先删除以下启动项目(删除启动,并在注册表里删除键值),然后按路径干掉文件
<vtupdate><C:\WINDOWS\> [N/A]
<Cmaudio><; RunDll32 cmicnfg.cpl,CMICtrlWnd> [N/A]
<wdfmgr32><C:\WINDOWS\system32\wdfmgr32.exe> []
<xvtaaf00><%systemroot%\system32\Rundll32.exe "%systemroot%\system32\xvtaaf00.dll",Start> [N/A]
<eapjwx82><%systemroot%\system32\Rundll32.exe "%systemroot%\system32\eapjwx82.dll",Start> [N/A]
<IMSCMig><; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<SiS KHooker><; C:\WINDOWS\system32\khooker.exe> [N/A]
<SiS Tray><; > [N/A]
<yokUninstall><cmd /c rd /s /q C:\PROGRA~1\yok> []
<{320D6AA0-A6FF-11E0-9A84-00C04FD8DBD8}><C:\WINDOWS\system32\H20D6AA0.log> [N/A]
以下服务拿不准,如果不是声卡显卡打印机,估计是病毒
[Remote Registry Protect / Framework][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\okpvt.dll><N/A>
[Movie of any portable media player / Movie of any portable media player][Stopped/Auto Start]
<C:\WINDOWS\system32\moviemk.exe><N/A>
[Local Connection Manager / NHLscA][Running/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLL2000.EXE C:\WINDOWS\SYSTEM32\WBEM\YWYDO.DLL,Export 1087><Microsoft Corporation>
[Number of any portable media. / Number of any portable media.][Stopped/Auto Start]
<C:\WINDOWS\system32\command.com><N/A>