c:\docume~1\admini~1\locals~1\temp\~10171d9.tmp
c:\docume~1\admini~1\locals~1\temp\rar$ex00.828\ch000001.sys
启动项目 -- 服务-- 驱动程序之如下项禁用:
[zx / zx] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~10171d9.tmp>
[Ch000001 / Ch000001] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.828\Ch000001.sys>
另外注册表清理一下:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{69B265A2-A172-4D27-BDF1-917E6D8B1DCC}><C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon> [File is missing]
<{E3531A16-FFEA-416F-82DF-32FEDE02EABF}><C:\WINDOWS\system32\emHnPuBAaF7XjuXBbdxSg.dll> [File is missing]
<{AB900155-F1F0-4165-9E73-67BC13BBCE89}><C:\WINDOWS\system32\xg4hAPNygs29.dll> [File is missing]
<{427E02E6-39DB-4424-A49C-7553CD1331F5}><C:\WINDOWS\system32\WcCtgJ4zcxHF.dll> [File is missing]
<{407C7A80-4656-4C4A-81C6-DFFB8009B80F}><C:\WINDOWS\system32\MV3ArsBMAPjxBcRuu.dll> [File is missing]
<{108DA6C0-CFBF-41D4-9A09-C4D06AE6FFD2}><C:\WINDOWS\system32\Q9q2MHJ3uTBErM7wc.dll> [File is missing]
<{D6129F8A-6F6E-41D7-BBC9-AC7426759CED}><C:\WINDOWS\system32\w7uds3zyayg9.dll> [File is missing]
<{A761BE8E-C15A-4DDD-A777-2C683E9E96C8}><C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll> [File is missing]
<{76B9BA7A-81D0-4979-8598-8471F2AB5186}><C:\WINDOWS\system32\76B9BA7A.dll> [File is missing]
<{B8898C49-7B3A-4306-A9EF-8E186EDEE5EA}><C:\WINDOWS\system32\Qh6xX7VN48sVPnK.dll> [File is missing]
<{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}><C:\WINDOWS\system32\122B901E.dll> [File is missing]
<{762D618C-E2CB-4217-8275-03302A93073F}><C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon> [File is missing]
<{704C3595-DB85-40F6-A601-8D6F346907BD}><C:\WINDOWS\system32\704C3595.dll> [File is missing]
<{E762D574-B60E-4160-B417-4788469ECB3E}><C:\WINDOWS\system32\ZZZCz7d8yS9vy.dll> [File is missing]
<{76CBCF38-0583-44C7-A1AE-D463DFE625EC}><C:\WINDOWS\system32\skcfujQ5EDN.dll> [File is missing]
<{8708994F-1758-4C2C-9A3F-FA22D6CCCB41}><C:\WINDOWS\fonts\A97CRaCB.fon> [File is missing]
<{5405A7B2-F3F5-446F-8715-2A4EF674E079}><C:\WINDOWS\system32\rfpz9wwyy2np.dll> [File is missing]
<{44145A62-C003-4C0E-ADDE-4AB37A7FD38B}><C:\Program Files\Internet Explorer\D9.dll> [File is missing]