F2 - REG:system.ini: UserInit=userinit.exe,C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\geibif.exe
O2 - BHO: RichSoft Internet Explorer Helper - {0E2F5DD8-5B0D-438F-A618-B0403F62636A} - C:\WINDOWS\system32\reshtm.dll
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\system32\wmpdrm.dll
O2 - BHO: IEYHlprObj Class - {5C761D09-377E-4EAC-ADA1-C9CDE39B5674} - C:\WINDOWS\IEYHelper.dll
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O2 - BHO: IEHlprObj Class - {999ADFA2-8AD1-47ff-97FC-69FB847458F4} - C:\Progra~1\NetMeeting\nmview.dll
O2 - BHO: Flash 8 ocx - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\system32\flash8.dll
O4 - HKLM\..\Run: [spoolsv] C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
O4 - HKCU\..\Run: [svc] ; C:\WINDOWS\svchost.exe
修复
删除
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\geibif.exe
C:\WINDOWS\system32\reshtm.dll
C:\WINDOWS\system32\wmpdrm.dll
C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll
C:\WINDOWS\IEYHelper.dll
C:\PROGRA~1\MMSASS~1\mmsass~1.dll
C:\Progra~1\NetMeeting\nmview.dll
C:\WINDOWS\system32\flash8.dll
C:\WINDOWS\svchost.exe
C:\WINDOWS\system32\spoolsv\ 整个文件夹
卸载C:\PROGRA~1\MMSASS~1\
04 - HKLM\..\Run: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
这个是落雪
你有兴趣就参考
http://bbs.ttwv.com/viewthread.php?tid=9159自己搞不定就重装系统