中毒严重:
删除启动项
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]下的以下注册表分支及<>内对应文件
<{00070007-0007-0007-0007-00070007BB15}><C:\WINDOWS\system32\dpvvoxmh.dll> [File is missing]
<{00150015-0015-0015-0015-00150015BB15}><C:\WINDOWS\system32\gmalkxlj.dll> [File is missing]
<{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}><C:\WINDOWS\system32\wklsdd.dll> [File is missing]
<{00170017-0017-0017-0017-00170017BB15}><C:\WINDOWS\system32\msobjstl.dll> [File is missing]
<{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}><> [N/A]
<{45AADFAA-DD36-42AB-83AD-0521BBF58C24}><> [N/A]
<{A9895933-6636-4281-BC58-EE6DE2AF96E3}><C:\WINDOWS\system32\ddserh.dll> [File is missing]
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> [File is missing]
<{B29583D8-033A-4B9F-8553-7C5458F3FB8E}><C:\WINDOWS\system32\jdsaex.dll> [File is missing]
<{7914E0AA-ECCB-4311-B584-C49538227824}><C:\WINDOWS\system32\jhfrxz.dll> [File is missing]
<{00130013-0013-0013-0013-00130013BB15}><C:\WINDOWS\system32\ksuserfy.dll> [File is missing]
<{5E907A48-400E-4EA8-9792-FFAE052D59E9}><C:\WINDOWS\system32\pedadt.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]下的注册表分支和<>内相关文件
<dpvvoxmh.dll><C:\WINDOWS\system32\dpvvoxmh.dll> [File is missing]
<gmalkxlj.dll><C:\WINDOWS\system32\gmalkxlj.dll> [File is missing]
<msobjstl.dll><C:\WINDOWS\system32\msobjstl.dll> [File is missing]
<ksuserfy.dll><C:\WINDOWS\system32\ksuserfy.dll> [File is missing]
并用附件去映像劫持