删除以下启动项
<Kvsc3><; C:\WINDOWS\Kvsc3.exE> [N/A]
<LotusHlp><; C:\WINDOWS\LotusHlp.exe> [N/A]
<MsIMMs32><; C:\WINDOWS\MsIMMs32.exE> [N/A]
<MsPrint32D><; C:\WINDOWS\MsPrint32D.exe> [N/A]
<spoolsv><; C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer> [N/A]
<SysExplr><; C:\Program Files\SuperPlayer3500\SysExplr.exe> []
<WinSysM><; C:\WINDOWS\338448M.exe> [N/A]
<WinSysW><; C:\WINDOWS\338448L.exe> [N/A]
<WSockx2_32><; C:\WINDOWS\WSockx2_32.exe> [N/A]
以下为IFEO劫持,可用autoruns修复
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavsvc.exe]
<IFEO[kavsvc.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVsvcUI.exe]
<IFEO[KAVsvcUI.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVFW.EXE.exe]
<IFEO[KVFW.EXE.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP.exe]
<IFEO[KVMonXP.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapsvc.exe]
<IFEO[navapsvc.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ravtimer.exe]
<IFEO[ravtimer.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rising.exe]
<IFEO[rising.exe]><C:\WINDOWS\system32\svchost.exe> [(Verified)Microsoft Windows Publisher]
删除以下驱动
[ATI2HDDSRV / ATI2HDDSRV][Running/Manual Start]
<\??\C:\WINDOWS\system32\drivers\ati32srv.sys><N/A>
[DeepFree Update / DeepFree Update][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\pcihdd2.sys><N/A>
[npkcrypt / npkcrypt][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\npkcrypt.sys><N/A>
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\npkycryp.sys><N/A>
[PciHardDisk / PciHardDisk][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\fat32.sys><N/A>
并删除以下文件
C:\WINDOWS\system32\drivers\ati32srv.sys
C:\WINDOWS\system32\drivers\pcihdd2.sys
C:\WINDOWS\system32\npkcrypt.sys
C:\WINDOWS\system32\npkycryp.sys
C:\WINDOWS\system32\fat32.sys
C:\WINDOWS\Kvsc3.exE
C:\WINDOWS\MsIMMs32.exE
C:\WINDOWS\LotusHlp.exe
C:\WINDOWS\MsPrint32D.exe> [N/A]
C:\WINDOWS\system32\spoolsv\spoolsv.exe
C:\Program Files\SuperPlayer3500\SysExplr.exe
C:\WINDOWS\338448M.exe
C:\WINDOWS\338448L.exe
C:\WINDOWS\WSockx2_32.exe
C:\WINDOWS\system32\HDDGuard.dll