用SREng删除
注册表启动项
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<wdfmgr32><C:\WINDOWS\System32\wdfmgr32.exe> []
<RavUpes><C:\WINDOWS\System32\agetltfes.exe> []
<YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> [Yahoo! China]
<yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"> [Yahoo! China]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<9><C:\WINDOWS\System32\vpcrm.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{8A238B14-A6FF-11E0-9A84-00C04FD8DBD8}><C:\WINDOWS\System32\sysldr.dll> []
<{4BAB150F-DD97-476D-9C1E-41B6CDC0CA7A}><C:\PROGRA~1\Yahoo!\ASSIST~1\yclickon.dll> [YAHOO Corporation Limited]
<{E568441B-9EF3-49F8-9A67-4141AC41ADD4}><C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ypatch.dll> [Yahoo! China]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS\DOWNLO~1\CnsHook.dll> []
<{6E44887F-5214-41F2-AB46-4728735C4CC6}><C:\Program Files\Internet Explorer\PLUGINS\system2.sys> []
<{DD7D4640-4464-48C0-82FD-21338366D2D2}><C:\Program Files\Internet Explorer\InfoMs.tdm> []
<{99F1D023-7CEB-4586-80F7-BB1A98DB7602}><C:\Program Files\Internet Explorer\IEXPLORE.Sys> []
<{FEB94F5A-69F3-4645-8C2B-9E71D270AF2E}><C:\Program Files\Internet Explorer\IEXPLORE.Dat> []
显示所有文件后删除:
C:\WINDOWS\System32\wdfmgr32.exe(如果有wdfmgr32.log也删除)
C:\WINDOWS\System32\agetltfes.exe
C:\WINDOWS\System32\vpcrm.exe
C:\WINDOWS\System32\sysldr.dll
C:\WINDOWS\DOWNLO~1\CnsHook.dll
C:\Program Files\Internet Explorer\PLUGINS\system2.sys
C:\Program Files\Internet Explorer\InfoMs.tdm
C:\Program Files\Internet Explorer\IEXPLORE.Sys
C:\Program Files\Internet Explorer\IEXPLORE.Dat
如果删不了下载killbox(地址见反病毒版置顶贴)
清理流氓软件~
把日志贴全.
SREng常用操作说明:
http://forum.ikaka.com/topic.asp?board=67&artid=8125594