C:\WINDOWS\system32\COMRes.dll被修改,建议从其他同版本操作系统中复制此文件,将其覆盖到本机上。
C:\WINDOWS\Tasks\CgbYR44s5jCmgAd6ar.inf
C:\WINDOWS\system32\122B901E.dll
C:\WINDOWS\Tasks\c2nH4numz9knY5zqnC.inf
C:\WINDOWS\fonts\acCjngH97w.fon
C:\WINDOWS\Tasks\SbrmpxjdCrgRAFhz4gHh.inf
C:\WINDOWS\system32\jY8sGUnWqbZb3x2BPhY.dllC:\WINDOWS\system32\BtmBAnd89jc9PsPq5EKNj.inf
C:\WINDOWS\system32\SjQGXVR4VJHtTHeDE75wC.inf
C:\WINDOWS\system32\CDuAUVkGy9.dll
C:\WINDOWS\system32\AMNCZw74h8gwd6CpYGkrZDy8.inf
C:\WINDOWS\Tasks\EfEPEaD4ZpVMUXrDbS.inf
C:\WINDOWS\Downloaded Program Files\rJaeKv7CcbwSzhQbDu.cur
C:\WINDOWS\system32\uvwrulpc.dll
<C:\WINDOWS\system32\ss12A701dll.dll
<C:\WINDOWS\system32\pwd4Xpm8KYzkcbqcaKT.inf
C:\WINDOWS\Downloaded Program Files\AnXnubyMnv58c9vaECWX.cur
C:\WINDOWS\Tasks\JJX5r8wnsqUnNxGwpwn.inf
C:\WINDOWS\Tasks\TDz5y2TEAKw2z7xkPhf9Sqj.inf
C:\WINDOWS\system32\PERrGx5DkqSbQdwauCRQH.dll
C:\WINDOWS\Downloaded Program Files\SjRjQgREDp3P8B4rEEg.cur
C:\WINDOWS\system32\WQVBYhAJ6ADw5qzCY8gv84KTH.inf
C:\WINDOWS\Tasks\yGfdVUegEQm9fhY5rnN.inf
C:\WINDOWS\Downloaded Program Files\WUstNjhyfQfpv8PQbC.cur
C:\WINDOWS\Downloaded Program Files\NnjrQW5EUm9zePgHXM2eB44E.cur
C:\WINDOWS\system32\2exJW3dsaTgWrf5uAPadmHN.inf
C:\WINDOWS\Downloaded Program Files\sZaeAC74EzXJeVeJu6p.cur
C:\WINDOWS\system32\CWcQnWxHjWqtE6PsYyEe.inf
C:\WINDOWS\system32\rb37sCqvGmszGJ3aQYB5qRczx.inf
C:\WINDOWS\system32\qzp3jTZCSfSh.dll
C:\WINDOWS\system32\ndxq9awMc.dll
C:\WINDOWS\system32\08223B03.dll
C:\WINDOWS\system32\t9hdtMrwMeQcvYV3CMvhtNZpC.inf
C:\WINDOWS\system32\SCEVFJRCmaB7.dll
C:\WINDOWS\Downloaded Program Files\gxrSG8sdA4hAbGNQXnr9JGFu6nZ.cur
C:\WINDOWS\fonts\A97CRaCB.fon
C:\WINDOWS\system32\FsmBY3kmWnAG5gRbwGgU.inf>
C:\WINDOWS\system32\z6FVkEF47huPzgaXee.inf
C:\WINDOWS\Tasks\CgbYR44s5jCmgAd6ar.inf
C:\WINDOWS\system32\ss12A701dll.dll
C:\WINDOWS\system32\uvwrulpc.dll
C:\WINDOWS\system32\NXD.exe
C:\WINDOWS\system32\e10811796t.exe
C:\WINDOWS\system32\ss12A701dll.dll
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\Tasks\CgbYR44s5jCmgAd6ar.inf
C:\WINDOWS\system32\qt-dx3.dll
建议把样本发给瑞星,地址为:
http://mailcenter.rising.com.cn/FileCheck/提交后,可自行查询处理进度。