参考这里
http://bbs.ikaka.com/showtopic-8502100.aspx下载并安装PE 重起进入PE 用附件中的费尔木马强力清除助手删除以下文件:
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.624328.exe
c:\windows\system32\com\smss.exe
c:\windows\system32\com\lsass.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.622281.exe
c:\windows\system32\dnsq.dll
c:\documents and settings\all users.windows\「开始」菜单\程序\启动\~.exe.80953.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.540812.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.595843.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.601015.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.608859.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.618203.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.619281.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.620281.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.621328.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.626453.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.627484.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.630968.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.630984.exe
c:\documents and settings\administrator.www-33da5a7e76a\「开始」菜单\程序\启动\~.exe.632640.exe
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.EXE.618203.EXE
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.EXE.619281.EXE
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.EXE.620281.EXE
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.EXE.621328.EXE
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.EXE.622281.EXE
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
注意该项[AppInit_DLLs]修改:把<C:\WINDOWS\system32\dnsq.dll>修改为<>即清空
启动项目 -- 启动文件夹之如下项删除:
[~.exe.80953] <C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\~.exe.80953.exe>
[~.exe.540812] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.540812.exe>
[~.exe.595843] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.595843.exe>
[~.exe.601015] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.601015.exe>
[~.exe.608859] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.608859.exe>
[~.exe.618203] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.618203.exe>
[~.exe.619281] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.619281.exe>
[~.exe.620281] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.620281.exe>
[~.exe.621328] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.621328.exe>
[~.exe.622281] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.622281.exe>
[~.exe.624328] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.624328.exe>
[~.exe.626453] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.626453.exe>
[~.exe.627484] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.627484.exe>
[~.exe.630968] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.630968.exe>
[~.exe.630984] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.630984.exe>
[~.exe.632640] <C:\Documents and Settings\Administrator.WWW-33DA5A7E76A\「开始」菜单\程序\启动\~.exe.632640.exe>
处理的时候不要运行任何原硬盘上的任何可执行文件,所有要用到的软件全部重新下载直接保存到c:\windows\system32\文件夹内再运行,记住做完以上操作之后,
点击下载大蜘蛛,更新后在首次默认的快速扫描之后再进行一次完全扫描