Keywords: msdeped32.exe ktv.exe wz041.dll notaped.exe Cdaudio.sys This article introduces the solution that can't double hit the opening
1, shut down the virus process
Ctrl + Alt + Del Task Manager, look in the process for SxS or svohost (not svchost, one letter), and then end it (not all systems show this process, skip this step).
2, restore the registry (some systems may be virus did not modify the registry, test method is, if your system can see hidden files so this step can be omitted, suggest everyone to see)
(remove virus from startup Item) Open registry Run--regedit
Hkey_local_machine>software>microsoft>windows>currentversion>run
SVOHOST.exe or Sxs.exe
Find Soundmam (note not soundman, only one letter) key value, there may be two, delete the key value is C:windowssystem32svohost.exe
(Show hidden system files)
Hkey_local_machinesoftwaremicrosoftwindowscurrentversionexploreradvancedfolderhiddenshowall, Modify the CheckedValue key value to 1
Notice here, the virus will be valid DWORD value CheckedValue deleted, a new invalid string value CheckedValue, type REG_SZ, and the key value to 0! It's no use changing this to 1. We have to see the type behind the CheckedValue, the correct is "Red_dword" instead of "REG_SZ" (some of the virus variants will directly delete this checkedvalue, just like the following, you can build a new one on it)
Method: Delete the CheckedValue key value, right-click the new--dword value-named CheckedValue, and modify its key value of 1 so that you can select Show all hidden files and show system files.
Set system files and hidden files to display in folder--Tools--Folder Options