找到文件C:\WINDOWS\System32\rarjbpi.dll重命名为11111111111.111111
重起后删除11111111111.11111
删除文件
C:\WINDOWS\WINLOG0N.EXE
C:\WINDOWS\sysinfo.exe
用SRENG删除注册表中
<{2598FF45-DA60-F48A-BC43-10AC47853D52}><C:\WINDOWS\System32\rarjbpi.dll> []
把[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><rarjbpi.dll> []设置为空
删除服务
[LanSeeker Server / LanSeeker][Stopped/Auto Start]
<"C:\WINDOWS\WINLOG0N.EXE" -service><N/A>
[LSNail Agent Service / LSAgent][Stopped/Auto Start]
<><N/A>
[Portable Audio Service / PraSrv][Running/Auto Start]
<C:\WINDOWS\sysinfo.exe><N/A>
[Windows Installe / wmir][Stopped/Auto Start]
<><N/A>
下载安全卫士360下载:http://www.onlinedown.net/soft/50671.htm
把IE清理下
重起进入安全模式(开机不停的按F8,选择安全模式启动) 清空临时文件夹:
C:\Documents and Settings\用户名\Local Settings\Temporary Internet Files
C:\Documents and Settings\用户名\Local Settings\Temp