禁用服务:
[System Event loader / sysloader][Stopped/Auto Start]
<"C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\sysloader.exe"><Microsoft>
禁用驱动程序:
bootdrv / bootdrv
kuka / kuka(怀疑)
gAGP440p / gAGP440p(怀疑)
npkycryp / npkycryp
txinjey / txinjey0
删除加载项
browser Class
重启系统,显示隐藏文件,删除
C:\WINDOWS\system32\ddos.exe
System32\Drivers\bootdrv.sys
C:\WINDOWS\system32\npkycryp.sys
System32\DRIVERS\txinjey0.sys
C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA(备份后删除)
C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM(备份后删除)
C:\WINDOWS\system32\msplrct.dll