运行sreng,删除注册表启动项
<Shell.exe><C:\WINDOWS\system32\Shell.exe> [N/A]
cmdbcs><C:\WINDOWS\WINLOGON.EXE> [N/A]
<load><C:\WINDOWS\uninstall\rundl132.exe> [N/A]
<twin><C:\WINDOWS\system32\ctfnom.exe> [Microsoft Corporation
<fysa><; C:\DOCUME~1\窝窝头\LOCALS~1\Temp\fyso.exe> [N/A]
<jtsa><; C:\DOCUME~1\窝窝头\LOCALS~1\Temp\jtso.exe> [N/A]
<Load><; ?粓T
?> [N/A]
mhsa><; C:\DOCUME~1\窝窝头\LOCALS~1\Temp\mhso.exe> [N/A]
<NeroFilterCheck><; C:\WINDOWS\system32\NeroCheck.exe> [Ahead Software Gmbh]
<qjsa><; C:\DOCUME~1\窝窝头\LOCALS~1\Temp\qjso.exe> [N/A]
<rxsa><; C:\DOCUME~1\窝窝头\LOCALS~1\Temp\rxso.exe> [N/A]
<testrun><; C:\DOCUME~1\窝窝头\LOCALS~1\Temp\testexe.exe> [N/A]
<tlsa><; C:\DOCUME~1\窝窝头\LOCALS~1\Temp\tlso.exe> [N/A]
<wdsa><; C:\DOCUME~1\窝窝头\LOCALS~1\Temp\wdso.exe> [N/A]
<wgsa><; C:\DOCUME~1\窝窝头\LOCALS~1\Temp\wgso.exe> [N/A]
<wlsa><; C:\DOCUME~1\窝窝头\LOCALS~1\Temp\wlso.exe> [N/A]
<wmsa><; C:\DOCUME~1\窝窝头\LOCALS~1\Temp\wmso.exe> [N/A]
<wosa><; C:\DOCUME~1\窝窝头\LOCALS~1\Temp\woso.exe> [N/A]
<ztsa><; C:\DOCUME~1\窝窝头\LOCALS~1\Temp\ztso.exe> [N/A]
运行sreng->启动项目 -->服务-->win32服务,删除以下服务(如果删不掉,就设置类型为disabled!)
[WinWMServiceNow / WinWMServiceNow][Stopped/Auto Start]
<C:\DOCUME~1\窝窝头\LOCALS~1\Temp\RAVWM.EXE><N/A>
删除以下文件
C:\WINDOWS\system32\Shell.exe
C:\WINDOWS\system32\ctfnom.exe[看准了,不是ctfmon.exe]
C:\WINDOWS\WINLOGON.EXE
C:\WINDOWS\uninstall\rundl132.exe
清空: C:\DOCUME~1\窝窝头\LOCALS~1\Temp