注册表
<bgswitch><C:\WINDOWS\system32\bgswitch.exe> []
<EXPLORER><C:\Program Files\Common Files\System\wab32res.exe> []
<b40hyut><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1explore.exe> []
<4mbv><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rundl132.exe> []
<l0d6><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\iexpl0re.exe> []
<qrzk303cmuf><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\crasos.exe> []
<xj89z><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Servere.exe> []
<mvjl3wj1mzxvqf3><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\c0nime.exe> []
<985cfzjv5c><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winlog0n.exe> []
<54xgx7i30h5><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Servera.exe> []
cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<shualai><C:\WINDOWS\shualai.exe /i> []
删除以上对应的EXE文件和下面的文件
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LgSy0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fyzo0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rav20.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Kavs0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Msxo0.dll] [N/A, ]