用sreng
删除启动项目=>注册表
<My App><a> [N/A]
<csrsses><c:\windows\csrsses.exe> [Microsoft Corporation]
<AVPSrv><C:\WINDOWS\AVPSrv.exE> []
<NVDispDrv><C:\WINDOWS\chjflp.exe> []
<MsPrint32D><C:\WINDOWS\dtvyat.exe> []
<DbgHlp32><C:\WINDOWS\DbgHlp32.exe> []
<comrepl32><C:\windows\system32\com\comrepl32.exe> []
<{5859245F-345D-BC13-AC4F-145D47DA34F5}><C:\WINDOWS\system32\avzxemn.dll> [N/A]
<{B0E4D1E9-3CE5-48A1-8DF0-6463E046E7EF}><C:\WINDOWS\system32\wgxfvtyyip.dll> [N/A]
<{5A1247C1-53DA-FF43-ABD3-345F323A48D5}><C:\WINDOWS\system32\avwgemn.dll> [N/A]
<{5BD41097-3693-4133-820E-FDAC57AF00E2}><C:\Program Files\Internet Explorer\PLUGINS\NvSys74.Sys> [N/A]
<{6859245F-345D-BC13-AC4F-145D47DA34F6}><C:\WINDOWS\system32\avzxfmn.dll> [N/A]
删除启动项目=>服务
[Remote IPRIP Listener / Iprip][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\liprip.dll><Microsoft Corporation>
[Infrared Monitor / Irmon][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\rimon.dll><Microsoft Corporation>
[Server / lanmanserver][Running/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\srvsvc.dll><Microsoft Corporation>
启动项目=>注册表
<AppInit_DLLs> 编辑成为空值
重启,删除
C:\WINDOWS\system32\NavCOM01.dll
C:\WINDOWS\system32\WSWSleak01.dll
c:\windows\csrsses.exe
C:\WINDOWS\AVPSrv.exE
C:\WINDOWS\chjflp.exe
C:\WINDOWS\dtvyat.exe
C:\WINDOWS\DbgHlp32.exe
C:\windows\system32\com\comrepl32.exe
C:\WINDOWS\system32\avzxemn.dll
C:\WINDOWS\system32\wgxfvtyyip.dll
C:\WINDOWS\system32\avwgemn.dll
C:\Program Files\Internet Explorer\PLUGINS\NvSys74.Sys
C:\WINDOWS\system32\avzxfmn.dll
C:\WINDOWS\system32\liprip.dll
C:\WINDOWS\system32\rimon.dll
C:\WINDOWS\System32\srvsvc.dll
参考下:http://www.vaid.cn/bbs/viewthread.php?tid=71&extra=page%3D1
建议使用xdelbox删除要删除的文件..
http://forum.ikaka.com/topic.asp?board=28&artid=8381032