[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]下注册表项目
<Userinit><C:\WINDOWS\system32\userinit.exe,,C:\WINDOWS\system32\Down(0).exe> [File is missing]
改为 <Userinit><C:\WINDOWS\system32\userinit.exe,>
删除文件C:\WINDOWS\system32\Down(0).exe
删除服务及对应文件
[360safeAVP.com.cn / 360safeAVP.com.cn][Stopped/Auto Start]
<C:\WINDOWS\360safe.com.cn.exe><N/A>
[Adobe LM Service / AdoLms][Running/Auto Start]
<C:\WINDOWS\system32\Backup\smss.exe><N/A>
[Microsoftpvsy / Microsoftpvsy][Stopped/Auto Start]
<C:\WINDOWS\times><(File is missing)>
[NetMeeting Remote Desktop Sharing / mnmsrvc][Stopped/Manual Start]
<C:\WINDOWS\system32\mnmsrvc.exe><(File is missing)>
[MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
<f:\PROGRA~1\MICROS~1\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
[Block Level Backup Engines / wbengins][Stopped/Auto Start]
<C:\WINDOWS\System32\odsvc.exe><N/A>
删除以下服务及svchost.exe 对应的DLL(不是删除svchost.exe )
[Windows Presentation Foundation (WPF) / application][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k application-->C:\WINDOWS\system32\onGGdkqOvSsDBx.dll><N/A>
[bechcl / bechcl][Stopped/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k bechcl-->%SystemRoot%\System32\gvtxbm.dll><N/A>
[mbxoyq / mbxoyq][Stopped/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k mbxoyq-->%SystemRoot%\System32\.mqucfu.dll><N/A>
删除驱动
[001fdd59 / 001fdd59][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\001fdd59.sys><N/A>
5901109 / 5901109][Running/]
<2 - 系统找不到指定的文件。
><N/A>
以下驱动对应文件可疑,楼主自己测下
http://www.virscan.org/[aaatimeo / aaatimeo][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\aaatimeo.sys><Microsoft Corporation>
[mv61xx / mv61xx][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\mv61xx.sys><Marvell Semiconductor, Inc.>
[mvSata / mvSata][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\mvsata.sys><Marvell Semiconductors Inc.>
[rr172x / rr172x][Stopped/Boot Start]
<\SystemRoot\system32\DRIVERS\rr172x.sys><HighPoint Technologies, Inc.>
[rr174x / rr174x][Stopped/Boot Start]
<\SystemRoot\system32\DRIVERS\rr174x.sys><HighPoint Technologies, Inc.>
[rr2340 / rr2340][Stopped/Boot Start]
<\SystemRoot\system32\DRIVERS\rr2340.sys><HighPoint Technologies, Inc.>
[UnlockerDriver4 Driver / UnlockerDriver4][Stopped/Manual Start]
<\??\d:\Program Files\Unlocker\UnlockerDriver4.sys><N/A>