把这一项置空:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><wsmsazx.dll> [N/A]
删除启动项:
<{6D47B341-43DF-4563-753F-345FFA3157D6}><C:\WINDOWS\system32\kvmxfma.dll> [N/A]
<{392FADFA-BCDE-ACDF-CDEF-21054865CBA3}><C:\WINDOWS\system32\wsmsazx.dll> [N/A]
<{7E32FA58-3453-FA2D-BC49-F340348ACCE7}><C:\WINDOWS\system32\rsmygpm.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<cctfnon.exe><; ctfmom.exe> [N/A]
icnskem><; C:\Program Files\Common Files\Microsoft Shared\tydfjbr.exe> [N/A]
删除服务:
PnP plug 0n Service / PnP plug 0n Service][Stopped/Auto Start]
<C:\WINDOWS\system32\Lcass.exe><N/A>
删除驱动:
[dyer1 / dyer1][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\dyer1.sys><N/A>
[eul8 / eul8t][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\eul8t.sys><N/A>
[kfqfkf / kfqfkf][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\kfqfkf.sys><N/A>
重启,进入安全模式后删除相应文件,升级病毒库,全盘查杀