用WINRAR(解压缩的软件)依次找出下列文件(找不到就算了),再依次重命名为1.EXE 2.EXE 3.EXE 4.EXE .....N.EXE
C:\WINDOWS\system32\msavpw0.dll> [N/A]
C:\WINDOWS\system32\kvdxcma.dll> [N/A]
C:\WINDOWS\system32\rsztbpm.dll> [N/A]
C:\WINDOWS\system32\kapjbzy.dll> [N/A]
C:\WINDOWS\system32\mypern0.dll> [N/A]
C:\WINDOWS\system32\kvmxdma.dll> [N/A]
C:\WINDOWS\system32\rarjbpi.dll> [N/A]
C:\WINDOWS\system32\ratbepi.dll> [N/A]
C:\WINDOWS\system32\WinFormA12.dll> []
C:\WINDOWS\system32\kafydzy.dll> [N/A]
C:\WINDOWS\system32\sidjazy.dll> [N/A]
C:\WINDOWS\system32\avwlamn.dll> [N/A]
C:\WINDOWS\system32\kawdbzy.dll> [N/A]
C:\WINDOWS\system32\kaqhdzy.dll> [N/A]
C:\WINDOWS\system32\avwlbmn.dll> [N/A]
C:\WINDOWS\system32\zxavast0.dll> [N/A]
C:\Program Files\Internet Explorer\PLUGINS\WinSys74.Sys> [N/A]
C:\WINDOWS\system32\xyupri0.dll> [N/A]
C:\WINDOWS\system32\csavpw0.dll> [N/A]
C:\WINDOWS\system32\ztavpw0.dll> [N/A]
c:\com1\com1.dll> []
C:\WINDOWS\system32\SysWln74_3.dll> []
C:\WINDOWS\system32\rsztcpm.dll> [N/A]
C:\WINDOWS\system32\rsmydpm.dll> [N/A]
C:\WINDOWS\system32\kaqhezy.dll> [N/A]
C:\WINDOWS\system32\ratbfpi.dll> [N/A]
C:\WINDOWS\system32\avzxdmn.dll> [N/A]
C:\WINDOWS\system32\kafyezy.dll> [N/A]
C:\WINDOWS\system32\hythsx.dll> [N/A]
C:\WINDOWS\system32\mssock.sys
C:\WINDOWS\system32\sqmapi32.dll
好几个在安全模式下都运行的