用sreng
删除启动项目=>注册表
<swg><; > [N/A]
<dasa><; > [N/A]
<fysa><; > [N/A]
<jtsa><; > [N/A]
<KuGoo3><; > [N/A]
<ltnward><; > [N/A]
<mhsa><; > [N/A]
<PHIME2002A><; > [N/A]
<PHIME2002ASync><; > [N/A]
<qjsa><; > [N/A]
<rxsa><; > [N/A]
<tlsa><; > [N/A]
<wdsa><; > [N/A]
<wgsa><; > [N/A]
<WinSys><; > [N/A]
<WinSysM><; > [N/A]
<wlsa><; > [N/A]
<wmsa><; > [N/A]
<ztsa><; > [N/A]
<MSDEG32><LYLoader.exe> [N/A]
<MSDWG32><LYLoadbr.exe> [N/A]
<MSDCG32 ><LYLeador.exe> [N/A]
<MSDOG32><LYLoador.exe> [N/A]
<MSDSG32><LYLoadar.exe> [N/A]
<MSDHG32><LYLoadhr.exe> [N/A]
<MSDQG32><LYLoadqr.exe> [N/A]
<main><rundll32.exe "C:\program files\internet explorer\use18.dll" mymain> [N/A]
<Userinit><C:\WINDOWS\system32\inf\svchost.exe C:\WINDOWS\system32\lwisys16_071113.dll start> [N/A]
<{AF26F407-E2BD-4708-9B88-71F815846E2E}><C:\WINDOWS\System32\igzxdd1.dll> []
用sreng
删除启动项目=>服务
[ttchbr.3322.org / ttchbr.3322.org][Stopped/Auto Start]
<C:\WINDOWS\system32\ttchbr.3322.org.exe><N/A>
[Windows Accounts Driver / WindowsRemote][Stopped/Auto Start]
<C:\WINDOWS\system32\805.exe><N/A>
[Telephotsgoogle / Winownes][Stopped/Auto Start]
<><N/A>
启动项目=>注册表
<AppInit_DLLs> 编辑改为空值
删除文件
C:\WINDOWS\system32\LYLoader.exe
C:\WINDOWS\system32\LYLoadbr.exe
C:\WINDOWS\system32\LYLeador.exe
C:\WINDOWS\system32\LYLoador.exe
C:\WINDOWS\system32\LYLoadar.exe
C:\WINDOWS\system32\LYLoadhr.exe
C:\WINDOWS\system32\LYLoadqr.exe
C:\program files\internet explorer\use18.dl
C:\WINDOWS\system32\inf\svchost.exe
C:\WINDOWS\system32\lwisys16_071113.dll
C:\WINDOWS\System32\igzxdd1.dll
C:\WINDOWS\system32\ttchbr.3322.org.exe
C:\WINDOWS\system32\805.exe