12   2  /  2  页   跳转

求助!!!

注意:删除病毒可能会具有一定的危险性 所以强烈建议操作前要把重要资料转移至非系统分区!
打开sreng
启动项目 注册表 删除如下项目
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><> [N/A]
<{E418E9ED-9221-4661-B1F3-4AA35BD83832}><C:\Program Files\Internet Explorer\PLUGINS\WinSys88.Sys> []
<{C5E87A05-F463-4841-B19E-DD3EC3862368}><C:\Program Files\Internet Explorer\IEXPLORE32.Sys> []
<{EE12D60D-AD9A-4095-B839-3BE6862679FD}><C:\Program Files\Internet Explorer\IEXPLORE32.Dat> []
<{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}><C:\Program Files\Internet Explorer\IEXPLORE32.win> []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Websv]
<N/A><C:\WINDOWS\web\host32.com> [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<ddvan><; > [N/A]
<helper.dll> C:\PROGRA~1\3721\helper.dll,Rundll32> [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<NWEReboot><; > [N/A]
<oxjsybe><; C:\Program Files\Common Files\Microsoft Shared\eleicnd.exe> [N/A]
<psdoawu><; C:\Program Files\Common Files\System\asgwmne.exe> [N/A]
<yassistse><; "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"> [N/A]
<YLive.exe><; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> [N/A]

用SRENG扫描工具删除以下驱动程序
[167750 / 167750][Stopped/Boot Start]
<\SystemRoot\System32\drivers\167750.sys><N/A>
[CnsMinKP / CnsMinKP][Stopped/Boot Start]
<\SystemRoot\System32\drivers\CnsMinKP.sys><N/A>

重启计算机进入安全模式下删除
[C:\Program Files\Internet Explorer\PLUGINS\WinSys88.Sys] [N/A, ]
[C:\Program Files\Internet Explorer\IEXPLORE32.Sys] [N/A, ]
[C:\Program Files\Internet Explorer\IEXPLORE32.Dat] [N/A, ]
[C:\Program Files\Internet Explorer\IEXPLORE32.win] [N/A, ]
<N/A><C:\WINDOWS\web\host32.com> [N/A]
<helper.dll> C:\PROGRA~1\3721\helper.dll,Rundll32> [N/A]
[D:\Program Files\AutoCAD 2006\wefsd.dll] [N/A, ]
<oxjsybe><; C:\Program Files\Common Files\Microsoft Shared\eleicnd.exe> [N/A]
<psdoawu><; C:\Program Files\Common Files\System\asgwmne.exe> [N/A]
<yassistse><; "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"> [N/A]
<YLive.exe><; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> [N/A]
<\SystemRoot\System32\drivers\167750.sys><N/A>
<\SystemRoot\System32\drivers\CnsMinKP.sys><N/A>
gototop
 

多谢了啊
我按你说的,删掉那些东西之后,真的好了啊
好佩服你们这些高手
谢谢
gototop
 

该用户帖子内容已被屏蔽
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT