raqjbpi.dll
lyleador.exe
crypt32.dll
cryptnet.dll
cscdll.dll
wlnotify.dll
sclgntfy.dll
c:\windows\system32\drivers\a347bus.sys
c:\windows\system32\drivers\a347scsi.sys
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
注意该项[AppInit_DLLs]修改:把<raqjbpi.dll>修改为<>即清空
[MSDCG32 ] <LYLeador.exe>
[WinlogonNotify: crypt32chain] <crypt32.dll>
[WinlogonNotify: cryptnet] <cryptnet.dll>
[WinlogonNotify: cscdll] <cscdll.dll>
[WinlogonNotify: ScCertProp] <wlnotify.dll>
[WinlogonNotify: Schedule] <wlnotify.dll>
[WinlogonNotify: sclgntfy] <sclgntfy.dll>
[WinlogonNotify: SensLogn] <WlNotify.dll>
[WinlogonNotify: termsrv] <wlnotify.dll>
[WinlogonNotify: wlballoon] <wlnotify.dll>
启动项目 -- 服务-- 驱动程序之如下项删除:
[a347bus / a347bus] <\SystemRoot\system32\DRIVERS\a347bus.sys>
[a347scsi / a347scsi] <\SystemRoot\System32\Drivers\a347scsi.sys>