启动项目 注册表 删除如下项目
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><ratbhpi.dll> []清空此项
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{B158698F-435B-CD34-FA34-59875412025B}><\\.\c:\com1\com2.dll> []
<{A158698F-435B-CD34-FA34-59875412025A}><\\.\c:\com1\com1.dll> []
<{86650011-3344-6688-4899-345FABCD1568}><C:\WINDOWS\system32\ratbhpi.dll> []
<{8C87A354-ABC3-DEDE-FF33-3213FD7447C8}><C:\WINDOWS\system32\kvdxhma.dll> []
重启计算机进入安全模式下删除
<{B158698F-435B-CD34-FA34-59875412025B}><\\.\c:\com1\com2.dll> []
<{A158698F-435B-CD34-FA34-59875412025A}><\\.\c:\com1\com1.dll> []
<{86650011-3344-6688-4899-345FABCD1568}><C:\WINDOWS\system32\ratbhpi.dll> []
<{8C87A354-ABC3-DEDE-FF33-3213FD7447C8}><C:\WINDOWS\system32\kvdxhma.dll> []