置顶下载IceSword,禁止进程创建,中止进程:
[PID: 1112][C:\WINDOWS\Explorer.EXE]
[PID: 1444][C:\WINDOWS\system32\svchost.exe]
[PID: 1340][D:\sreng\SREng.EXE]
删除加载项:
[C:\WINDOWS\system32\h1AA4033.log] [N/A, N/A]
[C:\Program Files\31AA4033\90AA6555.DLL] [N/A, N/A]
注册表中删除:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<NiceMs><C:\Program Files\Common Files\Microsoft Shared\MSINFO\Mymsok.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{31AA4033-A6FF-11E0-9A84-00C04FD8DBD8}><C:\WINDOWS\system32\h1AA4033.log> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<Nice><C:\Program Files\Common Files\Microsoft Shared\MSINFO\smss.exe> [N/A]
文件中删除:
各分区的Autorun.inf
C:\Program Files\Common Files\Microsoft Shared\MSINFO\smss.exe
C:\WINDOWS\system32\h1AA4033.log
C:\Program Files\Common Files\Microsoft Shared\MSINFO\Mymsok.exe
C:\Program Files\31AA4033\90AA6555.DLL
取消禁止进程创建,重启并监视