修复
所有的01项
O2 - BHO: CNav Class - {1954558D-BD14-420A-BC38-7F41F7A1DDBB} - C:\WINDOWS\System32\NAVIGA~1.DLL
O2 - BHO: URLMonitor Class - {3ED9FFDA-79DB-4B2D-99B7-16EA3C4A3A92} - C:\WINDOWS\System32\hap.dll
O2 - BHO: Wbho Class - {40E3A34A-3282-41F8-AD2C-051BAB96AD4A} - C:\WINDOWS\System32\Usign.dll
O2 - BHO: DownloadValue Class - {616D4040-5712-4F0F-BCF1-5C6420A99E14} - C:\WINDOWS\System32\winhtp.dll
O4 - HKLM\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKLM\..\Run: [3721] C:\$NtUninstallQ5926809$\3721.bat
O4 - HKLM\..\Run: [WlN32] regedit -s C:\$NtUninstallQ887678$\WINSYS.cer
O4 - Startup: hosts.exe
O4 - Startup: run.bat
O20 - AppInit_DLLs: KB2059102.LOG
O21 - SSODL: DLMon - {590498A3-4131-4D8F-BA4B-36791A0803B1} - C:\WINDOWS\System32\DLMain.dll
O23 - Service: internet systemrundll - Unknown owner - C:\WINDOWS\systemrundll.exe
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\G_Server.exe
O23 - Service: Gray_Pigeon_Server2.0 (GrayPigeonServer2.0) - Unknown owner - C:\WINDOWS\G_Server2.0.exe
O23 - Service: SYSTEM32_Server (SYSTEM32) - Unknown owner - C:\WINDOWS\SYSYTEM32.exe
卸载HAP
删除
C:\WINDOWS\System32\NAVIGA~1.DLL
C:\WINDOWS\System32\hap.dll
C:\WINDOWS\System32\Usign.dll
C:\WINDOWS\System32\winhtp.dll
C:\$NtUninstallQ5926809$
C:\$NtUninstallQ887678$
hosts.exe<注意路径是开始--程序--运行--hosts.exe>
run.bat<注意路径是开始--程序--运行--run.bat>
KB2059102.LOG
C:\WINDOWS\System32\DLMain.dll
C:\WINDOWS\systemrundll.exe
C:\WINDOWS\G_Server.exe
C:\WINDOWS\G_Server2.0.exe
C:\WINDOWS\SYSYTEM32.exe
在硬盘中搜索G_Server.dll
G_Serverkey.dll
G_Server_hook.dll
G_Server2.0.dll
G_Server2.0key.dll
G_Server2.0_hook.dll
SYSYTEM32.dll
SYSYTEM32key.dll
SYSYTEM32_hook.dll
找到后全部删除
找不到文件请参考图片设置
附件:
364052200622185910.JPG