相应文件C:\WINDOWS\rundl132.exe删除
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(tsnpstd3)(C:\WINDOWS\tsnpstd3.exe) []
(snpstd3)(C:\WINDOWS\vsnpstd3.exe) []
在注册表删,后找到相应文件删除,删之前备份C:\WINDOWS\tsnpstd3.exe,C:\WINDOWS\vsnpstd3.exe打包发给我,邮箱anglecomcn@163.com3.[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)(351677M.BMP) [N/A]
351677M.BMP删除
4.[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
(CnsMin)(; Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32) [N/A]
(helper.dll)(; C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32) [N/A]
删除,3721还在用佩服
5.[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
(Load)(; C:\WINDOWS\rundl132.exe) []
删除
6.[C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\uta1.tmp] [N/A, N/A]
[C:\DOCUME~1\poiu\LOCALS~1\Temp\yobB1.tmp] [N/A, N/A]
删除
7.[PID: 1820][C:\WINDOWS\vsnpstd3.exe] [, 1, 0, 5, 0]
删除
8.[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
删除
9.[PID: 3852][C:\WINDOWS\Logo1_.exe] [, 1.0.0.0]
删除
如果楼主没安装过CAMERAFIX,把camerafix.exe项也删除了,好多毒,呵呵