运行System Repair Engineer 注册表服务,删除
<kavshell><C:\Progra~1\Eset\svch0st.exe> [N/A]
<66><C:\SysDayN6\svchost.exe> []
<333><C:\Syswm1h\svchost.exe> []
<50><C:\SysAd5D\svchost.exe> []
<4><C:\SysWsj6\svchost.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<yupxdnd><C:\DOCUME~1\new\LOCALS~1\Temp\yupxdnd.exe> [N/A]
<upxdnd><C:\DOCUME~1\new\LOCALS~1\Temp\upxdnd.exe> []
<nwiz><; nwiz.exe /install> []
重起,安全模式,查看,显示所有文件夹,把"隐藏受保护的系统文件"的勾去掉,删除
[C:\WINDOWS\system32\nvshell.dll] [, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\WINDOWS\system32\msdmo.dll]
[C:\SysDayN6\Ghook.dll] [N/A, ]
[C:\SysAd5D\Ghook.dll] [N/A, ]
[C:\Syswm1h\Ghook.dll] [N/A, ]
[C:\SysWsj6\Ghook.dll] [N/A, ]
清空临时文件夹
C:\DOCUME~1\new\LOCALS~1\Temp