删除服务
[4CCFD7B4 / 4CCFD7B4][Stopped/Auto Start]
<C:\WINDOWS\system32\4CCFD7B4.EXE -service><Microsoft Corporation>
[error monitor / EmonSrv][Stopped/Auto Start]
<><N/A>
[kkdj3sdf3 / kkdj3sdf3][Stopped/Auto Start]
<C:\WINDOWS\system32\kkdj3sdf3.exe -j><Microsoft Corporation>
[Windows powr RunThem / powr][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\hgrj\utbw.dll>< >
删除驱动
[hbfeskxq / hbfeskxq][Running/Boot Start]
<\SystemRoot\system32\drivers\hbfeskxq.sys><N/A>
[jepxzv4 / jepxzv40][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\jepxzv40.sys><Microsoft Corporation>
[kobhlu9 / kobhlu96][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\kobhlu96.sys><N/A>
[loqgny9 / loqgny90][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\loqgny90.sys><N/A>
[qvvyis4 / qvvyis47][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\qvvyis47.sys><N/A>
[hcxytb90 / hcxytb90][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\hcxytb90.sys><Microsoft Corporation>
清除浏览加载
[ExtentIE Class]
{66C2C482-D4EE-42A5-AEF7-0B124F278D47} <C:\WINDOWS\system32\648a.dll, TODO: <公司名>>
结束进程
[PID: 224][C:\WINDOWS\system32\dgd4bs.exe] [N/A, ]
先备份\SystemRoot\System32\DRIVERS\jepxzv40.sys(事后没异常再删除)
删除上面提及的文件,再删除文件
[C:\WINDOWS\system32\kkdj3sdf3.dll
[C:\WINDOWS\system32\qvvyis47.dll
C:\WINDOWS\system32\hcxytb90.dll