O4 - HKLM\..\Run: [miniserver] C:\WINDOWS\system32\com\miniserver.exe
O4 - HKLM\..\Run: [MSService_v1.0] C:\WINDOWS\system32\vfp02.exe
O4 - HKLM\..\Run: [hcd4wm] RunDll32 "C:\WINDOWS\Downlo~1\zdkofo.dll",Run
O4 - HKLM\..\Run: [Winrun] C:\WINDOWS\bqq.exe
O4 - HKLM\..\Run: [rundll32] C:\WINDOWS\system32\IEXPLORER.EXE
O4 - HKLM\..\Run: [downs] C:\WINDOWS\system32\downs.exe
O4 - HKLM\..\Run: [CnsMHlp.exe] C:\WINDOWS\Downloaded Program files\CnsMHlp.exe
O4 - HKLM\..\Run: [downfile] C:\WINDOWS\system32\downfile.exe
O4 - HKCU\..\Run: [msq] C:\Program Files\Internet Explorer\PLUGINS\101344.exe
O4 - Startup: 地址栏搜索.lnk = C:\Documents and Settings\klhyyyyj\Local Settings\Temp\ebe.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
修复
删除
C:\WINDOWS\system32\com\miniserver.exe
C:\WINDOWS\system32\vfp02.exe
C:\WINDOWS\Downlo~1\zdkofo.dll
C:\WINDOWS\bqq.exe
C:\WINDOWS\system32\IEXPLORER.EXE
C:\WINDOWS\system32\downs.exe
C:\WINDOWS\Downloaded Program files\CnsMHlp.exe
C:\WINDOWS\system32\downfile.exe
C:\Program Files\Internet Explorer\PLUGINS\101344.exe
C:\Documents and Settings\klhyyyyj\Local Settings\Temp\ebe.exe
把所有02项的都修复后删除



这个日志比较汗