冰刃改名就可以打开了
这个C:\Program Files\R_Server\RemoteAbc.exe不知道是什么,自己去看看文件去。
——————————————————————————————————————————————————————
删除下面文件:
C:\WINDOWS\AVPSrv.exE
C:\WINDOWS\PTSShell.exe
C:\WINDOWS\WINSvr32.exE
C:\WINDOWS\system32\jhrcar.dll
C:\Program Files\Internet Explorer\PLUGINS\WinSys8v.Sys
C:\WINDOWS\system32\Setup\en_1072.bin
C:\WINDOWS\system32\interne.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp5A.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp48.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp6B.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp4D.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp2B.tmp
C:\WINDOWS\SoundMan.exe
C:\WINDOWS\popo.exe
——————————————————————————————————————————————————————
删除下面各项涉及到的注册表项:
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<AVPSrv><C:\WINDOWS\AVPSrv.exE> [N/A]
<PTSShell><C:\WINDOWS\PTSShell.exe> [N/A]
<WINSvr32><C:\WINDOWS\WINSvr32.exE> [N/A]
<SoundMan><SoundMan.exe> [1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{CAED0F3B-DF8B-4DBF-BB20-8DFBC3199068}><C:\WINDOWS\system32\jhrcar.dll> [N/A]
<{6167F471-EF2B-41DD-A5E5-C26ACDB5C096}><C:\Program Files\Internet Explorer\PLUGINS\WinSys8v.Sys> [N/A]
<{50632D5C-B71B-4ba0-B012-3DC6F15C011B}><C:\WINDOWS\system32\Setup\en_1072.bin> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Loader.exe]
<IFEO[360Loader.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe]
<IFEO[ctfmon.exe]><SoundMan.exe> [1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword]
<IFEO[IceSword]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ras]
<IFEO[ras]><svchost.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep]
<IFEO[runiep]><svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
<IFEO[taskmgr.exe]><svchost.exe> [(Verified)Microsoft Windows Publisher]
==================================
服务
[Help and Support / helpsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\interne.exe><1>
[RCef / ReRCef][Stopped/Auto Start]
<C:\Program Files\R_Server\RemoteAbc.exe><N/A>
==================================
驱动程序
[cqit / cqit][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp5A.tmp><N/A>
[dohs / dohs][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp48.tmp><N/A>
[drop / drop][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp6B.tmp><N/A>
[mhfp / mhfp][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp4D.tmp><N/A>
[mnsf / mnsf][Stopped/Auto Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp2B.tmp><N/A>
==================================
浏览器加载项
[]
{6167F471-EF2B-41DD-A5E5-C26ACDB5C096} <C:\Program Files\Internet Explorer\PLUGINS\WinSys8v.Sys, N/A>
———————————————————————————————————————————————————————
再重启电脑,升级杀毒软件至最新版本全盘杀毒。
下载卡卡助手,清理你那系统。
记得打打系统漏洞补丁
清空IE缓存,清空临时文件夹。
这 里 下 载 W i n d o w s 清 理 助 手 ,清理你那系统。
http://www.arswp.com/