运行SRENG 启动项 注册表
删除
systme32.exe><C:\WINDOWS\System32\systme32.exe> [N/A]
<System><C:\Program Files\Common Files\System\Update.exe> [N/A]
<{08315C1A-9BA9-4B7C-A432-26885F78DF28}><> [N/A]
<{729B6C61-BDC5-4C09-A1DE-A296BA0B89EC}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp
<{1A404685-7563-4d02-B0F6-58B308A406A9}><c:\program files\rising\rfw\uqrtoonp.dll> [N/A]
Torjan Program><C:\WINDOWS\SERVICES.EXE> [China]
-----------
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe 1> [N/A
这个尝试编辑下,把后面的1去掉看看
----------------------
RestoreService / RestoreService]
<C:\WINDOWS\System32\Svchost.exe -k RestoreService-->C:\WINDOWS\System32\drivers\service.dll><N/A>
WINIO / WINIO]
<\??\C:\WINDOWS\Downloaded Program Files\winio.sys><
运行SRENG 启动 服务 隐藏已认证的微软服务 选中该服务 设置点否删除
重起后删除 C:\WINDOWS\System32\drivers\service.dll
C:\WINDOWS\Downloaded Program Files\winio.sys
删除c:\windows\system32\drivers\service.dll] [N/A, N/A]
[c:\windows\system32\drivers\ms_restore.dll] [Microsoft Corporation All rights reserved, 1, 0, 0, 1]
[c:\windows\system32\drivers\Old_service.dll
C:\WINDOWS\SERVICES.EXE
c:\program files\rising\rfw\uqrtoonp.dll
C:\WINDOWS\System32\systme32.exe
C:\Program Files\Common Files\System\Update.exe
C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp