结束如下进程
C:\WINDOWS\QmlsbGdhdGVz\command.exe
C:\RECYCLER\RECYCLER.com
修复
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\RECYCLER\RECYCLER.com
O1 - Hosts: 255.255.255.255 ar.atwola.com atdmt.com avp.ch avp.com avp.ru awaps.net ca.com dispatch.mcafee.com download.mcafee.com download.microsoft.com downloads.microsoft.com engine.awaps.net f-secure.com ftp.f-secure.com ftp.sophos.com go.microsoft.com liveupdate.symantec.com mast.mcafee.com mcafee.com msdn.microsoft.com my-etrust.com nai.com networkassociates.com office.microsoft.com phx.corporate-ir.net secure.nai.com securityresponse.symantec.com service1.symantec.com sophos.com spd.atdmt.com support.microsoft.com symantec.com update.symantec.com updates.symantec.com us.mcafee.com vil.nai.com viruslist.ru windowsupdate.microsoft.com www.avp.ch www.avp.com www.avp.ru www.awaps.net www.ca.com www.f-secure.com www.kaspersky.ru www.mcafee.com www.my-etrust.com www.nai.com www.networkassociates.com www.sophos.com www.symantec.com www.trendmicro.com www.viruslist.com www.viruslist.ru www3.ca.com
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - (no file)
O2 - BHO: (no name) - {0C7C23EF-A848-485B-873C-0ED954731014}? - (no file)
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB}? - (no file)
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410}? - (no file)
O2 - BHO: (no name) - {3E422F49-1566-40D3-B43D-077EF739AC32}? - (no file)
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD}? - (no file)
O2 - BHO: (no name) - {4E83D567-4697-4F7B-B1F0-A513B01DB89A}? - (no file)
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B}? - (no file)
O2 - BHO: DuDu.com - {6BDE1669-B490-48E3-B668-456314F2D6C3} - C:\Program Files\DuDu\DddClient\dddiemon.dll (file missing)
O2 - BHO: (no name) - {6E28339B-7A2A-47B6-AEB2-197004272379}? - (no file)
O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Program Files\Accoona\ASearchAssist.dll
O2 - BHO: MAngle Class - {9A556B8F-FD02-420E-A1FD-9DB33808254E} - C:\Program Files\MySec\secmouseaaa.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7}? - (no file)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4}? - (no file)
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB}? - (no file)
O3 - Toolbar: (no name) - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5}? - (no file)
O3 - Toolbar: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD}? - (no file)
O3 - Toolbar: (no name) - {364B6276-C6C1-40B6-A6D7-6C48871FD707}? - (no file)
O4 - HKLM\..\Run: [SECUPDATE] C:\Program Files\MySec\secupdateaaa.exe -sv
O4 - HKLM\..\RunServices: [Configuration Loader] scvhost.exe
O4 - HKLM\..\RunServices: [MSN Messenger] msnmsgi.exe
O4 - HKLM\..\RunServices: [Microsoft sddcE Contol] taskmnegr.exe
O4 - HKLM\..\RunServices: [Microsoft Update] msconfg.exe
O4 - HKLM\..\RunServices: [Z]MNI_Ojrpek]`]JPV]`] C:\WINDOWS\System32\ikwhpntkmr.exe
O4 - HKLM\..\RunServices: [TMUHY[IMLWUZ] C:\WINDOWS\System32\iqhou.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\QmlsbGdhdGVz\command.exe
卸载
C:\Program Files\Accoona
C:\Program Files\MySec
删除
C:\WINDOWS\QmlsbGdhdGVz\command.exe
C:\RECYCLER\RECYCLER.com
scvhost.exe
msnmsgi.exe
taskmnegr.exe
msconfg.exe
C:\WINDOWS\System32\ikwhpntkmr.exe
C:\WINDOWS\System32\iqhou.exe
C:\WINDOWS\QmlsbGdhdGVz
C:\Program Files\Accoona
C:\Program Files\MySec
附件:
364052200626134758.JPG