建议修复(如果楼主认为安全可以不选)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
所有01项
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll (file missing)
O2 - BHO: (no name) - {2AEE1EC3-29FB-2330-150F-D0F318C3CB46} - C:\WINDOWS\inscdm\evuhebnsyb.dll
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem303.dll (file missing)
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\System32\qylhelper.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\Isass.exe
O4 - HKLM\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKLM\..\Run: [WIN32] win32.exe
O4 - HKLM\..\Run: [msxct] msxct.exe
O4 - HKLM\..\Run: [05roriof] C:\WINDOWS\System32\05roriof.exe
O4 - HKLM\..\Run: [MoveSearch] C:\Program Files\wsearch\Search.exe
O4 - HKLM\..\Run: [usbn] C:\WINDOWS\system32\usbn.exe -go -c77 -w
O4 - HKLM\..\Run: [BCUpdate] C:\WINDOWS\System32\BCUP.exe
O4 - HKLM\..\Run: [ilzrflm] c:\windows\system32\cdpuqs.exe r
O4 - HKLM\..\RunServices: [WIN32] win32.exe
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKCU\..\Run: [3721] C:\$NtUninstallQ5926809$\3721.bat
O4 - HKCU\..\Run: [WIN32] win32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {33331111-1111-1111-1111-611111193457} -
file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} -
file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-622221193458} -
file://c:\ex.cab
O16 - DPF: {64311111-1111-1121-1111-111191113457} -
file://c:\eied_s7.cab
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
重起进安全模式
管理工具--服务--停止并禁用System Startup Service (SvcProc)
我的电脑--工具--文件夹选项--查看--显示所有文件(如图,或参考本版基本操作说明http://forum.ikaka.com/topic.asp?board=67&artid=6789825)
查找并删除
C:\WINDOWS\Nail.exe
C:\WINDOWS\inscdm\evuhebnsyb.dll
C:\WINDOWS\System32\qylhelper.dll
C:\WINDOWS\System32\msbe.dll
C:\WINDOWS\System32\Isass.exe
C:\$NtUninstallQ5926809$\sp4custom.dll
win32.exe
msxct.exe
C:\WINDOWS\System32\05roriof.exe
C:\Program Files\wsearch\Search.exe
C:\WINDOWS\system32\usbn.exe
c:\windows\system32\cdpuqs.exe
C:\WINDOWS\System32\BCUP.exe
C:\$NtUninstallQ5926809$\3721.bat
c:\ex.cab
c:\eied_s7.cab
C:\WINDOWS\System32\vbsys2.dll
C:\WINDOWS\svcproc.exe
清空IE临时文件夹
附件:
5221632005719154051.gif