运行SRENG删除启动项注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<InternetEx><C:\WINDOWS\system\8.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<internet><C:\WINDOWS\system\taskmgr.exe /scan> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
<WinlogonNotify: psfus><fusstub.dll> [UPEK Inc.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon]
<WinlogonNotify: VESWinlogon><VESWinlogon.dll> [Sony Corporation]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<IEXPLORE.EXE><; C:\WINDOWS\system32\IEXPLORE.EXE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<mhs2><; C:\DOCUME~1\sony\LOCALS~1\Temp\mhs2.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<SrtWatch><; C:\PROGRA~1\C501~1\SrtWatch.exe> [N/A]
<yok.exe><; C:\Program Files\yok\yok.exe> [N/A]
删除服务:[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
删除文件:C:\WINDOWS\system\8.exe
C:\WINDOWS\system\taskmgr.exe
C:\WINDOWS\system32\fusstub.dll
C:\WINDOWS\system32\VESWinlogon.dll这个被份后删除~

C:\WINDOWS\system32\IEXPLORE.EXE
C:\DOCUME~1\sony\LOCALS~1\Temp\mhs2.exe建议安全模式下清空TEMP

C:\PROGRA~1\C501~1\SrtWatch.exe
C:\Program Files\yok这个文件夹下都删除

C:\WINDOWS\system32\windhcp.ocx
安全模式下~开始-运行-regedit-搜索YOK.EXE和YOK.DLL,把搜索到的删除