使用SREng禁用以下服务和驱动:
COM+ Event Systemp / COM+ Event Systemp
COM+ Event Systems / COM+ Event Systems
System Local Kernel Service / kernel
Volume Shadow Copyremd8 / ServiceCopyremd8
l2n / l2nr
q63pabht / q63pabht
清除以下浏览器加载项:
MyLoader Class
browser Class
重启系统,显示隐藏文件,删除:
D:\Program Files\Common Files\Microsoft Shared\MSINFO\svchost.exe
D:\Program Files\Common Files\Microsoft Shared\MSINFO\mas.exe
System32\DRIVERS\l2nr.sys
D:\WINDOWS\system32\drivers\q63pabht.sys
D:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEMDATA\vz7mAyn2M4_3027.dll
D:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\Fm9jx3OCeF_3027.dll
D:\WINDOWS\system32\k5m6h.dll