按ctrl+alt+del
调出任务管理器
结束C:\WINDOWS\system32\netdrvr.exe进程
用HIJACKTHIS修复
O2 - BHO: MSEvents
Object - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - C:\WINDOWS\System32\jkhgh.dll
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX
O2 - BHO: (no name) - {c82401d8-7d2f-43c4-bdfe-00320c008982} - C:\WINDOWS\System32\sompluex.dll
O2 - BHO: Bho Class - {EFDAC3FE-F44A-4030-8589-1E23BC6573D5} - C:\WINDOWS\System32\tkvpqinw.dll
O4 - 启动项HKLM\\Run: [Anti-Virus Update Scheduler V1.39.12R] C:\sfx.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O20 - Winlogon Notify: efedb - efedb.dll (file missing)
O20 - Winlogon Notify: jkhgh - C:\WINDOWS\System32\jkhgh.dll
O23 - NT 服务: BoolTern - Unknown owner - C:\WINDOWS\svch0st.exe (file missing)
O23 - NT 服务: EnvSec - Unknown owner - C:\WINDOWS\System32\envsec.exe (file missing)
O23 - NT 服务: spool - Unknown owner - C:\WINDOWS\spoollv.exe (file missing)
O23 - NT 服务: Windows Archiver (winarc) - Unknown owner - C:\WINDOWS\windat.exe (file missing)
O23 - NT 服务: Windows Basis Cont - Unknown owner - C:\WINDOWS\WinFTP32.exe (file missing)
O23 - NT 服务: WindowsSysBoot - Unknown owner - C:\WINDOWS\cytob.exe (file missing)
删除以上文件
找不到文件请参考图片设置:
附件:
364052200617185626.JPG