C:\WINDOWS\system32\bubbles.scr
C:\windos\System32\BIRD\rr232x.sys
可疑
自己测下
http://www.virscan.org/删除驱动
[49671 / 49671][Running/Manual Start]
<2 - 系统找不到指定的文件。
><N/A>
删除浏览器加载项
[]
{0062C9BD-B349-40DE-91A0-755F37ACD559} <, >
[]
{0062C9BD-B349-40DE-91A0-755F37ACD559} <, >
[WebThunder Class]
{03507A1A-E0C5-4404-AA26-205385C0892D} <, >
[]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <, >
[]
{54EBD53A-9BC1-480B-966A-843A333CA162} <, >
[]
{6096E38F-5AC1-4391-8EC4-75DFA92FB32F} <, >
[]
{6E5EECAF-8879-4A75-8A88-B44B6382A763} <, >
[]
{889D2FEB-5411-4565-8998-1DD2C5261283} <, >
[]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >
[]
{962EFB8E-2683-42D4-AC74-AAA4C759B9C6} <, >
[]
{AA58ED58-01DD-4D91-8333-CF10577473F7} <, >
[]
{C95FE080-8F5D-11D2-A20B-00AA003C157B} <, >
[]
{DEDEB80D-FA35-45D9-9460-4983E5A8AFE6} <, >
[]
{E2E2DD38-D088-4134-82B7-F2BA38496583} <, >
]
{FB5F1910-F110-11D2-BB9E-00C04F795683} <, >