运行sreng,删除启动--注册表项
<ravshell><C:\WINDOWS\rund1132.exe> [N/A]
<msccr><C:\WINDOWS\msccr.exe> [N/A]
<cmdbcs><C:\WINDOWS\cmdbcs.exe> [N/A]
<wsttrs><C:\WINDOWS\wsttrs.exe> [N/A]
<upxdn><C:\DOCUME~1\admin\LOCALS~1\Temp\TIMPLATF0RM.exe> [N/A]
<mhs3><C:\WINDOWS\mhs3.exe> [N/A]
<wsttr><C:\WINDOWS\wsttr.exe> [N/A]
结束进程 删除
[C:\DOCUME~1\admin\LOCALS~1\Temp\mhs0.dll] [N/A, N/A]
[PID: 1216][C:\WINDOWS\mhs3.exe] [N/A, N/A]
[C:\DOCUME~1\admin\LOCALS~1\Temp\mhs0.dll] [N/A, N/A]
[C:\DOCUME~1\admin\LOCALS~1\Temp\mhs0.dll] [N/A, N/A]
重起 安全模式下杀毒