删除这三个文件:
C:\WINDOWS\system32\lfrmewrk.exe
C:\WINDOWS\system32\GTIAPI.DLL
C:\WINDOWS\system32\hbcmd.dll
————————————————————————————————————
下面这些就实在看不懂了,平时实在没见过,楼主你得自己判断了。
启动项目
注册表
<sys31><C:\Documents and Settings\jb_xu\Local Settings\Application Data\c23235.exe> [N/A]
<sys32><C:\WINDOWS\c25409.exe> [N/A]
<sys41><C:\Program Files\Common Files\d1216.exe> [N/A]
<sys42><C:\Documents and Settings\jb_xu\Local Settings\History\d16704.exe> [N/A]
<sys259061><C:\Program Files\25743.exe> [N/A]
<sys236012><C:\Documents and Settings\jb_xu\Cookies\19155.exe> [N/A]
<sys131001><C:\Program Files\22680.exe> [N/A]
<sys296112><C:\Documents and Settings\All Users\Application Data\30977.exe> [N/A]
<sys174011><C:\Documents and Settings\jb_xu\My Documents\My Pictures\32267.exe> [N/A]
<sys147392><C:\Documents and Settings\jb_xu\My Documents\6325.exe> [N/A]
==================================
启动文件夹
[Microsoft Firewall Client 管理]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Firewall Client 管理.lnk --> C:\WINDOWS\Installer\{199B7F78-69B7-47C5-8D4B-A3ED1391FB6B}\NewShortcut1_8C7A59A89ABE459A9A9308C281A4A264.exe [InstallShield Software Corp.]><N>
==================================
服务
[Code Cvt / CodeCvt][Stopped/Auto Start]
<C:\WINDOWS\system32\CodeCvt.exe><N/A>
[DCOM Client / DCOMClient][Stopped/Auto Start]
<C:\WINDOWS\system32\DCOMSvr.EXE><N/A>
[error monitor / EmonSrv][Running/Auto Start]
<C:\WINDOWS\system32\lfrmewrk.exe><N/A>
[ms cic / mscic][Stopped/Auto Start]
<C:\WINDOWS\system32\CIC~1.EXE><N/A>
[wup sex / wupsex][Stopped/Auto Start]
<C:\WINDOWS\system32\wupsex.exe><N/A>
==================================
驱动程序
[proregnh / proregnh][Stopped/System Start]
<system32\drivers\proregnh.sys><N/A>
[SYMIDSCO / SYMIDSCO][Stopped/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\IDS-DI~1\20070330.003\symidsco.sys><N/A>
==================================
浏览器加载项
[Abho Class]
{1238F6B9-C123-4049-B07E-7A71AF320032} <C:\WINDOWS\system32\571.dll, N/A>
[Jpeg Class]
{4970DA77-DB06-4EB9-AAB5-77AF0CC77310} <C:\WINDOWS\system32\2ab4.dll, N/A>
[TAid Class]
{54D8C87D-A513-4FB8-BF68-41965B66E4C5} <C:\WINDOWS\system32\chajei.ocx, N/A>
[UAid Class]
{7895DF4C-A963-4E63-AB8D-F85C7AF1CD66} <C:\WINDOWS\system32\winar.cpl, N/A>
[WAid Class]
{A79E7C91-A35B-486F-9BA0-14802C79A7BA} <C:\WINDOWS\system32\cdview.cpl, N/A>
[CPPIE Class]
{C6844939-C324-41E0-84D0-D42F8DA5EBAD} <C:\WINDOWS\system32\hbcmd.dll, TODO: <公司名>>
[ff Class]
{FAAAC0F6-94BE-4466-934B-7C53666A2F41} <C:\WINDOWS\system32\5711.dll, N/A>
[Abho Class]
{1238F6B9-C123-4049-B07E-7A71AF320032} <C:\WINDOWS\system32\571.dll, N/A>
[Jpeg Class]
{4970DA77-DB06-4EB9-AAB5-77AF0CC77310} <C:\WINDOWS\system32\2ab4.dll, N/A>
[TAid Class]
{54D8C87D-A513-4FB8-BF68-41965B66E4C5} <C:\WINDOWS\system32\chajei.ocx, N/A>
[UAid Class]
{7895DF4C-A963-4E63-AB8D-F85C7AF1CD66} <C:\WINDOWS\system32\winar.cpl, N/A>
[WAid Class]
{A79E7C91-A35B-486F-9BA0-14802C79A7BA} <C:\WINDOWS\system32\cdview.cpl, N/A>
[CPPIE Class]
{C6844939-C324-41E0-84D0-D42F8DA5EBAD} <C:\WINDOWS\system32\hbcmd.dll, TODO: <公司名>>
[ff Class]
{FAAAC0F6-94BE-4466-934B-7C53666A2F41} <C:\WINDOWS\system32\5711.dll, N/A>