<zskNZ><; C:\WINDOWS\System32\_zskdmwin\S^RMIMDXPL\W\ZN.exe> []
<zskvevgyvqhzl_yzpf`niwmdksz_><; c:\windows\system32\_zskdmwin`fpzy_lzhqvygvev.exe> []
<zskXZBOS]PDQGS[><; C:\WINDOWS\System32\_zskdmwinSTF\[SGQDP]SOBZX.exe> []
这是什么鸟玩意?
用sreng
删除启动项目=>注册表
<run><C:\WINDOWS\System32\new.exe> []
<system><C:\WINDOWS\System32\explore.exe> []
<JXFUpSRpR><C:\WINDOWS\System32\zojh.dll> []
<DCOM Server 2236><> []
<DCOM Server><> []
<{2C1CD3D7-86AC-4068-93BC-A02304BB2236}><> []
<{2C1CD3D7-86AC-4068-93BC-A02304BB8C34}><> []
<WinlogonNotify: 1_32bean32_1reg><C:\Documents and Settings\All Users\Documents\Settings\1_32bean32_1.dll> []
<b4c8077b.exe><; C:\WINDOWS\System32\b4c8077b.exe> []
<defender><; C:\\dfndred_7.exe> []
<keyboard><; C:\\kybrded_7.exe> []
<Mixer Update><; iyokdkk.exe> []
<msupdate><; C:\WINDOWS\msupdate.exe> []
<newname><; C:\\nwnmed_7.exe> []
<secure socket layer><; wins32a.exe> []
<Windows Task Manager><; c:\windows\system32\taskmgn.exe> []
删除
C:\WINDOWS\System32\new.exe
C:\WINDOWS\System32\explore.exe
C:\WINDOWS\System32\zojh.dll
C:\Documents and Settings\All Users\Documents\Settings\1_32bean32_1.dll
C:\WINDOWS\System32\b4c8077b.exe
C:\\dfndred_7.exe
C:\\kybrded_7.exe
iyokdkk.exe(搜一下)
C:\WINDOWS\msupdate.exe
C:\\nwnmed_7.exe
wins32a.exe(搜一下)
c:\windows\system32\taskmgn.exe