F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 207.234.225.136 www.halifax-online.co.uk
O1 - Hosts: 207.234.225.136 ibank.barclays.co.uk
O1 - Hosts: 207.234.225.136 online.lloydstsb.co.uk
O1 - Hosts: 207.234.225.136 online-business.lloydstsb.co.uk
O1 - Hosts: 207.234.225.136 www.ukpersonal.hsbc.co.uk
O1 - Hosts: 207.234.225.136 www.nwolb.com
O1 - Hosts: 207.234.225.136 banesnet.banesto.es
O1 - Hosts: 207.234.225.136 extranet.banesto.es
O1 - Hosts: 207.234.225.136 ebanking.bccbrescia.it
O1 - Hosts: 207.234.225.136 www.bankofscotlandhalifax-online.co.uk
O1 - Hosts: 207.234.225.136 www.rbsdigital.com
O1 - Hosts: 207.234.225.136 oi.cajamadrid.es
O1 - Hosts: 207.234.225.136 bancae.caixapenedes.com
O1 - Hosts: 207.234.225.136 banking.postbank.de
O1 - Hosts: 207.234.225.136 meine.deutsche-bank.de
O1 - Hosts: 207.234.225.136 myonlineaccounts2.abbeynational.co.uk
O1 - Hosts: 207.234.225.136 ibank.cahoot.com
O1 - Hosts: 207.234.225.136 webbank.openplan.co.uk
O1 - Hosts: 207.234.225.136 bancopostaonline.poste.it
O1 - Hosts: 207.234.225.136 www.rasbank.it
O1 - Hosts: 207.234.225.136 www.credem.it
O1 - Hosts: 207.234.225.136 mybank.bybank.it
O1 - Hosts: 207.234.225.136 www.bancagenerali.it
O1 - Hosts: 207.234.225.136 www.bancaintesa.it
O1 - Hosts: 207.234.225.136 www.creval.it
O1 - Hosts: 207.234.225.136 ibank.internationalbanking.barclays.com
O1 - Hosts: 207.234.225.136 www.abbeyinternational.com
O1 - Hosts: 207.234.225.136 www.bbvanet.com
O1 - Hosts: 207.234.225.136 www.fineco.it
O1 - Hosts: 207.234.225.136 www.cajamar.es
O1 - Hosts: 207.234.225.136 welcome7.co-operativebank.co.uk
O1 - Hosts: 207.234.225.136 welcome11.co-operativebankonline.co.uk
O4 - 启动项HKLM\\Run: [Driv] C:\windows\mrjj.exe
O4 - 启动项HKLM\\Run: [virD] C:\windows\mrjj.exe
O11 - Options group: [!CNS] 网络实名
O11 - Options group: [CDNCLIENT] 中文上网
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O15 - “受信任的站点”中添加项: *.media-motor.net
O15 - “受信任的站点”中添加项: *.popuppers.com
O16 - DPF: {28E0FA88-ABA8-4937-A247-3031F1A11165} (Installer Class) - http://pi.51.net/download/diybar2.cab
O16 - DPF: {7149E79C-DC19-4C5E-A53C-A54DDF75EEE9} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/joysaver.cab
O16 - DPF: {9A578C98-3C2F-4630-890B-FC04196EF420} - http://jump.cnnic.cn/stat/stat?sid=0008&debug=false&pid=c_95p&url=http://client.jogo.cn/download/cnnic/cdn.cab
这几项直接在扫描工具上修复.
附件:
5220982005112485654.bmp