【回复“poipoise”的帖子】
任务管理器结束进程:
[PID: 1084][C:\WINDOWS\rundl132.exe] [, 1.0.0.0]
用SRENG删除启动项:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<wl><C:\WINDOWS\System32\svvosts.exe> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><C:\WINDOWS\rundl132.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{81201A28-1A28-120D-2812-A2820A28120D}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\1A28120D.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Realplayer.exe><; > [N/A]
<RealTray><; C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER> [N/A]
显示隐藏文件,删除文件:
C:\WINDOWS\System32\svvosts.exe
C:\WINDOWS\rundl132.exe
C:\Program Files\Common Files\Microsoft Shared\MSINFO\1A28120D.dll
C:\WINDOWS\rundl132.exe
C:\WINDOWS\System32\mywl.dll(如果存在)
ZO&Ô§°Â©c*bbs.ikaka.com¢8°<È