楼主的日志贴得极有个性,一气呵成,不过没贴全
再补充(上面二位的具体操作):
运行sreng,删除启动--注册表项:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ravtask><C:\Progra~1\Eset\rund1132.exe> [N/A]
<szdtfzs><C:\WINDOWS\iexpl0re.exe> [N/A]
<giz><C:\WINDOWS\winlog0n.exe> [N/A]
<svc><C:\DOCUME~1\gaojie\LOCALS~1\Temp\logsony.exe> [N/A]
<25mjk9><C:\WINDOWS\system.exe> [N/A]
<hhzey><C:\WINDOWS\iexp1ore.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<upxdn><C:\DOCUME~1\gaojie\LOCALS~1\Temp\upxdn.exe> [N/A]
<upxse><C:\DOCUME~1\gaojie\LOCALS~1\Temp\1.exe> [N/A]
<sye><C:\WINDOWS\sye.exe> [N/A]
<NopHelp><C:\DOCUME~1\gaojie\LOCALS~1\Temp\7577my.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<twin><C:\WINDOWS\system32\twunk32.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{3A00B453-B453-A002-53A0-45300453A002}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\B453A002.dll> [N/A]
<{2D49692C-A5FD-4E29-A3CD-37E9B182FCC6}><C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys> [N/A]
删除启动--服务项:
[49CD654E / 49CD654E][Stopped/Auto Start]
<C:\WINDOWS\system32\49CD654E.EXE -service><Microsoft Corporation>
[Updata Server / Updata Server][Stopped/Auto Start]
<C:\Program Files\Common Files\Updater><N/A>
[Win32 Display Driver / Win32DDS][Stopped/Auto Start]
<C:\WINDOWS\system32\\rundll32.exe windds32.dll,input><Microsoft Corporation>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\\rundll32.exe windhcp.ocx,input><Microsoft Corporation>
[WinXP DHCP Service / WinXPDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\\rundll32.exe xpdhcp.dll,input><Microsoft Corporation>
删除启动--服务--驱动:
[00 / 00][Stopped/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\159289.sys><N/A>
[2440439 / 2440439][Running/Boot Start]
<\SystemRoot\System32\drivers\2440439.sys><N/A>
[a0 / a0][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\2440439.sys><N/A>
[ggttufkv / ggttufkv][Running/Manual Start]
<2 - 系统找不到指定的文件。
><N/A>
安全模式下,删除(可借助killbox):
C:\DOCUME~1\gaojie\LOCALS~1\Temp没装其他东东的话,清空这个文件夹
C:\WINDOWS\system32\sye.dll
C:\Progra~1\Eset\rund1132.exe
C:\WINDOWS\iexpl0re.exe
C:\WINDOWS\winlog0n.exe
C:\WINDOWS\system.exe
C:\WINDOWS\iexp1ore.exe
C:\WINDOWS\sye.exe
C:\WINDOWS\system32\twunk32.exe
C:\Program Files\Common Files\Microsoft Shared\MSINFO\B453A002.dll
C:\Program Files\Internet Explorer\PLUGINS\SystemKb.sys
<C:\WINDOWS\system32\49CD654E.EXE
C:\WINDOWS\system32\windds32.dll
C:\WINDOWS\system32\windhcp.ocx
C:\WINDOWS\system32\xpdhcp.dll
C:\WINDOWS\System32\drivers\159289.sys
C:\WINDOWS\System32\drivers\2440439.sys
C:\WINDOWS\System32\drivers\2440439.sys
卸载QQ,清理注册表,重新安装QQ
清理流氓软件
操作结束后,重新扫日志贴上来