一、拔掉网线;
二、进入注册表编辑器,删除以下注册表子项:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Loader.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kmailmon.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ras]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep]
三、用SRENG扫描工具删除如下服务项目:
[Help and Support / helpsvc][Stopped/Auto Start]
<C:\WINNT\system32\interne.exe><1>
[Inupiat / Inupiat][Running/Auto Start]
<C:\WINNT\system32\Inupiat.exe><N/A>
[Peridtig Dista / PerAdaps Tation][Running/Auto Start]
<C:\WINNT\system32\Com\secvec.exe><N/A>
[Symantec AntiVirus / Symantec AntiVirus][Running/Auto Start]
<C:\WINNT\system32\Microsoft\Symantec.exe><N/A>
[Windows Reoid / Windows Reoid][Stopped/Auto Start]
<C:\WINNT\Windows Reoid><N/A>
四、重启电脑,用WINRAR找到和删除以下文件:
C:\WINNT\system32\interne.exe
C:\WINNT\system32\Inupiat.exe
C:\WINNT\system32\Com\secvec.exe
C:\WINNT\system32\Microsoft\Symantec.exe
C:\WINNT\Windows Reoid
五、联网将瑞星升级到最新版本,全盘杀毒。
六、把c:\winnt\soundman.exe文件压缩,把压缩包发到可疑文件交流区鉴定,该文件是否正常我尚不清楚。