终于找到一个工具 avenger
能在启动过程中在病毒前面载入,然后删掉了那两个文件
http://swandog46.geekstogo.com/avengernotes.htm
he Avenger is a full-able, kernel-level driver designed to remove highly persistent files and registry keys/values protected by entrenched malware. Basically this means that The Avenger is a program to which you give commands to execute (the ) consisting of files to delete, etc., which would otherwise be hard to delete because they were protected or “in use” by malicious software. With the recent proliferation of rootkits and other strongly-protected forms of malware, a tool like this one to remove deeply-entrenched files has become more and more necessary.