修改注册表键值
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<SystemCheck><%SystemRoot%\system32\syschk.exe> [File is missing]
为<>
删除启动项
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]下注册表项目及<>内DLL文件
<rasdlgcq.dll><C:\WINDOWS\system32\rasdlgcq.dll> [File is missing]
<cryptuiwlqx.dll><C:\WINDOWS\system32\cryptuiwlqx.dll> [File is missing]
<slbiopfs2.dll><C:\WINDOWS\system32\slbiopfs2.dll> [File is missing]
删除服务及对应文件
[Nandra / Nandra][Stopped/Auto Start]
<C:\WINDOWS\system32\Nandra.com -service><(File is missing)>
可疑文件,自己测
http://www.virscan.org/http://www.virustotal.com/zh-cn/C:\WINDOWS\secsvr.exe
C:\WINDOWS\usblogon.exe
C:\WINDOWS\secsvr.exe