运行SRENG删除启动项注册表:
<ST0RMSetEx><C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system\AV1CAP.dll,Run> [mcsoft]
编辑[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe realshed.exe> [N/A],把explorer.exe后面的REALSHED。EXE删除
删除服务:[Remote Registry Protect / AtWork][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\swoyj.dll><Microsoft Corporation>
[sdhcvs / edfscv][Stopped/Auto Start]
<C:\WINDOWS\system32\fgdfsdf.exe -service><Microsoft Corporation>
[F0FBE0A / F0FBE0A][Stopped/Auto Start]
<C:\WINDOWS\system32\F0FBE0A.EXE -service><Microsoft Corporation>
[Google Updater Service / gusvc][Stopped/Manual Start]这个是GOOGLE,建议也删除了
<"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><N/A>
[HP Status Server / HP Status Server][Stopped/Manual Start]这个请确认下是否是你自己开的
<C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE><Hewlett-Packard Company>
[Pml Driver HPZ12 / Pml Driver HPZ12][Running/Auto Start]
<C:\WINDOWS\system32\HPZipm12.exe><HP>
[Std qspu Service / qspu][Running/Auto Start]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\ikhm\vxuw.dll,Service -s><Microsoft Corporation>
[REM0TE REGISTRY / REM0TEREGISTRY][Running/Auto Start]
<C:\WINDOWS\system\REM0REG.EXE><N/A>
[VRVWatchServer / VRVWatchServer][Running/Auto Start]
<"C:\WINDOWS\system32\WatchClient.exe" -service><N/A>
[Windows Media Connect Service / WMConnectCDS][Stopped/Manual Start]
<C:\Program Files\Windows Media Connect 2\wmccds.exe><Microsoft Corporation>
[fhrpqbu / fhrpqbu][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\COMMON~1\lhrpdbu\lhrpdbu.dll>< >
删除文件;C:\WINDOWS\system\AV1CAP.dll
C:\WINDOWS\system32\swoyj.dll
C:\WINDOWS\system32\fgdfsdf.exe
C:\WINDOWS\system32\F0FBE0A.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\ikhm\删除这个文件夹
C:\WINDOWS\system\REM0REG.EXE
C:\WINDOWS\system32\WatchClient.exe
C:\Program Files\Windows Media Connect 2\wmccds.exe
C:\PROGRA~1\COMMON~1\lhrpdbu\删除这个文件夹
C:\WINDOWS\system32\winlib .dll] [N/A, N/A]
[C:\WINDOWS\system32\bdrrdf.dll] [N/A, N/A]
[C:\WINDOWS\system32\vrvhook.dll
c:\progra~1\common~1\okuszxq\删除这个文件夹
[C:\PROGRA~1\ikhm\vxxs.dll
[C:\PROGRA~1\ikhm\acse.dll
以上请用ICESWORLD在安全模式下强删