Manual cleanup: Before cleanup, set "show all files" and "Hide protected operating system files" in the folder options ".
(1.exe clear svchost.exe
Svchost.exe in windowssystem32is a normal system program. If svchost.exe is found in the Windows directory, the SYSTEM process is terminated first and the file is deleted. (Note: In the xp system, many processes are svchost, but generally all SYSTEM process users are SYSTEM, if the process is used with your username, it indicates a Trojan Program)
(2)clear wincfgs.exe
The Wincfgs.exe file is generally in the WINDOWS-SYSTEM32 directory, it is also the first to end the process, and then delete the file.
Then go to the Registry: regedit
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunOnce
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunOnceEx
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun
If the preceding two process names appear, the key property value is deleted.
Similarly, go to MSCONFIG and remove the hook of the startup Item. Then restart