boot into safe mode -- F8

1. boot into safe mode (because some AD softwares have multiple processes, and it can general itself as soon as you delete it, both in registry and files).

2. run regedit.
remove suspected keys under:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

or

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

3. remove related folders/files.

4. run AD-aware or spy-bot to double check.

請您先登陸,再發跟帖!