你先用安全卫士删除一下吧!我试了可以清除!手工清除比较困难一些!到注册表找到HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run启动项,果然看到一字符串desktop,其值为“C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",Run”及:
KCR\bho.IEMonitor.1 KCR\bho.IEMonitor.1 [Default]: (IEMonitor Class)
KCR\bho.IEMonitor.1\CLSID KCR\bho.IEMonitor.1\CLSID [Default]: ({08A312BB-5409-49FC-9347-54BB7D069AC6})
KCR\bho.IEMonitor KCR\bho.IEMonitor [Default]: (IEMonitor Class)
KCR\bho.IEMonitor\CLSID KCR\bho.IEMonitor\CLSID [Default]: ({08A312BB-5409-49FC-9347-54BB7D069AC6})
KCR\bho.IEMonitor\CurVer KCR\bho.IEMonitor\CurVer [Default]: (bho.IEMonitor.1)
KCR\CLSID\{08A312BB-5409-49FC-9347-54BB7D069AC6} KCR\CLSID\{08A312BB-5409-49FC-9347-54BB7D069AC6} [Default]: (IEMonitor Class)
HKCR\CLSID\{08A312BB-5409-49FC-9347-54BB7D069AC6}\InprocServer32 [Default]: (C:\WINDOWS\system32\deskipn.dll)
HKCR\CLSID\{08A312BB-5409-49FC-9347-54BB7D069AC6}\InprocServer32 [ThreadingModel]: (Apartment)
HKCR\CLSID\{08A312BB-5409-49FC-9347-54BB7D069AC6}\ProgID HKCR\CLSID\{08A312BB-5409-49FC-9347-54BB7D069AC6}\ProgID [Default]: (bho.IEMonitor.1)
HKCR\CLSID\{08A312BB-5409-49FC-9347-54BB7D069AC6}\Programmable HKCR\CLSID\{08A312BB-5409-49FC-9347-54BB7D069AC6}\TypeLib HKCR\CLSID\{08A312BB-5409-49FC-9347-54BB7D069AC6}\TypeLib [Default]: ({647BB013-E900-473E-BC10-99CF3AC365AD})
HKCR\CLSID\{08A312BB-5409-49FC-9347-54BB7D069AC6}\VersionIndependentProgID HKCR\CLSID\{08A312BB-5409-49FC-9347-54BB7D069AC6}\VersionIndependentProgID [Default]: (bho.IEMonitor)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [desktop]: ("C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTService32.dll",HKCU\Software\DeskAdTop HKCU\Software\DeskAdTop [MsRouteVer]: (1.0.1.3)
HKCU\Software\DeskAdTop [TM]: (1164601948)
HKLM\SYSTEM\CurrentControlSet\Services\Windows NT Service32 HKLM\SYSTEM\CurrentControlSet\Services\Windows NT Service32 [Type]: (16)
HKLM\SYSTEM\CurrentControlSet\Services\Windows NT Service32 [Start]: (2)
HKLM\SYSTEM\CurrentControlSet\Services\Windows NT Service32 [ErrorControl]: (1)
HKLM\SYSTEM\CurrentControlSet\Services\Windows NT Service32 [ImagePath]: ("C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\NTServ HKLM\SYSTEM\CurrentControlSet\Services\Windows NT Service32 [DisplayName]: (Windows NT Service32)
HKLM\SYSTEM\CurrentControlSet\Services\Windows NT Service32 [
ObjectName]: (LocalSystem)
HKLM\SYSTEM\CurrentControlSet\Services\Windows NT Service32 [Description]: (Windows NT service for Windows NT/XP/2003 system)
HKLM\SYSTEM\CurrentControlSet\Services\Windows NT Service32\Security HKLM\SYSTEM\CurrentControlSet\Services\Windows NT Service32\Enum HHKLM\SYSTEM\CurrentControlSet\Services\Windows NT Service32\Enum [0]: (Root\LEGACY_WINDOWS_NT_SERVICE32\0000)
HKLM\SYSTEM\CurrentControlSet\Services\Windows NT Service32\Enum [Count]: (1)
HKLM\SYSTEM\CurrentControlSet\Services\Windows NT Service32\Enum [NextInstance]:
仅供参考!