启动项目
注册表
<webwork><C:\WINDOWS\webwork\webwork.dll> [N/A](这项自己确认下)
==================================
删除服务
[CoolWare / CoolWare][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\gcvu.dll><N/A>
[Windows fbut RunThem / fbut][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\awpo\kgzy.dll><N/A>
[Gentad / Gentad][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\struts.dll><N/A>
[ijkzdv / ijkzdv][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\COMMON~1\vjkzjv\vjkzjv.dll,Service -s><Microsoft Corporation>
[Navoct / Navoct][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\Program Files\iesnap\navoct.dll>< >
[ykyisx / ykyisx][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\PROGRA~1\lkyisx\lkyisx.dll><N/A>
==================================
删除驱动程序
[ADProt / ADProt][Stopped/System Start]
<\SystemRoot\system32\drivers\ADProt.sys><N/A>
[bcgdjecc / bcgdjecc][Stopped/Boot Start]
<\SystemRoot\system32\drivers\bcgdjecc.sys><N/A>
[bjqnicj / bjqnicj][Stopped/Boot Start]
<\SystemRoot\system32\drivers\bjqnicj.sys><>
[cdnprot / cdnprot][Running/Boot Start]
<\SystemRoot\system32\drivers\cdnprot.sys><中国互联网络信息中心(CNNIC)>
[CnsMinKP / CnsMinKP][Stopped/Boot Start]
<\SystemRoot\system32\drivers\CnsMinKP.sys><国风因特软件(北京)有限公司>
[gafbwm5 / gafbwm53][Stopped/Boot Start]
<\SystemRoot\System32\DRIVERS\gafbwm53.sys><N/A>
[libzkc6 / libzkc62][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\libzkc62.sys><N/A>
[lubyjb9 / lubyjb95][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\lubyjb95.sys><N/A>
[oemhpf / oemhpf][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\oemhpf.sys><N/A>
[R2A / R2A][Stopped/Disabled]
<\??\C:\WINDOWS\system32a2.sys><N/A>
[yaskp / yaskp][Stopped/Boot Start]
<\SystemRoot\system32\drivers\yaskp.sys><Copyright (C) yahoo Corporation.>
==================================
浏览器加载项
[]
{F40C6AF8-0252-4324-9F0C-27E93FB7A512} <C:\WINDOWS\system32\WINSC.dll, N/A>
[]
{F70231A8-C197-496B-A3E5-CF62FB5C246C} <C:\WINDOWS\system32\DpiDS\BHO.dll, >
[]
{F40C6AF8-0252-4324-9F0C-27E93FB7A512} <C:\WINDOWS\system32\WINSC.dll, N/A>
==================================
删除以上提到的文件,(除了C:\WINDOWS\System32\svchost.exe)
用windows清理助手清理下
还有问题再扫个日志上来