用同版本正常文件替换:c:\windows\system32\comres.dll
删除:
c:\windows\system32\wgalogon.dll (windows 正版验证)
c:\windows\system32\drivers\asyncmac.sys
删除注册表启动项目:
[WinlogonNotify: WgaLogon] <WgaLogon.dll>
[{25BC5491-68B6-4416-BC69-6E8442312604}] <C:\WINDOWS\system32\aEUzzDyN4fVnJ.dll>
[{23DA65D2-C696-4EE4-BEE8-B4841DEC3E30}] <C:\WINDOWS\system32\ndxq9awMc.dll>
[{37C5D66A-8B1B-4545-8112-3751194F6A4A}] <C:\WINDOWS\system32\taNjsFa2tT2Dh.dll>
[{FC8F4603-4AB2-4A0D-B17F-886CC8AAAFD2}] <C:\WINDOWS\fonts\CESPVP8FQd.fon>
[{71C4F360-FF1E-413E-B17A-0CA267A78E97}] <C:\WINDOWS\system32\qB5BKZy7vR5m.dll>
[{FCA4D3BE-C6C7-4F4D-9CBD-CB2666647ACA}] <C:\WINDOWS\system32\EN7hzSreCat8.dll>
[{AC933D46-96A7-4670-9292-E7C4126C071E}] <C:\WINDOWS\fonts\wQ7KbaNZKMe5G4qZ.fon>
[{76CBCF38-0583-44C7-A1AE-D463DFE625EC}] <C:\WINDOWS\system32\skcfujQ5EDN.dll>
[{A23CA53C-731F-4033-92E8-C1DFB4E71D34}] <C:\WINDOWS\system32\JBn2ypqY23vWX.dll>
[{E4814792-EFA3-4C20-93D0-8B130A59F9A8}] <C:\WINDOWS\system32\E4814792.dll>
[{F1C149F4-380C-4F8A-B87E-7393732B27C1}] <C:\WINDOWS\system32\GsfMwDWD3.dll>
[{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}] <C:\WINDOWS\system32\08223B03.dll>
[{750DBD56-AF03-47CB-BB28-BBF312B059F9}] <C:\WINDOWS\fonts\xbpCfXnG6wUVF.fon>
[{AB900155-F1F0-4165-9E73-67BC13BBCE89}] <C:\WINDOWS\system32\xg4hAPNygs29.dll>
服务:
[RAS Asynchronous Media Driver / AsyncMac] <system32\DRIVERS\asyncmac.sys>