删除启动项:
<winform><C:\WINDOWS\winform.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<testrun><C:\WINDOWS\testexe.exe> []
<upxdnd><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.exe> []
删除服务:
[3B7D8D8E / 3B7D8D8E][Stopped/Auto Start]
<C:\WINDOWS\system32\54FE265B.EXE -k><Microsoft Corporation>
删除驱动:
[Netgroup Packet Filter / NPF][Stopped/System Start]
<2 - 系统找不到指定的文件。
><N/A>
删除文件:
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\testdll.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\6A168E6E.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\nwizAsktao.dll] [N/A, ]
[C:\Program Files\WinRAR\rarext.dll] [N/A, ]
[C:\WINDOWS\system32\xunleibho_v8.dll] [, 4, 5, 1, 33]
[C:\WINDOWS\system32\6A168E6E.DLL] [Microsoft Corporation, ]
删除Autorun.inf
[C:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[D:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
[E:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe