1. 關閉系統還原, 重新開機, 按f8進入安全模式.
2. 開啟hijackthis , 按 "do a system scan only".
3. 剔選以下項目, 按 "fix checked" , 然後關閉hijackthis.
O2 - BHO: (no name) - {A1626E66-B26B-C628-A1DF-BDACCFA26EE1} - C:\Program Files\Common Files\Relive.dll (file missing)
O2 - BHO: (no name) - {C2626E66-D21B-E628-C1DF-1DACCFA36ED2} - C:\Program Files\Common Files\fjOs0r.dll (file missing)
O11 - Options group: [TBH] SOSO AddressBar Search
O18 - Protocol: sogua - {E61B2425-635A-487B-AF55-83D287118F59} - C:\WINDOWS\system32\SoguaPlayerXControl.ocx (file missing)
4. 到控制台 > 資料夾選項 > 檢視 > 選「顯示所有檔案」及 不選「隱藏受保護的系統檔」,刪除C:\Documents and Settings\用戶名\Local Settings\Temp\ 及 Temporary Internet Files 入面所有的files.
刪除以下檔案(如有)
C:\Program Files\Common Files\Relive.dll
C:\Program Files\Common Files\fjOs0r.dll
C:\WINDOWS\system32\SoguaPlayerXControl.ocx
5. 以附件形式附上新的hijackthis report + combofix report,以便作檢查,順便報告狀況。