双击sreng,删除启动项目
<myMh2><C:\DOCUME~1\sailor\LOCALS~1\Temp\mh2\iexpl0re.EXE> [N/A]
<myZt2><C:\DOCUME~1\sailor\LOCALS~1\Temp\Zt2\SVCH0ST.EXE> [N/A]
<load><C:\PROGRA~1\svhost32.exe> [N/A]
mhs2><C:\DOCUME~1\sailor\LOCALS~1\Temp\nwHfDA.exe> [N/A]
<rxzs><C:\DOCUME~1\sailor\LOCALS~1\Temp\uZcNbz.exe> [N/A]
<wlzs><C:\DOCUME~1\sailor\LOCALS~1\Temp\dpqIyl.exe> [N/A]
<CdnCtr><C:\Program Files\CNNIC\Cdn\cdnup.exe> [CNNIC]
<zts2><C:\DOCUME~1\sailor\LOCALS~1\Temp\KlPLSq.exe> [N/A]
<{729B6C61-BDC5-4C09-A1DE-A296BA0B89EC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp> [N/A]
重启后删除 使用KILLBOX删除以下文件:
C:\DOCUME~1\sailor\LOCALS~1\Temp\Mhgx.dll
C:\DOCUME~1\sailor\LOCALS~1\Temp\Ztgx.dll
C:\WINDOWS\system32\windhcp.ocx
C:\WINDOWS\system32\dllwm.dll
C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp
C:\DOCUME~1\sailor\LOCALS~1\Temp\MjjiIs.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\xnhuQD.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\esMOrT.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\wlzs.dll
C:\DOCUME~1\sailor\LOCALS~1\Temp\KatWIR.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\xvYMql.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\XtKJLD.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\mh2\iexpl0re.EXE
C:\DOCUME~1\sailor\LOCALS~1\Temp\Zt2\SVCH0ST.EXE
C:\DOCUME~1\sailor\LOCALS~1\Temp\Ztgx.dll
C:\DOCUME~1\sailor\LOCALS~1\Temp\vJXWOj.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\nfrBxX.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\UVlppo.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\EhgfUx.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\ApUHYG.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\xoZnxx.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\mhs2.dll
C:\DOCUME~1\sailor\LOCALS~1\Temp\zts2.dll
C:\DOCUME~1\sailor\LOCALS~1\Temp\xoZnxx.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\rxzs.dll
[C:\DOCUME~1\sailor\LOCALS~1\Temp\PYRYAD.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\HNmDWh.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\CMxPUP.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\XUnHLt.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\shWZct.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\KlPLSq.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\nwHfDA.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\uZcNbz.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\dpqIyl.exe
C:\Program Files\svhost32.exe
C:\DOCUME~1\sailor\LOCALS~1\Temp\g.dll
删除完毕之后,清理系统临时文件。
不仅如此,个人感觉你的服务项和驱动项有一些没有能扫描到的。
你按照上面的方法,清理之后,重新扫描日志发上来。