C:\WINDOWS\system32\cards.dll
C:\WINDOWS\system32\Primomonnt.dll
上面这两文件,我不能判断,自己去看文件属性判断去。
————————————————————————————————————————————————
下面这些,你自己再搞搞吧,相关的文件删除必须一气呵成,否则没办法成功。
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><SysWoWa8.dll,msosping00.dll,msosdohs00.dll,msosmhfp01.dll> [N/A]
启动项目
注册表
<{6BBAA1E6-CF54-4139-AB9C-8491A9F909D7}><C:\WINDOWS\system32\wfrdvq.dll> [N/A]
<{1AB1F65A-964F-4AE7-B254-05146A0E602E}><C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys> []
<{875E07B1-0614-43D9-A76E-D76A28AB3D7B}><C:\WINDOWS\system32\tfsdmz.dll> [N/A]
<{C36ECF8F-EAD9-44BD-8DD0-C4240A06F51C}><C:\WINDOWS\system32\sqavpw0.dll> []
<{3E387664-C799-4D62-B196-25776EF35C51}><C:\WINDOWS\system32\mxavpw0.dll> []
<{C0595A7E-2E2F-4B34-A83A-019270A0A464}><C:\WINDOWS\system32\tdffdl.dll> [N/A]
<{6E6CA8A1-81BC-4707-A54C-F4903DD70BAD}><C:\WINDOWS\system32\zgxfdx.dll> [N/A]
<{7FA4A83B-F99A-4bfc-A8E2-6A62B05D2C82}><C:\WINDOWS\TEMP\dat17.tmp> []
<{45AADFAA-DD36-42AB-83AD-0521BBF58C24}><C:\WINDOWS\system32\zjydcx.dll> [N/A]
<{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}><C:\WINDOWS\system32\hhrdxd.dll> [N/A]
<{7914E0AA-ECCB-4311-B584-C49538227824}><C:\WINDOWS\system32\jhfrxz.dll> [N/A]
<{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}><C:\WINDOWS\system32\wyrsdj.dll> [N/A]
<{1DB3C525-5271-46F7-887A-D4E1ADAA7632}><C:\WINDOWS\system32\hfrdzx.dll> [N/A]
<{CAED0F3B-DF8B-4DBF-BB20-8DFBC3199068}><C:\WINDOWS\system32\jhrcar.dll> [N/A]
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgrefg.dll> [N/A]
<{B29583D8-033A-4B9F-8553-7C5458F3FB8E}><C:\WINDOWS\system32\jdsaex.dll> [N/A]
==================================
服务
[uans / uans][Stopped/Auto Start]
<><N/A>
[Windows Accounts Driver / WindowsRemote][Running/Auto Start]
<C:\WINDOWS\system32\135.exe><N/A>
==================================
驱动程序
[86xlx / 86xlxw][Stopped/Disabled]
<System32\DRIVERS\86xlxw.sys><N/A>
[dohs / dohs][Stopped/Auto Start]
<\??\C:\WINDOWS\TEMP\tmp13.tmp><N/A>
[mhfp / mhfp][Stopped/Auto Start]
<\??\C:\WINDOWS\TEMP\tmp3.tmp><N/A>
[msfpfis64 / msfpfis64][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosmsfpfis64.sys><N/A>
[ntptdb / ntptdb][Stopped/Auto Start]
<\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\ntptdb.sys><N/A>
[ping / ping][Stopped/Auto Start]
<\??\C:\WINDOWS\TEMP\tmp20.tmp><N/A>
==================================
浏览器加载项
[]
{1AB1F65A-964F-4AE7-B254-05146A0E602E} <C:\Program Files\Internet Explorer\PLUGINS\WinSys16.Sys, N/A>
==================================
正在运行的进程
[C:\WINDOWS\system32\msosdohs00.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosping00.dll] [N/A, ]
[C:\WINDOWS\TEMP\dat33.tmp] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\msosdohs00.dll] [N/A, ]
[C:\WINDOWS\TEMP\dat17.tmp] [, 1, 0, 0, 1]
[PID: 488 / SYSTEM][C:\WINDOWS\system32\135.exe] [N/A, ]
[C:\WINDOWS\system32\msosdohs02.dll] [N/A, ]
[C:\WINDOWS\system32\msosping00.dll] [N/A, ]
[C:\WINDOWS\system32\fiosectc.dll] [N/A, ]
[C:\WINDOWS\system32\sqavpw0.dll] [N/A, ]
[C:\WINDOWS\system32\mxavpw0.dll] [N/A, ]
[C:\WINDOWS\system32\mxavpw3.dll] [N/A, ]
[C:\WINDOWS\TEMP\dat33.tmp] [, 1, 0, 0, 1]
[C:\WINDOWS\system32\anistio.dll] [N/A, ]
[C:\WINDOWS\system32\bincdwsa.dll] [N/A, ]
[C:\WINDOWS\system32\fmsjhif.dll] [N/A, ]
[C:\WINDOWS\system32\fmsbbqi.dll] [N/A, ]
[C:\WINDOWS\system32\msosdohs00.dll] [N/A, ]
[C:\WINDOWS\TEMP\dat17.tmp] [, 1, 0, 0, 1]