楼主的机子是灰鸽子+木马+流氓软件。
修复:
R3 - 默认的URLSearchHook丢失。用HijackThis修复
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\System32\wmpdrm.dll (file missing)
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_8019.dll
O2 - BHO: QuickBtn - {1A199C20-DE2B-4838-AE3F-B5257ECE2B7E} - C:\Program Files\CoolWebsite\QuickLink.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: NewWeb Controller - {9ACEEE30-143F-471A-AA45-72B061FE7D60} - C:\WINDOWS\system32\WinSC.dll
O2 - BHO: IEhlprObj Class - {A3803141-3CF5-4D66-B7EA-8D2674FE152C} - C:\WINDOWS\stdie.dll
O2 - BHO: MacroMediapd - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\System32\microapmddt.dll
O2 - BHO: (no name) - {B9E914B5-6B61-401f-A49F-9E84E547D3DD} - C:\WINDOWS\System32\leftup.dll
O4 - 启动项HKLM\\Run: [SCIntruder.dll] RUNDLL32.EXE C:\WINDOWS\system32\WinSC64.dll,Service
O4 - 启动项HKLM\\Run: [Update] C:\Program Files\Common Files\UPDAT\Update.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O9 - 浏览器额外的按钮: 实用网址导航 - {1D901067-2529-4A9B-9B6B-7A1DB3A44CB5} - C:\Program Files\CoolWebsite\QuickLink.dll
O9 - 浏览器额外的按钮: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - 浏览器额外的“工具”菜单项: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O18 - Filter: text/html - {65CBAF77-19CA-4B81-86D5-7835D59BEA85} - C:\WINDOWS\System32\intel.dll
O23 - NT 服务: COM+ Event Systems - Unknown owner - C:\WINDOWS\rver1.0.exe (file missing)
O23 - NT 服务: PigeonServer - Unknown owner - C:\WINDOWS\winft.bat
O23 - NT 服务: Winserver - Unknown owner - C:\WINDOWS\winserver.pif
O23 - NT 服务: YMAPI CDBurning COM Service - Unknown owner - C:\WINDOWS\MSN.exe
禁用COM+ Event Systems、PigeonServer、Winserver和YMAPI CDBurning COM Service四顶服务,在注册表HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services中删除这四项
卸载:
C:\Program Files\CoolWebsite\
C:\PROGRA~1\MMSASS~1\
重启后删除:
C:\Program Files\CoolWebsite\(表示文件夹,下同)
C:\PROGRA~1\MMSASS~1\
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_8019.dll
C:\WINDOWS\SYSTEM32\stdup.dll
C:\WINDOWS\system32\WinSC.dll
C:\WINDOWS\stdie.dll
C:\WINDOWS\System32\microapmddt.dll
C:\WINDOWS\System32\leftup.dll
C:\WINDOWS\system32\WinSC64.dll
C:\Program Files\Common Files\UPDAT\
C:\WINDOWS\System32\intel.dll
C:\WINDOWS\winft.bat
C:\WINDOWS\winserver.pif
C:\WINDOWS\MSN.exe
其中
O23 - NT 服务: PigeonServer - Unknown owner - C:\WINDOWS\winft.bat
O23 - NT 服务: Winserver - Unknown owner - C:\WINDOWS\winserver.pif
这两项当灰鸽子处理,参考
http://forum.ikaka.com/topic.asp?board=28&artid=7713905C:\WINDOWS\SYSTEM32\stdup.dll若删不掉则参考
http://forum.ikaka.com/topic.asp?board=28&artid=7971417