【回复“欢梦缘星星”的帖子】
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.7255.com/
O2 - BHO: MyLoader Class - {09BA1AA9-CAD4-4C14-BDE6-922DFF5F6F38} - C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEMDATA\YLxmdBrnv2_2002.dll
O2 - BHO: browser Class - {C86488AF-13D5-4FEF-9DDF-9FB88698CFC1} - C:\Documents and Settings\All Users\Application Data\Microsoft\Office\USERDATA\aGp7I0W3Fd_2002.dll
O4 - HKLM\..\Run: [C:\DOCUME~1\new\LOCALS~1\Temp\Setup_623.exe] C:\DOCUME~1\new\LOCALS~1\Temp\Setup_623.exe
O4 - HKLM\..\Run: [C:\DOCUME~1\new\LOCALS~1\Temp\dodolook057.exe] C:\DOCUME~1\new\LOCALS~1\Temp\dodolook057.exe
O4 - HKLM\..\Run: [C:\DOCUME~1\new\LOCALS~1\Temp\bind_50103.exe] C:\DOCUME~1\new\LOCALS~1\Temp\bind_50103.exe
O23 - Service: Network IPSEC Connections (BARCASE) - - C:\WINDOWS\system32\rundll32.exe c:\windows\system32\wbem\xefcn.dll,export 1087
关闭HIjackThis以外的所有应用程序。
断开网络。
用HijackThis修复上述项目。
重启。
显示隐藏文件。
删除下列文件:
C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEMDATA\YLxmdBrnv2_2002.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Office\USERDATA\aGp7I0W3Fd_2002.dll
C:\DOCUME~1\new\LOCALS~1\Temp\Setup_623.exe
C:\DOCUME~1\new\LOCALS~1\Temp\dodolook057.exe
C:\DOCUME~1\new\LOCALS~1\Temp\bind_50103.exe
C:\WINDOWS\system32\rundll32.exe c:\windows\system32\wbem\xefcn.dll