操作参考:
结束C:\windows\smss.exe进程
修复
O2 - BHO: - {1E6CE4CD-161B-4847-B8BF-E2EF72299D69} - C:\WINDOWS\System32\ib6.dll
O2 - BHO: DownloadBHO T2BHO - {B1D147E7-873E-4909-8127-695D9BB78728} - C:\WINDOWS\Downloaded Program Files\barhelp24.0.dll
O3 - IE工具栏增项: 天下搜索 - {56A7DC70-E102-4408-A34A-AE06FEF01586} - C:\WINDOWS\Downloaded Program Files\iebar23.0.dll
O4 - 启动项HKLM\\Run: [Microsoft Windows Session Manager Subsystem] C:\windows\smss.exe
O4 - 启动项HKLM\\Run: [Microsoft Windows Logon Process] C:\windows\winlogon.exe
O4 - 启动项HKLM\\Run: [Microsoft Office] C:\windows\System32\msoff.exe
O23 - NT 服务: Gray_Pigeon_Server2.0 (GrayPigeonServer2.0) - www.huigezi.net - C:\WINDOWS\G_Server2.0.exe
删除C:\WINDOWS\System32\ib6.dll
C:\WINDOWS\Downloaded Program Files\barhelp24.0.dll
C:\WINDOWS\Downloaded Program Files\iebar23.0.dll
C:\windows\smss.exe
C:\windows\winlogon.exe
C:\windows\System32\msoff.exe
C:\WINDOWS\G_Server2.0.exe
另外在硬盘中搜索G_Server2.0.dll
G_Server2.0key.dll
G_Server2.0_hook.dll
找到后全部删除
或文件找不到或无法删除
请参考http://www.xfilt.com/tech/trojan-horse.htm
或参考图片设置:
附件:
3640522006127145940.JPG