运行SREng2,使用“启动项目”--注册表--删除
C:\DOCUME~1\FAFA\LOCALS~1\Temp\Rxa3\iexp1ore.exe
><C:\WINDOWS\system32\expiorer.exe
C:\Program Files\Microsoft\svhost32.exe
C:\Program Files\Common Files\Microsoft Shared\MSINFO\LSASS.EXE
:\Program Files\Common Files\Microsoft Shared\MSINFO\WinInfo.rxk
C:\DOCUME~1\FAFA\LOCALS~1\Temp\services.exe
C:\DOCUME~1\FAFA\LOCALS~1\Temp\conime.exe
C:\DOCUME~1\FAFA\LOCALS~1\Temp\mhs2.exe
重启按F8进入安全模式下
显示隐藏文件
删除:
C:\DOCUME~1\FAFA\LOCALS~1\Temp\清空文件夹
><C:\WINDOWS\system32\expiorer.exe
C:\Program Files\Microsoft\svhost32.exe
C:\Program Files\Common Files\Microsoft Shared\MSINFO\LSASS.EXE
:\Program Files\Common Files\Microsoft Shared\MSINFO\WinInfo.rxk
C:\WINDOWS\system32\dms.dll
C:\WINDOWS\system32\twunk32.exe
参考
http://forum.ikaka.com/topic.asp?board=28&artid=8237996