【回复“新版菜鸟”的帖子】
您好!
终止进程:
C:\WINNT\svchost.exe
C:\WINNT\svchoct.exe
C:\WINNT\system32\14531485.exe
修复:
R3 - Default URLSearchHook is missing
所有的O1项
O2 - BHO: Router Layer - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - C:\WINNT\System32\aclayer.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (file missing)
O2 - BHO: (no name) - {9C5875B8-93F3-429D-FF34-660B206D897A} - C:\WINNT\system32\performent002.dll
O2 - BHO: IEMozgObj Class - {CE7C3CF0-4B15-11D1-0BED-709549C10020} - C:\WINNT\system32\1zr8rjmzr1.dll (file missing)
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:
file://d: oo.mht!http://195.95.218.83/users/sale/web/axe/x.chm::/update.exe
O16 - DPF: {11311111-1111-1111-1111-111111111157} -
file://C:\Recycled\Q337751.exe
O23 - Service: eoffice - Unknown owner - d:\eoffice\bin\apache.exe" -k runservice (file missing)
O23 - Service: svchost.exe (moto) - Unknown owner - C:\WINNT\svchost.exe(疑似灰鸽子)
O23 - Service: MySQL - Unknown owner - D:\EOFFICE\mysql\bin\mysqld-nt.exe (file missing)
O23 - Service: svchoct.exe (yuto) - Unknown owner - C:\WINNT\svchoct.exe(疑似灰鸽子)
删除:
以上提及的所有文件。
关于灰鸽子,请参考:
http://forum.ikaka.com/topic.asp?board=28&artid=5666824。