【回复“星际幻想”的帖子】
O1 - Hosts: 59.36.96.156 www.wg581.com
O2 - BHO: CpapView Class - {77962960-536E-47EC-9DDB-52651519705F} - C:\WINDOWS\system32\cpap.dll
O2 - BHO: XBTP05119 - {B6E5299F-7521-4433-A563-5B3236E95E72} - C:\WINDOWS\DOWNLO~1\tbu1F\bysoo.dll
O3 - Toolbar: Bysoo Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\WINDOWS\DOWNLO~1\tbu1F\bysoo.dll
O4 - HKLM\..\Run: [_rx] C:\WINDOWS\rundll32.exe
O4 - HKCU\..\Run: [HideFolder] C:\WINDOWS\system32\HideFolder\HideFolder.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O15 - Trusted Zone: easyabc.95599.cn
O15 - Trusted Zone: www.95599.cn
O16 - DPF: {18226BF8-DC0B-4D81-80E9-A41AE37BB73A} (EWA Control) - http://ftp.116.com.cn/p2ptest/SynaLiveSetup.exe
O16 - DPF: {2DCEAEFB-ABD9-490F-894B-E7A99103CD06} (Echat2 Class) - http://chat.a8.com/cab/A8KSong.CAB
O16 - DPF: {87CCFDB0-C4BE-4BC2-A78C-9EAA7CF96667} (pcastup Class) - http://ps.itv.mop.com/dn/files/vodupdate_1.0.0.8_20051009.cab
O16 - DPF: {8CF01FD9-23BC-42DC-B371-8DD53EFF53C7} (Accompany Class) - http://www.a8.com/hfq/recorder/A8Record.CAB
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) - http://static.zangocash.com/cab/Seekmo/ie/bridge-c15.cab
O16 - DPF: {A8497454-CB7D-4877-A633-3932BF776A6A} (Webinstall Control) - http://211.214.161.198/downloads/one/one007/OneSetup.cab
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown4.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
Object) - http://202.99.232.33/cabs/swflash.cab
O16 - DPF: {D39A7678-3647-45FA-8E7B-727E9984BAC7} - http://dl.bysoo.com/bysooTBV10/bysoo.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} (SAIX) - http://static.zangocash.com/cab/Seekmo/ie/bridge-c15.cab?a0dbba5079a7604e4c93f4ab8f2582a5854f3a49c786c57500b463da4ed0c12aeffcd5d5e34f57ce9695b84fb9dfe7e7348cac9fd26416455c00170142:f5bc481adedbecd5174fbce3a1105f83
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl
Object) - https://www.tenpay.com/download/qqedit.cab
O16 - DPF: {F553811C-C2CE-4A33-90B4-A6D333FDF794} (DreamSetup Control) - http://58.18.51.251/ddvod/user/help/player/DreamPlayer/DreamSetup.cab
O23 - Service: Open Search Keyword Services (ossvc) - Brainnames - C:\WINDOWS\system32\ossvc.exe
O23 - Service: Ineterner Explorer Add Update Services (updatecheck) - Brainnames - C:\WINDOWS\system32\ieaus.exe
用HijackThis修复以上各项。
重启系统。显示隐藏文件。
删除:
C:\WINDOWS\system32\ossvc.exe
C:\WINDOWS\system32\SCHAS.EXE
C:\WINDOWS\system32\ieaus.exe
C:\WINDOWS\system32\cpap.dll
C:\WINDOWS\DOWNLO~1\tbu1F\bysoo.dll
C:\WINDOWS\DOWNLO~1\tbu1F\bysoo.dll
C:\WINDOWS\rundll32.exe
C:\WINDOWS\system32\HideFolder\HideFolder.exe
用LSPFix修复O10项。

