找出:
C:\WINDOWS\system32\rsmyapm.dll
C:\WINDOWS\system32\mxaman.dll
C:\WINDOWS\system32\wlhpri.dll
C:\WINDOWS\system32\rsjzapm.dll
C:\WINDOWS\system32\avzxamn.dll
C:\WINDOWS\system32\rsqmapm.dll
依次改名为1.dll 2.dll ...
删除注册表内:
<{0CEC10DA-61C5-4254-AF59-0B3151B12BD0}><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1\4hj.dll> [N/A]
<{13B917C5-1BAB-1F85-237A-273D2B3E2F27}><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1\wmsjxx1kml.dll> [N/A]
<{1C87A354-ABC3-DEDE-FF33-3213FD7447C1}><> [N/A]
<{1A321487-4977-D98A-C8D5-6488257545A1}><> [N/A]
<{1960356A-458E-DE24-BD50-268F589A56A1}><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<DirectX><C:\WINDOWS\system32\d3d8xof.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<avpqqsg><; C:\Program Files\NetMeeting\avpqqsg.exe> [N/A]
<MsIMMs32><; C:\WINDOWS\MsIMMs32.exe> [N/A]
<ravwdmon><; C:\Program Files\NetMeeting\ravwdmon.exe> [N/A]
<ravztmon><; C:\Program Files\NetMeeting\ravztmon.exe> [N/A]
<UserFaultCheck><; %systemroot%\system32\dumprep 0 -u> [N/A]
删除驱动:
[ATSpy / ATSpy][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\ATSpy.sys><N/A>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
<system32\DRIVERS\ipinip.sys><N/A>
重器 ,删除:
该过名字的
C:\WINDOWS\system32\rsmyapm.dll
C:\WINDOWS\system32\mxaman.dll
C:\WINDOWS\system32\wlhpri.dll
C:\WINDOWS\system32\rsjzapm.dll
C:\WINDOWS\system32\avzxamn.dll
C:\WINDOWS\system32\rsqmapm.dll
清空:
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
删除文件:
C:\WINDOWS\system32\mscomm.dll
C:\WINDOWS\system32\d3d8xof.dll
C:\Program Files\NetMeeting\avpqqsg.exe
C:\WINDOWS\MsIMMs32.exe
C:\Program Files\NetMeeting\ravwdmon.exe
C:\Program Files\NetMeeting\ravztmon.exe
C:\WINDOWS\system32\ATSpy.sys
C:\WINDOWS\system32\DRIVERS\ipinip.sys
删除注册表启动项目
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{1E32FA58-3453-FA2D-BC49-F340348ACCE1}><C:\WINDOWS\system32\rsmyapm.dll> []
<{1231A43A-1642-641A-64FD-146ADAB223B1}><C:\WINDOWS\system32\mxaman.dll> [N/A]
<{5182C1EB-375C-573D-1F5E-234552345215}><C:\WINDOWS\system32\wlhpri.dll> [N/A]
<{12FAACDE-34DA-CCD4-AB4D-DA34485A3421}><C:\WINDOWS\system32\rsjzapm.dll> [N/A]
<{1859245F-345D-BC13-AC4F-145D47DA34F1}><C:\WINDOWS\system32\avzxamn.dll> []
<{1F364345-3094-1202-2581-45981903A4F1}><C:\WINDOWS\system32\rsqmapm.dll> []
把
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><rsqmapm.dll> []
设置为空
修复Winsock