1. 结束进程
%WINDOWS%\IGW.exe
2. 删除病毒创建的注册表项
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinSys"="%WINDOWS%\IGW.exe
[HKLM\SYSTEM\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations"="%WINDOWS%\UUUUU12999"
3. 删除病毒释放的文件
%WINDOWS%\IGW.exe
%WINDOWS%\XXXXXXWO.DLL
XXXXXX=六位数字
安全模式操作.