木马群呀
改注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><myasemt.dll wcnonpe.dll longasus.dll xboxdo.dll theralte.dll follwel.dll jolin0.dll hourpx2.dll> [N/A]
为<AppInit_DLLs><>
操作方法见我签名
建议先用暴力删除工具删除病毒文件并抑制再生
再处理其他
删除文件
C:\windos\system32\myasemt.dll
C:\windos\system32\wcnonpe.dll
C:\windos\system32\ longasus.dll
C:\windos\system32\xboxdo.dll
C:\windos\system32\theralte.dll
C:\windos\system32\follwel.dll
C:\windos\system32\jolin0.dll
C:\windos\system32\ hourpx2.dll
删除启动项及对应dll文件
<{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}><C:\WINDOWS\system32\wklsdd.dll> []
<{A9895933-6636-4281-BC58-EE6DE2AF96E3}><C:\WINDOWS\system32\ddserh.dll> []
<{84143967-B645-4BFF-B873-DA1DC886E9A7}><C:\WINDOWS\system32\cedafb.dll> []
<{006CA8A1-61BC-4774-A54C-F49034270BAD}><C:\WINDOWS\system32\zgtwfx.dll> []
<{45AADFAA-DD36-42AB-83AD-0521BBF58C24}><C:\WINDOWS\system32\zycdex.dll> []
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgdewg.dll> []
<{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}><C:\WINDOWS\system32\hhrdxd.dll> []
<{EB71E0B3-E97D-4D30-8733-E28266467617}><C:\WINDOWS\system32\wyhesm.dll> []
<{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6}><C:\WINDOWS\system32\fsrgeb.dll> []
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> []
<{F99DEFDD-200B-4410-B572-E90883D527D2}><C:\WINDOWS\system32\wrqszl.dll> []
<{461D2AB4-29A5-45C2-9134-D52272D3DE38}><C:\WINDOWS\system32\rfdswc.dll> []
<{81AF1CF6-D1C9-4C6A-AC01-EDE54E71945B}><C:\WINDOWS\system32\jfdses.dll> []
<{50A8A8C4-EDC9-4ABD-A0A2-2E2418982189}><C:\WINDOWS\system32\kgfghd.dll> []
<{259BF3CF-194D-4FE6-9ADB-DE6544B098B6}><C:\WINDOWS\system32\dndsaf.dll> []
<{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}><C:\WINDOWS\system32\wyrsdj.dll> []
删除服务
[mms-up / mms-up][Stopped/Auto Start]
<C:\DOCUME~1\user\LOCALS~1\Temp\mms.exe -R><(File is missing)>
以下驱动对应文件自己测下
http://www.virscan.org/http://www.virustotal.com/zh-cn/[Sentinel / Sentinel][Running/Auto Start]
<C:\windos\System32\Drivers\SENTINEL.SYS><>
删除浏览器加载项
[]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <, >
[]
{06926B30-424E-4F1C-8EE3-543CD96573DC} <, >
[]
{0A155D3C-68E2-4215-A47A-E800A446447A} <, >
[]
{1E0DFFCF-27FF-4574-849B-55007349FEDA} <, >
[]
{29CF293A-1E7D-4069-9E11-E39698D0AF95} <, >
[]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <, >
[]
{54EBD53A-9BC1-480B-966A-843A333CA162} <, >
[]
{56A7DC70-E102-4408-A34A-AE06FEF01586} <, >
[]
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >
[]
{95B3F550-91C4-4627-BCC4-521288C52977} <, >
[]
{A5366673-E8CA-11D3-9CD9-0090271D075B} <, >
[]
{B580CF65-E151-49C3-B73F-70B13FCA8E86} <, >
[]
{B83FC273-3522-4CC6-92EC-75CC86678DA4} <, >
[]
{C728DAB8-FDF5-4CD7-89DD-879D25794C77} <, >
[]
{D18A0B52-D63C-4ED0-AFC6-C1E3DC1AF43A} <, >
[OfficeObj Class]
{D2BD7935-05FC-11D2-9059-00C04FD7A1BD} <, >
[]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} <, >
]
{FB3412B6-6D67-4650-B3B4-C2A90191A80F} <, >
[]
{FBBCF512-3DD7-4017-9CFA-892761F77751} <, >
[]
{FC87A650-207D-4392-A6A1-82ADBC56FA64} <, >
[]
{FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} <, >