启动项目
注册表
删除
<svc><E:\DOCUME~1\msi\LOCALS~1\Temp\byetmr.exe> [Microsoft Corporation]
<wgs3><E:\WINDOWS\wgs3.exe> []
<wms3><E:\WINDOWS\wms3.exe> []
<{B8A170A8-7AD3-4678-B2FE-F2D7381CC1B5}><E:\Program Files\Internet Explorer\Connection Wizard\isignup.sys> [N/A]
停止并删除服务
[Routing Protect Access / SHipING][Running/Auto Start]
<E:\WINDOWS\SYSTEM32\RUNDLL2000.EXE E:\WINDOWS\SYSTEM32\WBEM\PAQXB.DLL,Export 1087><Microsoft Corporation>
停止驱动服务
[acpidisk / acpidisk][Running/Auto Start]
<\??\E:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[mrtxnjtg / mrtxnjtg][Stopped/Auto Start]
<\??\E:\WINDOWS\system32\drivers\mrtxnjtg.sys><N/A>
删除
E:\WINDOWS\system32\winlib .dll
E:\DOCUME~1\msi\LOCALS~1\Temp\wgs0.dll
E:\WINDOWS\wgs3.exe
E:\WINDOWS\wms3.exe
E:\WINDOWS\system32\NpOpenStore.dll
E:\WINDOWS\system32\NPCard.dll
E:\WINDOWS\system32\RsaFun.dll
E:\WINDOWS\system32\GPKPCSC.dll
E:\DOCUME~1\msi\LOCALS~1\Temp\byetmr.exe
E:\WINDOWS\SYSTEM32\RUNDLL2000.EXE
进安全模式杀毒。LZ参考