结束进程
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins] [N/A, N/A]
删除注册表启动项[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]下的
<{A693A5AB-BDBA-4AE7-A1C8-E41FEE1C020B}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins> [N/A]
<{A7D81718-1314-5200-2597-58790101807A}><C:\WINDOWS\system32\kaqhjzy.dll> [N/A]
<{592FADFA-BCDE-ACDF-CDEF-21054865CBA5}><C:\WINDOWS\system32\wsmsczx.dll> [N/A]
<{8859245F-345D-BC13-AC4F-145D47DA34F8}><C:\WINDOWS\system32\avzxhmn.dll> [N/A]
<{AC87A354-ABC3-DEDE-FF33-3213FD7447CA}><C:\WINDOWS\system32\kvdxjma.dll> [N/A]
<{6A1247C1-53DA-FF43-ABD3-345F323A48D6}><C:\WINDOWS\system32\avwgfmn.dll> [N/A]
<{AD561258-45F3-A451-F908-A258458226DA}><C:\WINDOWS\system32\kvdxsjma.dll> [N/A]
<{48847374-8323-FADC-B443-4732ABCD3784}><C:\WINDOWS\system32\sidjdzy.dll> [N/A]
<{678A7521-FA87-34AB-34C2-4893F3AD34C6}><C:\WINDOWS\system32\swrcezc.dll> [N/A]
<{25679330-4034-9021-7012-909856721372}><C:\WINDOWS\system32\wszjbzx.dll> [N/A]
<{5A321487-4977-D98A-C8D5-6488257545A5}><C:\WINDOWS\system32\kapjezy.dll> [N/A]
<{A12C8D43-AC10-4C17-9136-E3E2FC9B3D21}><C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys> [N/A]
删除浏览器加载项
[]
{A693A5AB-BDBA-4AE7-A1C8-E41FEE1C020B} <C:\Program Files\Common Files\Microsoft Shared\MSINFO\System76.Ins, N/A>
然后在相应目录下删除病毒文件