禁用错误报告治标不治本!
现在已经找到解决方法,并成功解决了!!:-)
把病毒生成的文件:
%Windir%System32magicap.dll
%Windir%System32magicap.ver
%Windir%System32magicaptmp.ver
%Windir%System32taskmngr.exe
%Windir%System32autorun.inf
%Windir%System32taskmngrtmp.exe
%Windir%System32d11host.exe
%Windir%System32magicapf.log
%Windir%System32oleauto32.dll
%Windir%System32ntcoredll.dll
%Windir%System32rpcfap.dll
%Windir%System32fileap.dll
%Windir%System32fileap.ver
%Windir%System32msieinslog.dat
%Windir%prfexp.dat
%Windir%secupadf.dat
%Windir%msimfinst.log
%Windir%ntcoredlltmp.dll
全部删掉,再把注册表中的
[HEKY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{372F096E-977F-4BF9-A97E-0BBED41332F2}="magicaps"
[HEKY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
{372F096E-977F-4BF9-A97E-0BBED41332F2}="magicaps"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
d11host="C:\\WINNT\\System32\\d11host.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
GinaDLL="rpcfap.dll"