删除注册表
<HBService><HBInject.exe> [N/A]
<{71A78CD4-E470-4a18-8457-E0E0283DD507}><C:\WINDOWS\system32\lweurqhx.dll> []
<{7A6DF30E-D0F2-446f-B4F0-BF4232D60E07}><C:\WINDOWS\system32\cliconfgzx.dll> []
<{6B9FEAD7-4319-4312-AB05-D8C9CD255BFE}><C:\WINDOWS\system32\avicapwm.dll> [N/A]
<{21BE5FDF-D4CB-4850-AD99-21E68B50BF3F}><C:\WINDOWS\system32\exbbhlvv.dll> []
<{841529CB-7F77-4B99-A895-B5441E0D302F}><C:\WINDOWS\system32\jfrwdh.dll> [N/A]
<{76D44356-B494-443a-BEDC-AA68DE4255E6}><C:\WINDOWS\system32\dispexcb.dll> []
<{9E8287B0-0F3A-48ae-99C5-A6E0AAC36BC5}><C:\WINDOWS\system32\certmgrkd.dll> []
<{D47A61B8-0EAB-417F-8DF4-5C949982A2AF}><C:\Program Files\Internet Explorer\PLUGINS\Windows64.Sys> []
<{28766E1C-74B0-4417-8C75-F12AE309EF35}><C:\WINDOWS\system32\wzcfsw.dll> []
<{5E907A48-400E-4EA8-9792-FFAE052D59E9}><C:\WINDOWS\system32\pedadt.dll> [N/A]
<{0B846B26-BFE6-4E8E-A948-1DB17B77B483}><C:\WINDOWS\system32\tdfhex.dll> [N/A]
<HBService><; HBInject.exe> [N/A]
<UserFaultCheck><; %systemroot%\system32\dumprep 0 -u> [N/A]
<WinampAgent><; d:\Winamp\winampa.exe> []
<YLive.exe><; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> [N/A]
删除服務
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\lgap\vqkz.dll
C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\Program Files\iesnap\navoct.dll
有問題的驅動
[Apaidi / Apaidi][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\Apaidi.sys><N/A>
[aslm75 / aslm75][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\aslm75.sys><N/A>
[d344bus / d344bus][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\d344bus.sys><>
[d344prt / d344prt][Running/Boot Start]
<\SystemRoot\System32\Drivers\d344prt.sys><>
[ferdr / ferdr][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\Ferdr.sys><N/A>
[HBKernel Driver / HBKernel][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\HBKernel.sys><N/A>
[ids00026 / ids00026][Stopped/Manual Start]
<\??\C:\Documents and Settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids00026.sys><N/A>
[ids0005c / ids0005c][Stopped/Manual Start]
<\??\C:\Documents and Settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids0005c.sys><N/A>
[kmsinput / kmsinput][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\kmsinput.sys><N/A>
[MyFSD / MyFSD][Stopped/Manual Start]
<\??\C:\Documents and Settings\pengwenlisust\Application Data\vosClient\myfsd.sys><N/A>
[npkcrypt / npkcrypt][Stopped/Auto Start]
<\??\D:\Tencent\qq\npkcrypt.sys><N/A>
[PCAMp50 NDIS Protocol Driver / PCAMp50][Stopped/Manual Start]
<System32\Drivers\PCAMp50.sys><N/A>
[PCASp50 NDIS Protocol Driver / PCASp50][Stopped/Manual Start]
<System32\Drivers\PCASp50.sys><N/A>
删除進程
[C:\WINDOWS\system32\HBmhly.dll] [N/A, ]
[C:\WINDOWS\system32\AcSignIcon.dll] [Autodesk, 16.2.54.0]
[C:\WINDOWS\system32\lweurqhx.dll] [N/A, ]
[C:\WINDOWS\system32\cliconfgzx.dll] [N/A, ]
[C:\WINDOWS\system32\exbbhlvv.dll] [N/A, ]
[C:\WINDOWS\system32\dispexcb.dll] [N/A, ]
[C:\WINDOWS\system32\certmgrkd.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\Windows64.Sys] [N/A, ]
[C:\WINDOWS\system32\wzcfsw.dll] [N/A, ]
[C:\WINDOWS\system32\iuzvqmnwf.dll] [N/A, ]