R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)
R3 - URLSearchHook: SgUrlSearHook Class - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - C:\WINDOWS\system32\socul.dll
O1 - Hosts: 255.0.0.1 www.wg2046.com
O1 - Hosts: 255.0.0.1 wg2046.com
O2 - BHO: (no name) - {35980F6E-A137-4E50-953D-813BB8556899} - (no file)
O2 - BHO: 360搜 - {472101C2-1109-43f4-9112-31F33E3F2127} - (no file)
O2 - BHO: IeControler Class - {9AFD91F9-6B03-4D22-A1E1-67D224CB7AB1} - C:\Downloads\IEMate.dll (file missing)
O4 - HKLM\..\Run: [dmastu] rundll32.exe C:\PROGRA~1\DESKTO~1\Cast\dmipn.dll,Always
O4 - HKLM\..\Run: [360Main.exe] C:\PROGRA~1\360so\360Main.exe
O4 - HKCU\..\Run: [a6b6edb36a5ac12e3c648924c3c698b4] "C:\Downloads\d120jx210.12012.0.exe" -t 12012.0
O23 - Service: Pigeon_Server (PigeonServer) - Unknown owner - C:\WINDOWS\Server.exe (file missing)
卸载:
C:\PROGRA~1\DESKTO~1\
C:\PROGRA~1\360so\
删除:
C:\PROGRA~1\DESKTO~1\
C:\PROGRA~1\360so\
C:\WINDOWS\system32\socul.dll
C:\Downloads\d120jx210.12012.0.exe
O23 - Service: Pigeon_Server (PigeonServer) - Unknown owner - C:\WINDOWS\Server.exe (file missing)
这项是灰鸽子的残余注册表项。主程序应该是没了,但是其他dll文件可能还在,注册表项也没有清干净。参考
http://forum.ikaka.com/topic.asp?board=28&artid=7713905