开始-附件-启动里的全删除
建议用SRENG删除以下启动项:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<stup.exe><C:\PROGRAM FLIES\TENCENT\Adplus\stup.exe> [Tencent]
<Knight V><> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{5D06580A-08EB-4DD0-8425-DDBB5198B30C}><C:\Program Files\Common Files\Microsoft Shared\MSInfo\IEINFO5.sys> [N/A]
<{A771A1EC-975E-4718-AF5E-A3F552D45C41}><C:\WINDOWS\system32\msipri.dll> [N/A]
以下文件压缩发上来鉴定,情况比较复杂,伪装的签名多C:\PROGRAM FLIES\TENCENT\Adplus\stup.exe
C:\PROGRAM FILES\RISING\RAV\HookApi.Sys
C:\Program Files\Rising\Rav\HOOKCONT.sys
C:\Program Files\Rising\Rav\HookReg.sys
C:\Program Files\Rising\Rav\HookSys.sys
C:\Program Files\Rising\Rav\HookCont.dll
C:\Program Files\Rising\Rav\SpamEng.dll
C:\Program Files\Rising\Rav\RsVM.dll
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Internet Explorer\Connection Wizard\isignup.sys
C:\Program Files\TENCENT\Adplus\Adplus.dll
C:\WINDOWS\system32\msdmo.dll
C:\Program Files\WinRAR\rarext.dll
C:\WINDOWS\system32\msipri.dll
c:\program files\rising\rfw\MonDrv.dll
C:\Program Files\Rising\Rav\RsCommX.dll