| 引用: |
【ADL的贴子】HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] <rundll32><C:\Program Files\Common Files\System\MSOSV.EXE> [] <NTService><C:\Program Files\Common Files\System\MSOSV.EXE> []
TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.] <NMGameX_AutoRun><C:\WINDOWS\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa> [NMGameX]
C:\WINDOWS\system32\RAV00AE.DAT] [N/A, ] [C:\WINDOWS\system32\mh104.dll] [N/A, ] [C:\WINDOWS\system32\nwizwlwzs.dll] [N/A, ] [C:\WINDOWS\system32\MOSOU.dll] [N/A, ] [C:\WINDOWS\system32\nwiztlbb.dll] [N/A, ] [C:\WINDOWS\system32\Ravasktao.dll] [N/A, ] [C:\WINDOWS\system32\nwizwmgjs.dll] [N/A, ]
Autorun.inf [C:\] [AutoRun] OPEN=pagefiles.pif shell\open=打开(&O) Shell\open\command=pagefiles.pif Shell\open\default=1 shell\explore=资源管理器(&X) shell\explorer\command=pagefiles.pif [D:\] [AutoRun] open=RavMon.exe shell\open=打开(&O) shell\open\Command=RavMon.exe shell\explore=资源管理器(&X) shell\explore\Command="RavMon.exe -e" [E:\] [AutoRun] open=RavMon.exe shell\open=打开(&O) shell\open\Command=RavMon.exe shell\explore=资源管理器(&X) shell\explore\Command="RavMon.exe -e" [F:\] [AutoRun] open=RavMon.exe shell\open=打开(&O) shell\open\Command=RavMon.exe shell\explore=资源管理器(&X) shell\explore\Command="RavMon.exe -e" [G:\] [AutoRun] open=RavMon.exe shell\open=打开(&O) shell\open\Command=RavMon.exe shell\explore=资源管理器(&X) shell\explore\Command="RavMon.exe -e"
================================== HOSTS 文件 127.0.0.1 localhost 127.0.0.1 mmm.caifu18.net 127.0.0.1 www.18dmm.com 127.0.0.1 d.qbbd.com 127.0.0.1 www.5117music.com 127.0.0.1 www.union123.com 127.0.0.1 www.wu7x.cn 127.0.0.1 www.54699.com 127.0.0.1 www.97725.com 127.0.0.1 down.97725.com 127.0.0.1 ip.315hack.com 127.0.0.1 ip.54liumang.com 127.0.0.1 www.41ip.com 127.0.0.1 xulao.com 127.0.0.1 www.heixiou.com 127.0.0.1 www.9cyy.com 127.0.0.1 www.hunll.com 127.0.0.1 www.down.hunll.com 127.0.0.1 www1.6tan.com 127.0.0.1 www2.6tan.com 127.0.0.1 do.77276.com 127.0.0.1 www.baidulink.com 127.0.0.1 adnx.yygou.cn 127.0.0.1 222.73.220.45 127.0.0.1 www.f5game.com 127.0.0.1 www.guazhan.cn 127.0.0.1 wm,103715.com 127.0.0.1 www.my6688.cn 127.0.0.1 i.96981.com 127.0.0.1 d.77276.com 127.0.0.1 www.tie2bu.com 127.0.0.1 www.byip.cn 127.0.0.1 178.shen9.net 127.0.0.1 www.h-t1.com 127.0.0.1 www.puma164.com 127.0.0.1 www.56jb.com 127.0.0.1 jxdoe.com 127.0.0.1 www.08325.cn 127.0.0.1 www1.cw988.cn 127.0.0.1 cool.47555.com 127.0.0.1 www.asdwc.com 127.0.0.1 55880.cn 127.0.0.1 61.152.169.234 127.0.0.1 cc.wzxqy.com 127.0.0.1 www.54699.com 127.0.0.1 t.gcuj.com 127.0.0.1 www.puma163.com 127.0.0.1 ceoww.com 127.0.0.1 ad.uiiiu.com 127.0.0.1 boolom.com 127.0.0.1 www.copyip.com 127.0.0.1 boolom.com 127.0.0.1 adult-novel.cn 127.0.0.1 ll.chinasese.net 127.0.0.1 www.tellumore.com 127.0.0.1 www.o1wg.com 127.0.0.1 www.qq756.com 127.0.0.1 ll.chinasese.net 127.0.0.1 cool.47555.com 127.0.0.1 www.panama8.com 127.0.0.1 www.zt04.cn
……………… |
用killbox删除
C:\Program Files\Common Files\System\MSOSV.EXE
C:\WINDOWS\system32\RAV00AE.DAT
C:\WINDOWS\system32\mh104.dll
C:\WINDOWS\system32\nwizwlwzs.dll
C:\WINDOWS\system32\MOSOU.dll
C:\WINDOWS\system32\nwiztlbb.dll
C:\WINDOWS\system32\Ravasktao.dll
C:\WINDOWS\system32\nwizwmgjs.dll
把下面的代码复制到记事本中,保存成文件名为
fix.bat,运行
@echo off
c:
cd \
attrib -s -h -r copy.exe
del copy.exe /F
attrib -s -h -r *.inf
del autorun.inf /F
d:
cd \
attrib -s -h -r copy.exe
del copy.exe /F
attrib -s -h -r *.inf
del autorun.inf /F
e:
cd \
attrib -s -h -r copy.exe
del copy.exe /F
attrib -s -h -r *.inf
del autorun.inf /F
f:
cd \
attrib -s -h -r copy.exe
del copy.exe /F
attrib -s -h -r *.inf
del autorun.inf /F
g:
cd \
attrib -s -h -r copy.exe
del copy.exe /F
attrib -s -h -r *.inf
del autorun.inf /F
h:
cd \
attrib -s -h -r copy.exe
del copy.exe /F
attrib -s -h -r *.inf
del autorun.inf /F
i:
cd \
attrib -s -h -r copy.exe
del copy.exe /F
attrib -s -h -r *.inf
del autorun.inf /F
@echo 修复完成。按任意键继续……记得手动重启计算机!!
pause然后开始--》运行...
请输入(建议你也可以复制/粘贴过去):
notepad %SystemRoot%\system32\drivers\etc\hosts点确定按钮。
保留包含127.0.0.1的行,把其它行全部删除。