【回复“如晨雪花2008”的帖子】
开始--运行
输入regedit
确定
进入注册表
修改
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe"C:\WINDOWS\KesenjanganSosial.exe">
为
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
修改
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\
AlternateShell = "cmd-brontok.exe"
为
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\
AlternateShell = "cmd.exe"
修改
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\explorer\advanced
"Hidden"="0"
为
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\explorer\advanced
"Hidden"="2"
修改
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\explorer\advanced
"HideFileExt"="1"
为
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\explorer\advanced
"HideFileExt"="0"
删除如下自启动项:
HKLM\software\microsoft\windows\currentversion\run\
Bron-Spizaetus = "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"
HKCU\software\microsoft\windows\currentversion\run\
Tok-Cirrhatus-1464 = "C:\Documents and Settings\用户名\Local Settings\Application Data\br3951on.exe"
HKCU\software\microsoft\windows\currentversion\run\
Tok-Cirrhatus = ""
HKLM\SoftWare\Microsoft\Windows\CurrentVersionWinlogon\Shell
Bron-Spizaetus="C:\WINDOWS\ShellNew\RakyatKelaparan.exe"
============
删除如下文件:
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\br8241on.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\csrss.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\inetinfo.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\services.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\smss.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\svchoost.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\lsass.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\winlogon.exe
C:\WINDOWS\System32\administrator'ssetting.exe
C:\WINDOWS\System32\cmd-brontok.exe
C:\WINDOWS\KesenjanganSosial.exe
C:\WINDOWS\ShellNew\RakyatKelaparan.exe
C:\DocumentsandSettings\administrator\[开始]菜单\程序\启动\empty.pif