用ICESWORD结束下面进程
C:\WINDOWS\Explorer.EXE
C:\Program Files\Rising\AntiSpyware\runiep.exe
C:\Program Files\racer-henan-cnc\racer.exe
C:\Program Files\Internet Explorer\iexplore.exe
禁止进程创建
SRENG删除下面注册表项
<xhti5v7ddcdssu5><C:\DOCUME~1\user\LOCALS~1\Temp\1explore.exe> [N/A]
<1imv77legwbr><C:\DOCUME~1\user\LOCALS~1\Temp\c0nime.exe> [N/A]
<z35y5q><C:\DOCUME~1\user\LOCALS~1\Temp\iexpl0re.exe> [N/A]
<9wc00402><C:\DOCUME~1\user\LOCALS~1\Temp\crasos.exe> [N/A]
<zvqltc><C:\DOCUME~1\user\LOCALS~1\Temp\rundl132.exe> [N/A]
<0y><C:\DOCUME~1\user\LOCALS~1\Temp\winlog0n.exe> [N/A]
<ejfr0um0><C:\DOCUME~1\user\LOCALS~1\Temp\cftmon.exe> [N/A]
删除驱动
<\SystemRoot\system32\enusndis.sys><N/A>
清空C:\DOCUME~1\user\LOCALS~1\Temp\cftmon.exe
你的后面的几个不明驱动,自己备份后试着删除