http://bbs.ikaka.com/showtopic-8565484.aspx参看天月版主关于木马群的处理
清除下面的
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<nwiz><aliba32.exe> []
C:\WINDOWS\system32\userinit.exe这个文件被替换了
下面的值编辑惟空
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs
清楚下面的
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{5934EA2B-B2C4-4BE7-BF7A-FBA781A12E40}><5934EA2B.dll> []
<{B6E23E89-C925-4BF7-92EB-77EFDF8C58A6}><B6E23E89.dll> []
<{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}><08223B03.dll> []
<{D7C79813-9233-4AE0-832C-99B2E8019673}><D7C79813.dll> []
<{2EF0D734-21FD-4225-A1A2-BCD296182AAF}><2EF0D734.dll> []
<{93DEE065-EC9B-4505-ADD3-19880AD3C38F}><93DEE065.dll> []
<{56BC86C7-0692-4F94-A2C1-6CF1DBF8096C}><56BC86C7.dll> []
<{DFB3DAC5-B0B5-4B05-BFCF-FB42737778FA}><DFB3DAC5.dll> []
<{D9C002DD-EA51-43A2-9009-54EAAAF031A4}><D9C002DD.dll> []
<{4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96}><4FBFD5A4.dll> []
<{4D023DE9-F4B5-4BE0-99C6-7C7AD0CF5426}><4D023DE9.dll> []
<{DA63E650-537C-4042-87BB-9D19D844680B}><DA63E650.dll> []
<{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}><122B901E.dll> []
<{201476D0-2B18-462E-AB9F-3E2B0CC8732B}><201476D0.dll> []
<{E783C505-FA27-48BD-9B35-C84E5CEA523F}><E783C505.dll> []
<{755D0ED0-3996-4ADB-9B1F-AD8F0E9E4738}><755D0ED0.dll> []
一下驱动都清除
C:\WINDOWS\system32\b1a18a3e.sys
C:\WINDOWS\system32\b71fe93.sys
C:\WINDOWS\system32\b770ca2.sys
C:\WINDOWS\system32\f28907d.sys
SystemRoot\system32\drivers\HBKernel32.sys
<\??\C:\WINDOWS\system32\Nskhelper2.sys><N/A>
<\??\C:\WINDOWS\system32\NsPass0.sys><N/A>
<\??\C:\WINDOWS\system32\NsPass1.sys><N/A>
<\??\C:\WINDOWS\system32\NsPass2.sys><N/A>
<\??\C:\WINDOWS\system32\NsPass3.sys><N/A>
<\??\C:\WINDOWS\system32\NsPass4.sys><N/A>
C:\WINDOWS\system32\Drivers\SUPERNT.SYS
上边我写的东西不全,先参看那个帖子,
然后可以把我写的能找到的删除