运行sreng,删除启动注册表项:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{5C4DE495-E495-C4D0-95C4-4954D495C4D0}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\E495C4D0.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<DVDBurn><C:\WINDOWS\Downloaded Program Files\AfxEdit.dll> [N/A]
启动服务项:
[System Event Notification / SENS][Stopped/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\kbigmlgj.dll><N/A>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>
启动服务驱动:
[New0 / New0][Stopped/Auto Start]
<\??\C:\WINDOWS\System32\new.sys><N/A>
安全模式删除:
C:\WINDOWS\System32\kbigmlgj.dll
C:\WINDOWS\System32\new.sys
C:\Program Files\Common Files\Microsoft Shared\MSINFO\E495C4D0.dll
C:\WINDOWS\Downloaded Program Files\AfxEdit.dll--自己确认