[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<kws39migkxkkrq1><C:\DOCUME~1\flfh\LOCALS~1\Temp\iexpl0re.exe> []
<1vf0gimde2t><C:\DOCUME~1\flfh\LOCALS~1\Temp\Servera.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<sun><C:\WINDOWS\SysSun2\svchost.exe> []
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<nwiztlbb><C:\WINDOWS\System32\nwiztlbb.exe> []
<nwizAskTao><C:\WINDOWS\System32\nwizAskTao.exe> []
驱动:
[Disk Driver Service / Disk Service][Stopped/Auto Start]
<C:\Program Files\Common Files\Microsoft Shared\Web Folders\MSOSV.EXE><N/A>
[局域网通讯协议 / Hello World][Stopped/Auto Start]
<C:\Program Files\Common Files\Microsoft Shared\Web Folders\MSOSV.EXE><N/A>
清理用户名下的TEMP文件夹
删除文件:[C:\WINDOWS\SysSun2\Ghook.dll] [N/A,
[C:\DOCUME~1\flfh\LOCALS~1\Temp\LgSy1.dll] [N/A, ]
[C:\WINDOWS\System32\nwizAskTao.dll] [N/A, ]
[C:\WINDOWS\System32\nwiztlbb.dll] [N/A, ]
[C:\DOCUME~1\flfh\LOCALS~1\Temp\Kavs0.dll] [N/A, ]
保留127.0.0.1 localhost,删除其他的HOST文件.
以上是我找到的一些可疑文件,有什么不足的请帮忙指出.