结束进程C:\WINDOWS\system32\NTdhcp.exe
修复
O4 - HKLM\..\Run: [NTdhcp] C:\WINDOWS\system32\NTdhcp.exe
删除C:\WINDOWS\system32\NTdhcp.exe
然后参考
http://forum.ikaka.com/topic.asp?board=28&artid=7866296恢复瑞星的运转。
以上是最大的问题,另外还有:
修复:
O2 - BHO: Ad Engine - {077FD0C3-1291-4104-A356-41E36B252682} - C:\Program Files\Yayad\AdCore.dll
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\system32\wmpdrm.dll
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O4 - HKLM\..\Run: [spoolsv] C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - Extra 'Tools' menuitem: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O18 - Filter: text/html - {65CBAF77-19CA-4B81-86D5-7835D59BEA85} - C:\WINDOWS\system32\intel.dll
O21 - SSODL: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
卸载:
C:\Program Files\Yayad\
C:\PROGRA~1\MMSASS~1\
删除:
C:\Program Files\Yayad\
C:\PROGRA~1\MMSASS~1\
还有:
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
这项的详细处理参考
http://forum.ikaka.com/topic.asp?board=28&artid=7971417O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\system32\wmpdrm.dll
O4 - HKLM\..\Run: [spoolsv] C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
这两项的详细处理参考
http://forum.ikaka.com/topic.asp?board=28&artid=7948848O23 - Service: NTService - mk music - C:\WINDOWS\system32\ntservice.exe
这一项很可疑,有可能是木马程序。建议:
控制面板-性能与维护-管理工具-服务→找到NTService→双击→启动类型→禁止→停止→应用→确定。终止NTService这个服务。
然后在注册表中展开
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
删除NTService项目
然后在硬盘中删除C:\WINDOWS\system32\ntservice.exe