删除文件
C:\windos\System32\DRIVERS\18yshb.sys
C:\WINDOWS\system32a2.sys
C:\windos\system32\drivers\rxqzdtb.sys
C:\WINDOWS\system32\msjetoledb40.dll
删除驱动
[18ysh / 18yshb][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\18yshb.sys><N/A>
R2A / R2A][Stopped/Disabled]
<\??\C:\WINDOWS\system32a2.sys><N/A>
[rxqzdtb / rxqzdtb][Stopped/Boot Start]
<\SystemRoot\system32\drivers\rxqzdtb.sys><>
删除浏览器加载项
[]
{00000000-12C9-4305-82F9-43058F20E8D2} <, >
[]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <, >
[]
{507F9113-CD77-4866-BA92-0E86DA3D0B97} <, >
[]
{59BC54A2-56B3-44A0-93E5-432D58746E26} <, >
[]
{5D73EE86-05F1-49ED-B850-E423120EC338} <, >
[]
{6354ABE6-05F1-49ED-B850-E423120EC338} <, >
[]
{6DBB2904-082D-4DB0-944A-21C22BA121F4} <, >
[]
{9E385F0A-0BA2-430C-96AA-4399C5E40F6C} <, >
[]
{9FAFB576-6933-4CCC-AB3D-B988EC43D04E} <, >
[]
{C86488AF-13D5-4FEF-9DDF-9FB88698CFC1} <, >
[]
{DC7094C6-8F61-42ED-AECE-63F5EEF647C5} <, >
[]
{E2E2DD38-D088-4134-82B7-F2BA38496583} <, >
[]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <, >
[]
{ECF2E268-F28C-48D2-9AB7-8F69C11CCB71} <, >
[]
{EF791A6B-FC12-4C68-99EF-FB9E207A39E6} <, >[]
{FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
[]
{FD00D911-7529-4084-9946-A29F1BDF4FE5} <, >
自己测下C:\WINDOWS\system32\XDva092.sys
http://www.virscan.org/http://www.virustotal.com/zh-cn/