删除注册表中
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><kvmxema.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{A158698F-435B-CD34-FA34-59875412025A}><\\.\c:\com1\com1.dll> []
<{39659854-7415-1025-5982-789541250193}><C:\WINDOWS\system32\SysWln74_3.dll> [N/A]
<{4E32FA58-3453-FA2D-BC49-F340348ACCE4}><C:\WINDOWS\system32\rsmydpm.dll> [N/A]
删除文件
C:\WINDOWS\system32\SysWln74_3.dll
C:\WINDOWS\system32\rsmydpm.dll