用SREng删除启动项目==>注册表
<myZt2><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Zt2\SVCH0ST.EXE> [N/A]
<myMh2><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mh2\iexpl0re.EXE> [N/A]
<rxzs><C:\WINDOWS\TEMP\rxzs.exe> [N/A]
<{1A404685-7563-4d02-B0F6-58B308A406A9}><e:\rising\rav\rising\rav\vnuncgip.dll> [N/A]
用SREng删除启动项目==>服务==>服务WIN32
[NT Data Provider / BRGNS][Running/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\YTBVT.DLL,Export 1087><N/A>
[Distributed Console Manager / ClipArt][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\zahwv.dll><Microsoft Corporation>
[RpcService / RpcService][Stopped/Auto Start]
<C:\WINDOWS\SYSTEM32\EXPLORE.EXE><Microsoft Corporation>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
用SREng删除启动项目==>服务==>驱动程序
[ahhheeff / ahhheeff][Stopped/Boot Start]
<\SystemRoot\system32\drivers\ahhheeff.sys><N/A>
[f / f][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fxpo><N/A>
[fifeijch / fifeijch][Stopped/Boot Start]
<\SystemRoot\system32\drivers\fifeijch.sys><N/A>
[ladqtqw / ladqtqw][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ladqtqwxts><N/A>
[nwvmtq4 / nwvmtq49][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\nwvmtq49.sys><N/A>
[svwa / svwa][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\svwavkj><N/A>
[ta / ta][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tafbg><N/A>
[vgei / vgei][Stopped/Manual Start]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vgeiujp><N/A>
修复错误的文件关联
重启,安全模式下删除
C:\WINDOWS\TEMP\rxzs.exe
e:\rising\rav\rising\rav\vnuncgip.dll
C:\WINDOWS\SYSTEM32\WBEM\YTBVT.DLL
C:\WINDOWS\system32\zahwv.dll
C:\WINDOWS\SYSTEM32\EXPLORE.EXE
SystemRoot\system32\drivers\ahhheeff.sys
SystemRoot\System32\DRIVERS\nwvmtq49.sys
清空C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp文件夹
C:\WINDOWS\system32\windhcp.ocx已经插入个程序中,很难删除,建议参考http://forum.ikaka.com/topic.asp?board=28&artid=8240356如有问题跟贴说明!!