注意:删除病毒可能会具有一定的危险性 所以强烈建议操作前要把重要资料转移至非系统分区!
打开sreng
启动项目 注册表 删除如下项目
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><kvmxcma.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{5D83AD9C-3BFC-43F5-979D-2904DBC54A8E}><C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys> []
<{3D47B341-43DF-4563-753F-345FFA3157D3}><C:\WINDOWS\system32\kvmxcma.dll> []
<{134345F1-DACF-3452-CB7D-4620F34A1531}><C:\WINDOWS\system32\rsztapm.dll> []
<{1859245F-345D-BC13-AC4F-145D47DA34F1}><C:\WINDOWS\system32\avzxamn.dll> []
<{3B681598-AD5F-BC8C-77DC-748FAC8D3FB3}><C:\WINDOWS\system32\kafyczy.dll> []
<{1960356A-458E-DE24-BD50-268F589A56A1}><C:\WINDOWS\system32\avwlamn.dll> []
重启计算机进入安全模式下删除
[PID: 1116][C:\WINDOWS\system32\kvmxcis.exe] [N/A, ]
[PID: 3340][C:\WINDOWS\system32\rsztasp.exe] [N/A, ]
[PID: 2744][C:\WINDOWS\system32\avzxast.exe] [N/A, ]
[PID: 1580][C:\WINDOWS\system32\kafycaz.exe] [N/A, ]
[PID: 2624][C:\WINDOWS\system32\avwlast.exe] [N/A, ]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\System6.ins] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys] [N/A, ]
<{3D47B341-43DF-4563-753F-345FFA3157D3}><C:\WINDOWS\system32\kvmxcma.dll> []
<{134345F1-DACF-3452-CB7D-4620F34A1531}><C:\WINDOWS\system32\rsztapm.dll> []
<{1859245F-345D-BC13-AC4F-145D47DA34F1}><C:\WINDOWS\system32\avzxamn.dll> []
<{3B681598-AD5F-BC8C-77DC-748FAC8D3FB3}><C:\WINDOWS\system32\kafyczy.dll> []
<{1960356A-458E-DE24-BD50-268F589A56A1}><C:\WINDOWS\system32\avwlamn.dll> []
用winrar把E盘下的AutoRun.exe删除掉