%Documents and Settings%\当前用户名\Local Settings\Temp\mh1\iexpl0re.EXE %Documents and Settings%\当前用户名\Local Settings\Temp\mh2\iexpl0re.EXE %Documents and Settings%\当前用户名\Local Settings\Temp\Wl2\lexplore.exe %Documents and Settings%\当前用户名\Local Settings\Temp\Zt2\SVCH0ST.exe %Documents and Settings%\当前用户名\Local Settings\Temp\Mhgx.dll %Documents and Settings%\当前用户名\Local Settings\Temp\Mhgl.dll %Documents and Settings%\当前用户名\Local Settings\Temp\Mhgy.dll %Documents and Settings%\当前用户名\Local Settings\Temp\Wlgx.dll %Documents and Settings%\当前用户名\Local Settings\Temp\ZtgL.dll %Documents and Settings%\当前用户名\Local Settings\Temp\ZtgQ.dll
2、可能新建注册表键值:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\myMH1 键值: 字符串: " %Documents and Settings%\当前用户名\Local Settings\Temp\mh1\iexpl0re.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\myMH2 键值: 字符串: " %Documents and Settings%\当前用户名\Local Settings\Temp\mh2\iexpl0re.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\myW12 键值: 字符串: " %Documents and Settings%\当前用户名\Local Settings\Temp\mh2\lexplore.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\myZt2 键值: 字符串: " %Documents and Settings%\当前用户名\Local Settings\Temp\mh2\svch0st.exe"
%Documents and Settings%\当前用户名\Local Settings \Temp\mh1\iexpl0re.EXE %Documents and Settings%\当前用户名\Local Settings \Temp\mh2\iexpl0re.EXE %Documents and Settings%\当前用户名\Local Settings \Temp\Wl2\lexplore.exe %Documents and Settings%\当前用户名\Local Settings \Temp\Zt2\SVCH0ST.exe %Documents and Settings%\当前用户名\Local Settings \Temp\Mhgx.dll %Documents and Settings%\当前用户名\Local Settings \Temp\Mhgl.dll %Documents and Settings%\当前用户名\Local Settings \Temp\Mhgy.dll %Documents and Settings%\当前用户名\Local Settings \Temp\Wlgx.dll %Documents and Settings%\当前用户名\Local Settings \Temp\ZtgL.dll %Documents and Settings%\当前用户名\Local Settings \Temp\ZtgQ.dll
(4) 恢复可能被病毒修改的注册表项目,删除病毒添加的注册表项
HKEY_CURRENT_USER\Software\Microsoft\Windows \CurrentVersion\Run\myMH1键值: 字符串: " %Documents and Settings%\当前用户名\Local Settings\Temp\mh1\iexpl0re.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows \CurrentVersion\Run\myMH2键值: 字符串: " %Documents and Settings%\当前用户名\Local Settings\Temp\mh2\iexpl0re.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows \CurrentVersion\Run\myW12键值: 字符串: " %Documents and Settings%\当前用户名\Local Settings\Temp\mh2\lexplore.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows \CurrentVersion\Run\myZt2键值: 字符串: " %Documents and Settings%\当前用户名\Local Settings\Temp\mh2\svch0st.exe"