注册表启动项
<TIMHost><C:\WINDOWS\TIMHost.exe> []
<RAV00AE><C:\WINDOWS\system32\RAV00AE.exe> []
<Microsoft Autorun9><C:\WINDOWS\system32\Ravasktao.exe> []
<Microsoft Autorun5><C:\WINDOWS\system32\mosou.exe> []
<Soltek><C:\WINDOWS\system32\autorun.exe> []
<{90BC520C-9175-470E-94B8-10FD869D170B}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.yer> []
<{754FB7D8-B8FE-4810-B363-A788CD060F1F}><C:\Program Files\Internet Explorer\PLUGINS\System64.Sys> []
<{88A46432-969E-4F5E-913D-3AAF4B6A3051}><C:\WINDOWS\system32\SvTime.dll> []
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
<N/A><C:\WINDOWS\system32\nwizzhuxians.exe> []
服务
[Remote Debug Service / RemoteDbg][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe RemoteDbg.dll,input><Microsoft Corporation>
[Windows Driver Foundation - User-mode Driver Framework / WudfSvc][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup-->%SystemRoot%\System32\WUDFSvc.dll><Microsoft Corporation>
重启删除
[C:\WINDOWS\system32\hjtdx.dll] [N/A, ]
[C:\WINDOWS\system32\whgdm.dll] [N/A, ]
[C:\WINDOWS\system32\wgfdl.dll] [N/A, ]
[C:\WINDOWS\system32\GetsFile.dll] [N/A, ]
[C:\WINDOWS\system32\zerwx.dll] [N/A, ]
[C:\WINDOWS\system32\wkufd.dll] [N/A, ]
[C:\WINDOWS\system32\wkjbj.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\System64.Sys] [N/A, ]
[C:\WINDOWS\system32\RemoteDbg.dll] [N/A, ]
怀疑
[C:\WINDOWS\system32\msapi.dll] [N/A, ]
删除D盘的Autorun.inf