进入安全模式.
结束进程
[PID: 1320][C:\WINDOWS\system32\spoolsv.exe]
][C:\WINDOWS\System32\drivers\CDAC11BA.EXE]
关闭服务
C-DillaCdaC11BA / C-DillaCdaC11BA]
Gray_Pigeon_Server1.23 / GrayPigeonServer1.23
Proxy Service / HTran
host Service For Windows / mshostsr
Windows DHCP Service / WinDHCPsvc
注册表删除
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<wywbgl4><C:\WINDOWS\servicer.exe> [N/A]
<2se3><C:\WINDOWS\iexp1ore.exe> [N/A]
<8m9ug528qw1fg><C:\WINDOWS\system.exe> [N/A]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{DEC39E0E-F1F2-41E5-80B8-592A67AB0AA5}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.rxk> [N/A]
删除文件(太多了汗一个)