使用SRENG删除注册表项目
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<DbgHlp32><C:\WINDOWS\DbgHlp32.exe> []
<ravztmon><C:\Program Files\NetMeeting\ravztmon.exe> []
<DiskMan32><C:\WINDOWS\DiskMan32.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<visin><C:\WINDOWS\system32\visin.exe> [Microsoft Corporation]
删除驱动程序
[abp480n5 / abp480n5][Stopped/Boot Start]
<\SystemRoot\system32\DRIVERS\ABP480N5.SYS><Microsoft Corporation>
[CdnHook / CdnHook][Running/System Start]
<System32\drivers\cdnhook.sys><N/A>(可疑驱动,先不处理)
下载arswp(Windows清理助手)清理下..
http://www.arswp.com/download/arswp/arswp.rar
重起,进入安全模式(开机按F8)
删除文件,能找到什么删什么
C:\WINDOWS\System32\nsp.dll
C:\WINDOWS\SYSTEM32\AVWLAST.EXE
C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
C:\WINDOWS\DbgHlp32.exe
C:\Program Files\NetMeeting\ravztmon.exe
C:\Program Files\NetMeeting\ravztmon.dat
C:\WINDOWS\DiskMan32.exe
C:\WINDOWS\system32\visin.exe
C:\Program Files\Common Files\SyInfo.bps
C:\WINDOWS\system32\avzxamn.dll
C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys
C:\WINDOWS\system32\avwlamn.dll
再用SRENG删除注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{72204F90-5CD6-41B1-BD69-62CD84C9FB24}><C:\Program Files\Common Files\SyInfo.bps> []
<{1859245F-345D-BC13-AC4F-145D47DA34F1}><C:\WINDOWS\system32\avzxamn.dll> [N/A]
<{5D83AD9C-3BFC-43F5-979D-2904DBC54A8E}><C:\Program Files\Internet Explorer\PLUGINS\WinSys64.Sys> [N/A]
<{1960356A-458E-DE24-BD50-268F589A56A1}><C:\WINDOWS\system32\avwlamn.dll> [N/A]
最后全盘杀毒