【回复“奔跑的少年”的帖子】
1、用XDELBOX删除下列注册表项指向的程序以及各个分区根目录下的Autorun.inf和soS.Exe。
2、重启后,用SRENG删除下列注册表内容:
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<wcmdmgr><C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch> [WildTangent, Inc.]
<hxgame-update><C:\Program Files\hxupdate\hxgame-update.exe> [N/A]
<crsss><C:\WINDOWS\system32\TxHMoU.Exe> []
<SSLDyn><C:\WINDOWS\SSLDyn.exE> []
<upxdnd><C:\WINDOWS\upxdnd.exe> []
<WinSysM><C:\WINDOWS\721815M.exe> [N/A]
<MsPrint32D><C:\WINDOWS\MsPrint32D.exe> []
<KVP><C:\WINDOWS\system32\drivers\svchost.exe> []
<WinSysW><C:\WINDOWS\721815L.exe> [N/A]
<LotusHlp><C:\WINDOWS\LotusHlp.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><avwghmn.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{521DAF25-0CF6-4605-A66D-010E84546FED}><C:\WINDOWS\system32\gkpubglqwb.dll> [Microsoft Corporation]
<{9963387B-212E-4643-B207-82DAEA0E713D}><C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys> []
<{AC87A354-ABC3-DEDE-FF33-3213FD7447CA}><C:\WINDOWS\system32\kvdxjma.dll> []
<{7960356A-458E-DE24-BD50-268F589A56A7}><C:\WINDOWS\system32\avwlgmn.dll> []
<{BD561258-45F3-A451-F908-A258458226DB}><C:\WINDOWS\system32\kvdxskma.dll> []
<{8A1247C1-53DA-FF43-ABD3-345F323A48D8}><C:\WINDOWS\system32\avwghmn.dll> []
<{C7D81718-1314-5200-2597-58790101807C}><C:\WINDOWS\system32\kaqhlzy.dll> []
<{68907901-1416-3389-9981-372178569986}><C:\WINDOWS\system32\kawdfzy.dll> []
<{F6650011-3344-6688-4899-345FABCD156F}><C:\WINDOWS\system32\ratbopi.dll> []
<{88847374-8323-FADC-B443-4732ABCD3788}><C:\WINDOWS\system32\sidjhzy.dll> []
<{809B3B49-72F3-491E-87FA-1753DA02FA06}><C:\WINDOWS\system32\sxbgotxcinsx.dll> [Microsoft Corporation]
<{45679330-4034-9021-7012-909856721374}><C:\WINDOWS\system32\wszjdzx.dll> []
服务
[DNS Cache / MOVEESS][Stopped/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[Windows_ServerDdos / Windows_ServerDdos][Stopped/Auto Start]
<C:\WINDOWS\system32\ddos.exe><N/A>
驱动程序
[1096366 / 1096366][Stopped/Boot Start]
<\SystemRoot\System32\drivers\1096366.sys><N/A>
[2CFE34D2 / 2CFE34D2][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\2CFE34D2.367><N/A>
[comint32 / comint32][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\DRIVERS\comint32.sys><N/A>
[dump_wmimmc / dump_wmimmc][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\dump_wmimmc.sys><N/A>
[gAGP440p / gAGP440p][Stopped/Manual Start]
<\??\C:\DOCUME~1\FLYINT~1\LOCALS~1\Temp\gAGP440p.sys><N/A>
[ZX / ZX][Stopped/Manual Start]
<\??\C:\DOCUME~1\FLYINT~1\LOCALS~1\Temp\tmpFF.tmp><N/A>
浏览器加载项
[]
{9963387B-212E-4643-B207-82DAEA0E713D} <C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys, N/A>
[]
{9963387B-212E-4643-B207-82DAEA0E713D} <C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys, N/A>
关于“Winsock 提供者”下面的内容,我未见过。不知是否与病毒有关。自己酌情处理吧。