| 引用: |
【 新手上路的贴子】按照你说的做了。帮看下 ……………… |
将下列文件名的后缀改为.vir:
C:\windows\system32\kvdxcma.dll
C:\windows\system32\sqmapi32.dll
C:\windows\system32\qdshm.dll
C:\windows\system32\rsmydpm.dll
C:\Program Files\Internet Explorer\PLUGINS\WinSys88.Sys
C:\windows\system32\ratbfpi.dll
C:\windows\system32\hythsx.dll
C:\Program Files\Internet Explorer\IEXPLORE32.Sys
C:\windows\system32\winfast.dll
C:\Program Files\Internet Explorer\IEXPLORE32.Dat
C:\Program Files\Internet Explorer\IEXPLORE32.win
C:\windows\system32\kawdbzy.dll
C:\windows\system32\winkga.dll
C:\windows\system32\winpy.dll
C:\windows\system32\fhiry.dll]
C:\windows\system32\wkvfl.dll
C:\windows\system32\wuytm.dll
C:\windows\system32\hkjfx.dll
C:\windows\system32\wkjrj.dll
C:\windows\system32\allatl.dll
C:\windows\system32\msatl.dll
C:\windows\system32\addrwdhelp.dll
C:\windows\system32\msrav.dll
C:\windows\system32\ravztmon.dll
C:\RECYCLER\zx.dll
C:\RECYCLER\wm.dll
C:\RECYCLER\qj.dll
C:\RECYCLER\kulionrx.dll
C:\RECYCLER\video.dll
C:\windows\system32\sqmapi32.dll
重启系统。
删除那些后缀为.vir的文件以及下面两个文件:
e:\Autorun.inf
e:\AutoRun.exe
删除下列注册表内容:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ZSSnp211><; C:\WINDOWS\ZSSnp211.exe> [ZSMCSNAP]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><kvdxcma.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{37C3125C-9CB6-4503-8F38-63D80ADEFA07}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\System6.ins> []
<{4E32FA58-3453-FA2D-BC49-F340348ACCE4}><C:\windows\system32\rsmydpm.dll> []
<{E418E9ED-9221-4661-B1F3-4AA35BD83832}><C:\Program Files\Internet Explorer\PLUGINS\WinSys88.Sys> []
<{66650011-3344-6688-4899-345FABCD1566}><C:\windows\system32\ratbfpi.dll> []
<{3C87A354-ABC3-DEDE-FF33-3213FD7447C3}><C:\windows\system32\kvdxcma.dll> []
<{F2CEA371-1442-4F42-900F-97C479F406DB}><C:\windows\system32\hythsx.dll> []
<{C5E87A05-F463-4841-B19E-DD3EC3862368}><C:\Program Files\Internet Explorer\IEXPLORE32.Sys> []
<{566C4A67-DF8C-48C7-B32A-18E69FC90735}><C:\windows\system32\winfast.dll> []
<{EE12D60D-AD9A-4095-B839-3BE6862679FD}><C:\Program Files\Internet Explorer\IEXPLORE32.Dat> []
<{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}><C:\Program Files\Internet Explorer\IEXPLORE32.win> []
<{28907901-1416-3389-9981-372178569982}><C:\windows\system32\kawdbzy.dll> []
驱动程序
[cpuz / cpuz][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\cpuz.sys><N/A>