删除注册表启动项
<IE Helper><C:\DOCUME~1\centro\LOCALS~1\Temp\iexplore0.exe> [N/A]
<teelckk><C:\Program Files\Messenger\teelckk.exe> []
删除服务
[Windows rvgj RunThem / rvgj][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\mqbe\walo.dll>< >
[Local Connection Manager / SoSCAR][Running/Auto Start]
<C:\WINDOWS\SYSTEM32\RUNDLLFOROUR.EXE C:\WINDOWS\SYSTEM32\WBEM\DPZTY.DLL,Export 1087><Microsoft Corporation>
[WebPrint / WebPrint][Stopped/Auto Start]
<c:\windows\system32\webprint.exe><Microsoft Corporation>
删除驱动
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\drivers\npf.sys><CACE Technologies>
[anxh / anxhy][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\anxhy.sys><N/A>
[DCALEXICO / DCALEXICO][Stopped/Manual Start]
<system32\drivers\DCalexico.sys><N/A>
[fdjccijj / fdjccijj][Stopped/Boot Start]
<\SystemRoot\system32\drivers\fdjccijj.sys><N/A> 这几个可疑 网上搜不到
这两个
[c:\progra~1\mqbe\zdor.dll] [, 5, 0, 0, 4]
[c:\progra~1\mqbe\eitw.dll] [ , 5, 0, 0, 4]
狂插进程 不是什么好东西
还有
c:\windows\system32\nkedo.dll
c:\windows\system32\webpnt.exe
这两个也删除
修复文件关联