除了2、3楼说的以外
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<msnmsg><C:\Program Files\Messenger\msgmr.dll> [Microsoft Corporation]
个人认为这项也有问题,伪装签名
建议用Xdelbox删除,可以先根据路径C:\Program Files\Messenger\msgmr.dll上传到
http://www.virscan.org/验证一下
还有一个可疑驱动
[NetworkX / NetworkX][Running/System Start]
<\SystemRoot\system32\ckldrv.sys><N/A>
按照这个路径c:\windows\sysytem3ckldrv.sys也上传扫描一下,有问题就按楼上说的删除
下面的浏览器加载项用sreng删除
系统修复--浏览器加载项
[]
{0A155D3C-68E2-4215-A47A-E800A446447A} <, >
[]
{461CC20B-FB6E-4F16-8FE8-C29359DB100E} <, >
[]
{4eb89ff4-7f78-4a0f-8b8d-2bf02e94e4b2} <, >
[]
{4EDCB26C-D24C-4e72-AF07-B576699AC0DE} <, >
[]
{7390f3d8-0439-4c05-91e3-cf5cb290c3d0} <, >
[]
{7584c670-2274-4efb-b00b-d6aaba6d3850} <, >
[]
{9059f30f-4eb1-4bd2-9fdc-36f43a218f4a} <, >
[]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >
[]
{95B3F550-91C4-4627-BCC4-521288C52977} <, >
[]
{97421D0D-E07F-40DF-8F07-99597B9585AD} <, >
[]
{D6E814A0-E0C5-11D4-8D29-0050BA6940E3} <, >
[]
{FB5F1910-F110-11D2-BB9E-00C04F795683} <, >