进注册表,打开这个目录
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
删除
<{E3531A16-FFEA-416F-82DF-32FEDE02EABF}><C:\WINDOWS\system32\emHnPuBAaF7XjuXBbdxSg.dll> []
<{B8898C49-7B3A-4306-A9EF-8E186EDEE5EA}><C:\WINDOWS\system32\Qh6xX7VN48sVPnK.dll> []
<{108DA6C0-CFBF-41D4-9A09-C4D06AE6FFD2}><C:\WINDOWS\system32\Q9q2MHJ3uTBErM7wc.dll> []
<{0220FBE7-F757-4C74-B246-D6703DCF1087}><C:\WINDOWS\system32\EmfVcSFcRkARFbbTQW5V5.dll> []
<{762D618C-E2CB-4217-8275-03302A93073F}><C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon> []
<{9AD1DE62-196C-4C01-9A2F-0BEDEF727C59}><C:\WINDOWS\system32\mFr9FPruEFZ9VNdrveJunw3.dll> []
<{D6129F8A-6F6E-41D7-BBC9-AC7426759CED}><C:\WINDOWS\system32\w7uds3zyayg9.dll> []
<{427E02E6-39DB-4424-A49C-7553CD1331F5}><C:\WINDOWS\system32\WcCtgJ4zcxHF.dll> []
<{76CBCF38-0583-44C7-A1AE-D463DFE625EC}><C:\WINDOWS\system32\skcfujQ5EDN.dll> []
<{DA112397-5376-4E52-A333-A85284658DEA}><C:\WINDOWS\fonts\NPPVWvYEyCe8H.fon> []
<{8708994F-1758-4C2C-9A3F-FA22D6CCCB41}><C:\WINDOWS\fonts\A97CRaCB.fon> []
<{704C3595-DB85-40F6-A601-8D6F346907BD}><C:\WINDOWS\system32\704C3595.dll> []
<{15882A2F-A06D-486E-8958-E84C86CBF273}><C:\WINDOWS\fonts\fyrwJf5Qfhh.fon> []
<{CD95107F-52A5-42A4-9914-18949993E798}><C:\WINDOWS\fonts\tY5UFS434YYd.fon> []
<{5405A7B2-F3F5-446F-8715-2A4EF674E079}><C:\WINDOWS\system32\rfpz9wwyy2np.dll> []
<{A761BE8E-C15A-4DDD-A777-2C683E9E96C8}><C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll> []
<{4642593F-4159-4C7B-9036-33D6CD7F1750}><C:\WINDOWS\fonts\vds9ae5G5FmED.fon> []
<{0A2D7F10-1153-4061-AA4B-ACB870212B57}><C:\WINDOWS\system32\z5WRXqHagksJxWt.dll> []
<{76B9BA7A-81D0-4979-8598-8471F2AB5186}><C:\WINDOWS\system32\76B9BA7A.dll> []
<{23DA65D2-C696-4EE4-BEE8-B4841DEC3E30}><C:\WINDOWS\system32\ndxq9awMc.dll> []
<{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}><C:\WINDOWS\system32\08223B03.dll> []
<{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}><C:\WINDOWS\system32\122B901E.dll> []
<{36AC68E6-0C26-4D39-B98E-54B49DAB6BAA}><C:\WINDOWS\system32\dhDhwS7fFW.dll> []
<{822775B8-E45B-4E55-9325-0753A0C1DC00}><C:\WINDOWS\system32\wdGSVBqAs3Xk.dll> []
<{BD07AE7E-DB9C-4FFB-BD21-99DCC8434610}><C:\WINDOWS\system32\EMPPpCCSA8GtjURjn.dll> []
<{51AA0D89-E9A9-4284-93E8-40C0FDD59304}><C:\WINDOWS\system32\eNyN5X48HrtXc.dll> []
<{50EBD6A5-0CF6-4E59-AE08-CCD991AA0596}><C:\WINDOWS\system32\GU6f5sW42mdc.dll> []
<{2EF0D734-21FD-4225-A1A2-BCD296182AAF}><C:\WINDOWS\system32\2EF0D734.dll> []
<{1719B301-B494-4185-9379-242461F9CF02}><C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.dll> []
<{CD478099-014D-4B3A-A4BB-B518F1019BC7}><C:\WINDOWS\system32\SCEVFJRCmaB7.dll> []
<{69B265A2-A172-4D27-BDF1-917E6D8B1DCC}><C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon> []
<{93F33500-527E-4E33-AECA-69B15243A90E}><C:\WINDOWS\system32\cRsAQd4hw.dll> []
<{38FEFE05-702C-440D-AD5C-B796209A1CC5}><C:\WINDOWS\system32\Y4npJWJNr.dll> []
<{24144CB8-10ED-4BFC-843F-68A9F3369947}><C:\WINDOWS\fonts\SD78dgC7hD2sktQHyAu.fon> []
<{A5CA6C70-7185-4466-AB45-B1C34E7A37CA}><C:\WINDOWS\system32\ed78ab9.dll> []
<{B14764E8-6DD3-4781-B7F8-B94E662B8ED0}><C:\Documents and Settings\winson\Application Data\T1.dll> []
删除
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<360Soft><C:\WINDOWS\system32\scvhost.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll,> []
删除以下文件
[C:\WINDOWS\system32\COMRes.dll] [N/A, ]
[C:\WINDOWS\system32\emHnPuBAaF7XjuXBbdxSg.dll] [N/A, ]
[C:\WINDOWS\system32\Qh6xX7VN48sVPnK.dll] [N/A, ]
[C:\WINDOWS\system32\Q9q2MHJ3uTBErM7wc.dll] [N/A, ]
[C:\WINDOWS\system32\EmfVcSFcRkARFbbTQW5V5.dll] [N/A, ]
[C:\WINDOWS\fonts\zEfE48cw9EmcFaR.fon] [N/A, ]
[C:\WINDOWS\system32\mFr9FPruEFZ9VNdrveJunw3.dll] [N/A, ]
[C:\WINDOWS\system32\w7uds3zyayg9.dll] [N/A, ]
[C:\WINDOWS\system32\skcfujQ5EDN.dll] [N/A, ]
[C:\WINDOWS\fonts\NPPVWvYEyCe8H.fon] [N/A, ]
[C:\WINDOWS\fonts\A97CRaCB.fon] [N/A, ]
[C:\WINDOWS\system32\704C3595.dll] [N/A, ]
[C:\WINDOWS\fonts\fyrwJf5Qfhh.fon] [N/A, ]
[C:\WINDOWS\fonts\tY5UFS434YYd.fon] [N/A, ]
[C:\WINDOWS\system32\rfpz9wwyy2np.dll] [N/A, ]
[C:\WINDOWS\system32\a4rxQxCvNBMNnpqs.dll] [N/A, ]
[C:\WINDOWS\fonts\vds9ae5G5FmED.fon] [N/A, ]
[C:\WINDOWS\system32\z5WRXqHagksJxWt.dll] [N/A, ]
[C:\WINDOWS\system32\76B9BA7A.dll] [N/A, ]
[C:\WINDOWS\system32\ndxq9awMc.dll] [N/A, ]
[C:\WINDOWS\system32\08223B03.dll] [N/A, ]
[C:\WINDOWS\system32\122B901E.dll] [N/A, ]
[C:\WINDOWS\system32\dhDhwS7fFW.dll] [N/A, ]
[C:\WINDOWS\system32\WcCtgJ4zcxHF.dll] [N/A, ]
[C:\WINDOWS\system32\wdGSVBqAs3Xk.dll] [N/A, ]
[C:\WINDOWS\system32\EMPPpCCSA8GtjURjn.dll] [N/A, ]
[C:\WINDOWS\system32\eNyN5X48HrtXc.dll] [N/A, ]
[C:\WINDOWS\system32\GU6f5sW42mdc.dll] [N/A, ]
[C:\WINDOWS\system32\2EF0D734.dll] [N/A, ]
[C:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.dll] [N/A, ]
[C:\WINDOWS\system32\SCEVFJRCmaB7.dll] [N/A, ]
[C:\WINDOWS\system32\cRsAQd4hw.dll] [N/A, ]
[C:\WINDOWS\system32\Y4npJWJNr.dll] [N/A, ]
[C:\WINDOWS\fonts\SD78dgC7hD2sktQHyAu.fon] [N/A, ]
[C:\WINDOWS\system32\ed78ab9.dll] [N/A, ]
[C:\Documents and Settings\winson\Application Data\T1.dll] [N/A, ]
[C:\WINDOWS\fonts\jUxfqJDwmfQEHcy2.fon] [N/A, ]
用下面链接里的工具处理COMRes.dll
http://bbs.ikaka.com/attachment.aspx?attachmentid=542252删除
Autorun.inf
[E:\]
[AutoRun]
open=recycle.{645FF040-5081-101B-9F08-00AA002F954E}\kav32.exe
shell\open=打开(&O)
shell\open\Command=recycle.{645FF040-5081-101B-9F08-00AA002F954E}\kav32.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=recycle.{645FF040-5081-101B-9F08-00AA002F954E}\kav32.exe
清空回收站,全盘搜索kav32.exe,一样要删除掉
清除文件的工具可以使用xboxdel,置顶帖里有