楼主这是中毒了 当然修复不了了 重启开机按F8进入安全模式
然后删除启动项目
注册表(开始--运行--regedit 然后找下面的值进行清空 不要把AppInit_DLLs项删除)
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><ckgjcnnc.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{C403C77C-150C-4657-B3F2-9E2EF661EE82}><C:\WINDOWS\system32\ckgjcnnc.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<C403C77C><C:\WINDOWS\system32\ckgjcnnc.dll> []
正在运行的进程
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv8.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv18.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 3136, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\WQ69ISY0\ORANGEAUG[1].COM]
特殊特权被允许: SeLoadDriverPrivilege [PID = 3136, C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\WQ69ISY0\ORANGEAUG[1].COM]
----------------------------------------------------
删除C:\WINDOWS\system32和C:\WINDOWS\system32\Wbem下的ckgjcnnc.dll
删除C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv8.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv18.tmp
删除C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\WQ69ISY0\ORANGEAUG[1].COM
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\WQ69ISY0\ORANGEAUG[1].COM
然后用冰刃删除各进程里面加载的上面几个值项