用sreng
删除启动项目=>服务
[BFF89E7E / BFF89E7E][Stopped/Auto Start]
<><N/A>
[Remote Debug Service / RemoteDbg][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe RemoteDbg.dll,input><Microsoft Corporation>
[Win32 Display Driver / Win32DDS][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe windds32.dll,input><Microsoft Corporation>
[WMI Performance API / WMIApiSrv][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe WMIApiSrv.dll,input><Microsoft Corporation>
[Wireless Service / WZCSRVC][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe netsrvcs.dll,input><Microsoft Corporation>
删除启动项目=>服务=>驱动
[8xt / 8xt7][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\8xt7.sys><N/A>
启动项目=>注册表
<AppInit_DLLs> 编辑为 空值
重启,删除文件
C:\WINDOWS\system32\jhapri.dll
C:\WINDOWS\system32\RemoteDbg.dll
C:\WINDOWS\system32\windds32.dll
C:\WINDOWS\system32\WMIApiSrv.dll
C:\WINDOWS\system32\netsrvcs.dll
C:\WINDOWS\System32\DRIVERS\8xt7.sys