针对你的问题的解决方法
安全模式下(开机后不断 按F8键 然后出来一个高级菜单 选择第一项 安全模式 进入系统)
打开sreng (就是你扫日志的软件)启动项目 注册表 删除如下项目 (如果有哪项你认识或者确认不是病毒 请不要删除)
<tm7y0ss5yqb2><C:\WINDOWS\winlog0a.exe> [N/A]
<h2vw5hbw155u060><C:\WINDOWS\iexpl0ra.exe> [N/A]
<9i><C:\WINDOWS\Servera.exe> [N/A]
<z18y1e><C:\WINDOWS\crasoa.exe> [N/A]
<qbm6xybvi><C:\WINDOWS\rundl13a.exe> [N/A]
<qkf7lywi5bz><C:\WINDOWS\c0nima.exe> [N/A]
<z5j1byzh><C:\WINDOWS\servicea.exe> [N/A]
<j><C:\WINDOWS\cftmoa.exe> [N/A]
<
ObjectDock><C:\Program Files\
ObjectDock\
ObjectDock.exe> [Stardock]
<FYNEWS><C:\DOCUME~1\Ryan\LOCALS~1\Temp\sl.exe> [N/A]
<FYNEWS><C:\DOCUME~1\Ryan\LOCALS~1\Temp\sl.exe> [N/A]
<cmdbcs><C:\WINDOWS\cmdbcs.exe> [N/A]
<{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.rxk> [N/A]
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys> [N/A]
双击我的电脑-工具-文件夹选项-查看-显示所有文件和文件夹,把“隐藏受保护的系统文件”的勾去掉。
然后删除
[C:\WINDOWS\system32\tphklock.dll] [N/A, N/A]
[C:\WINDOWS\system32\Qqzos.dll] [N/A, N/A]
[C:\WINDOWS\system32\Gjzos.dll] [N/A, N/A]
[C:\WINDOWS\system32\Wmzos.dll] [N/A, N/A]
[C:\WINDOWS\system32\Rav26.dll] [N/A, N/A]
[C:\WINDOWS\system32\Msxos.dll] [N/A, N/A]
[C:\WINDOWS\system32\Rav32.dll] [N/A, N/A]
[C:\WINDOWS\system32\LgSym.dll] [N/A, N/A]
[C:\WINDOWS\system32\LgSyl.dll] [N/A, N/A]
[C:\WINDOWS\system32\Wmzos.dll] [N/A, N/A]
[C:\WINDOWS\system32\Gjzos.dll] [N/A, N/A]
[C:\WINDOWS\system32\Qqzos.dll] [N/A, N/A]
[PID: 1432][C:\WINDOWS\servicer.exe] [N/A, N/A]
[C:\WINDOWS\system32\Qqzos.dll] [N/A, N/A]
[PID: 3396][C:\WINDOWS\c0nime.exe] [N/A, N/A]
[C:\DOCUME~1\Ryan\LOCALS~1\Temp\h22q9eo.dll] [N/A, N/A]
[C:\WINDOWS\system32\Gjzos.dll] [N/A, N/A]
[PID: 2460][C:\WINDOWS\cftmon.exe] [N/A, N/A]
[C:\DOCUME~1\Ryan\LOCALS~1\Temp\g.dll] [N/A, N/A]
[C:\WINDOWS\system32\Wmzos.dll] [N/A, N/A]
[PID: 2884][C:\WINDOWS\winlog0n.exe] [N/A, N/A]
[C:\DOCUME~1\Ryan\LOCALS~1\Temp\5uygav.dll] [N/A, N/A]
[C:\WINDOWS\system32\LgSyl.dll] [N/A, N/A]
<tm7y0ss5yqb2><C:\WINDOWS\winlog0a.exe> [N/A]
<h2vw5hbw155u060><C:\WINDOWS\iexpl0ra.exe> [N/A]
<9i><C:\WINDOWS\Servera.exe> [N/A]
<z18y1e><C:\WINDOWS\crasoa.exe> [N/A]
<qbm6xybvi><C:\WINDOWS\rundl13a.exe> [N/A]
<qkf7lywi5bz><C:\WINDOWS\c0nima.exe> [N/A]
<z5j1byzh><C:\WINDOWS\servicea.exe> [N/A]
<j><C:\WINDOWS\cftmoa.exe> [N/A]
<
ObjectDock><C:\Program Files\
ObjectDock\
ObjectDock.exe> [Stardock]
<FYNEWS><C:\DOCUME~1\Ryan\LOCALS~1\Temp\sl.exe> [N/A]
<FYNEWS><C:\DOCUME~1\Ryan\LOCALS~1\Temp\sl.exe> [N/A]
<cmdbcs><C:\WINDOWS\cmdbcs.exe> [N/A]
<{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.rxk> [N/A]
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys> [N/A]
[PID: 3736][C:\WINDOWS\iexpl0re.exe] [N/A, N/A]
[C:\DOCUME~1\Ryan\LOCALS~1\Temp\cs5fnoqm.dll] [N/A, N/A]
[C:\WINDOWS\system32\LgSym.dll] [N/A, N/A]
[PID: 764][C:\WINDOWS\Servere.exe] [N/A, N/A]
[C:\DOCUME~1\Ryan\LOCALS~1\Temp\p9o.dll] [N/A, N/A]
[C:\WINDOWS\system32\Rav32.dll] [N/A, N/A]
[PID: 4308][C:\WINDOWS\crasos.exe] [N/A, N/A]
[C:\DOCUME~1\Ryan\LOCALS~1\Temp\4p8by7.dll] [N/A, N/A]
[C:\WINDOWS\system32\Msxos.dll] [N/A, N/A]
[PID: 4588][C:\WINDOWS\rundl132.exe] [N/A, N/A]