删除启动项
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]下注册表项目及<>内文件
<{50618412-C528-C784-C056-C164D1F7C505}><C:\WINDOWS\system32\detxeiua.dll> [File is missing]
<{8C8D1401-A58D-A81C-CD24-A5915C4517C8}><C:\WINDOWS\system32\mnmhhsrv.dll> [File is missing]
<{97FD640A-158F-48AC-FD14-1597F14A9779}><C:\WINDOWS\system32\mndsisrv.dll> [File is missing]
<{2A698452-C5D8-C584-C256-C264C987C5A2}><C:\WINDOWS\system32\ijdybpaw.dll> [File is missing]
<{48093456-9012-4568-9076-908765467184}><C:\WINDOWS\system32\tisqdtyu.dll> [File is missing]
<{8A041F13-A111-12A3-B0CF-F99818AA68A8}><C:\WINDOWS\system32\zxmsewin.dll> [File is missing]
<{470165F1-9F65-569F-F895-F14F58F41074}><C:\WINDOWS\system32\lofsdjbo.dll> [File is missing]
<{60940F85-F015-14F1-A05F-F69858AC6D06}><C:\WINDOWS\system32\zptldsys.dll> [File is missing]
<{6A069845-2036-6084-9054-6087502480A6}><C:\WINDOWS\system32\ozfyfbyt.dll> [File is missing]
<{25FD6584-698F-BCD2-602C-698745210352}><C:\WINDOWS\system32\rijxbkin.dll> [File is missing]
<{6A908760-8000-4000-A000-9000322145A6}><C:\WINDOWS\system32\akjsfkaq.dll> [File is missing]
<{E490415F-65F8-B5C5-D8BA-9405FB12054E}><C:\WINDOWS\system32\yzztnmsn.dll> [File is missing]
<{DC69134A-F15F-D14D-A31A-C31C4D124FCD}><C:\WINDOWS\system32\arjrkler.dll> [File is missing]
<{45671234-7890-ABCD-CDEF-567801237654}><C:\WINDOWS\system32\yxcsdhlp.dll> [File is missing]
<{8C954872-1230-6541-9548-6541025884C8}><C:\WINDOWS\system32\fd233ds4f4.dll> [File is missing]
<{A1954FAC-1023-154F-895A-1458258AD81A}><C:\WINDOWS\system32\ypdjhbmp.dll> [File is missing]
<{4D698451-2015-6358-9871-2015987452D4}><C:\WINDOWS\system32\apzhdtde.dll> [File is missing]
<{D47A61B8-0EAB-417F-8DF4-5C949982A2AF}><C:\Program Files\Internet Explorer\PLUGINS\Windows64.Sys> [File is missing]
<{A9895933-6636-4281-BC58-EE6DE2AF96E3}><C:\WINDOWS\system32\ddserh.dll> [File is missing]
<{8C41B7F7-3168-400D-A702-0E7EFE0BA304}><C:\WINDOWS\system32\sgdewg.dll> [File is missing]
删除驱动
[834e / 834ep][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\834ep.sys><>
[acpidisk / acpidisk][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[jql84 / jql84][Stopped/Boot Start]
<\SystemRoot\system32\drivers\jql84.sys><N/A>
删除浏览器加载项
[]
{D47A61B8-0EAB-417F-8DF4-5C949982A2AF} <C:\Program Files\Internet Explorer\PLUGINS\Windows64.Sys, N/A>
清除各个磁盘根目录的autorun.inf文件和MSDOS.bat文件
PS;LA看我签名,别中自动播放病毒了