安全模式下(开机后不断 按F8键 然后出来一个高级菜单 选择第一项 安全模式 进入系统)
打开sreng (就是你扫日志的软件)
启动项目 注册表 删除如下项目 (如果有哪项你认识或者确认不是病毒 请不要删除)
<svc><D:\DOCUME~1\dd\LOCALS~1\Temp\expseny.exe> [N/A]
<jwx078wu6wk3m7><D:\DOCUME~1\dd\LOCALS~1\Temp\iexplorer.exe> [N/A]
<wosa><D:\DOCUME~1\dd\LOCALS~1\Temp\woso.exe> [N/A]
<rxsa><D:\DOCUME~1\dd\LOCALS~1\Temp\rxso.exe> [N/A]
<wdsa><D:\DOCUME~1\dd\LOCALS~1\Temp\wdso.exe> [N/A]
<tlsa><D:\DOCUME~1\dd\LOCALS~1\Temp\tlso.exe> [N/A]
<dasa><D:\DOCUME~1\dd\LOCALS~1\Temp\daso.exe> [N/A]
<runeip><D:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<Local Security Authority Service><D:\WINNT\System32\lssas.exe> [N/A]
<Advanced DHTML Enable><D:\WINNT\System32\vvbb.exe> [N/A]
<RfwMain><"D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
<fysa><D:\DOCUME~1\dd\LOCALS~1\Temp\fyso.exe> [N/A]
<jtsa><D:\DOCUME~1\dd\LOCALS~1\Temp\jtso.exe> [N/A]
<wlsa><D:\DOCUME~1\dd\LOCALS~1\Temp\wlso.exe> [N/A]
<wgsa><D:\DOCUME~1\dd\LOCALS~1\Temp\wgso.exe> [N/A]
<wmsa><D:\DOCUME~1\dd\LOCALS~1\Temp\wmso.exe> [N/A]
<qjsa><D:\DOCUME~1\dd\LOCALS~1\Temp\qjso.exe> [N/A]
<MSDEG32><LYLoader.exe> [N/A]
<MSDWG32><LYLoadbr.exe> [N/A]
<MSDCG32 ><LYLeador.exe> [N/A]
<MSDOG32><LYLoador.exe> [N/A]
<MSDSG32><LYLoadar.exe> [N/A]
<MSDHG32><LYLoadhr.exe> [N/A]
<MSDQG32><LYLoadqr.exe> [N/A]
<?{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><> [N/A]
<?{0CD68AC9-FF63-3E61-626B-B663E62F6236}><> [N/A]
<{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><D:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.bmt> []
<{1496D5ED-7A09-46D0-8C92-B8E71A4304DF}><D:\WINNT\System32\msacn.dll> [N/A]
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><D:\Program Files\Internet Explorer\PLUGINS\System64.Sys> [N/A]
“启动项目”-“服务”-“Win32服务应用程序”中点“隐藏经认证的微软项目”,
选中以下项目,点“删除服务”,再点“设置”,在弹出的框中点“否”:
Win32 Debug Service / MSDebugsvc][Stopped/Auto Start]
<D:\WINNT\System32\msdebug.dll,input><Microsoft Corporation>
Remote Debug Service / RemoteDbg][Stopped/Auto Start]
<D:\WINNT\System32\RemoteDbg.dll,input><Microsoft Corporation>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<D:\WINNT\System32\windhcp.ocx,input><Microsoft Corporation>
[Network DDC / Windowsdate][Stopped/Auto Start]
<D:\WINNT\System32\servex.exe><N/A>
双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹" 并清除"隐藏受保护的操作系统文件(推荐)"前面的钩。在提示确定更改时,单击“是” 然后确定
然后删除<svc><D:\DOCUME~1\dd\LOCALS~1\Temp\expseny.exe> [N/A]
<jwx078wu6wk3m7><D:\DOCUME~1\dd\LOCALS~1\Temp\iexplorer.exe> [N/A]
<wosa><D:\DOCUME~1\dd\LOCALS~1\Temp\woso.exe> [N/A]
<rxsa><D:\DOCUME~1\dd\LOCALS~1\Temp\rxso.exe> [N/A]
<wdsa><D:\DOCUME~1\dd\LOCALS~1\Temp\wdso.exe> [N/A]
<tlsa><D:\DOCUME~1\dd\LOCALS~1\Temp\tlso.exe> [N/A]
<dasa><D:\DOCUME~1\dd\LOCALS~1\Temp\daso.exe> [N/A]
<runeip><D:\Program Files\Rising\AntiSpyware\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<Local Security Authority Service><D:\WINNT\System32\lssas.exe> [N/A]
<Advanced DHTML Enable><D:\WINNT\System32\vvbb.exe> [N/A]
<fysa><D:\DOCUME~1\dd\LOCALS~1\Temp\fyso.exe> [N/A]
<jtsa><D:\DOCUME~1\dd\LOCALS~1\Temp\jtso.exe> [N/A]
<wlsa><D:\DOCUME~1\dd\LOCALS~1\Temp\wlso.exe> [N/A]
<wgsa><D:\DOCUME~1\dd\LOCALS~1\Temp\wgso.exe> [N/A]
<wmsa><D:\DOCUME~1\dd\LOCALS~1\Temp\wmso.exe> [N/A]
<qjsa><D:\DOCUME~1\dd\LOCALS~1\Temp\qjso.exe> [N/A]
<{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><D:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.bmt> []
<{1496D5ED-7A09-46D0-8C92-B8E71A4304DF}><D:\WINNT\System32\msacn.dll> [N/A]
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><D:\Program Files\Internet Explorer\PLUGINS\System64.Sys> [N/A]
<D:\WINNT\System32\RemoteDbg.dll
<D:\WINNT\System32\windhcp.ocx
<D:\WINNT\System32\servex.exe><N/A>
D:\WINNT\System32\mspmsnsv.dll
<D:\WINNT\System32\netsrvcs.dll
[D:\WINNT\System32\skyubr.dll] [N/A, ]