【回复“qqjljl”的帖子】
结束如下进程:
[svchost.exe]
CommandLine = "C:\WINDOWS\svchost.exe"
[downnew.exe]
CommandLine = "C:\WINDOWS\system32\downnew.exe"
[Systems.exe]
CommandLine = "C:\WINDOWS\system32\Systems.exe"
[outwindow.exe]
CommandLine = "C:\WINDOWS\system32\outwindow.exe"
[downfile.exe]
CommandLine = "C:\WINDOWS\system32\downfile.exe"
[sysmini.exe]
CommandLine = "C:\WINDOWS\system32\sysmini.exe"
[RUNDLL32.EXE]
CommandLine = C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\MMSASS~1\MMSSVER.DLL,Service
[UpdateService.exe]
CommandLine = C:\WINDOWS\system32\UpdateService.exe
[RUNDLL32.EXE]
CommandLine = C:\WINDOWS\system32\rundll32.exe C:\DOCUME~1\ADMINI~1\TEMPLA~1\aa4663f\1.dll,Always
==============
修复
R3 - URLSearchHook: YOK Search Class - {88351CEF-BAC0-4A9B-8380-31A173E2926F} - C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O2 - BHO: Shockwave Flash
Object - {14A21378-5BB1-4BC4-95D5-5D3F51527F6F} - C:\WINDOWS\system32\smflash.ocx
O2 - BHO: C:\WINDOWS\system32\NBBHO.dll
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O2 - BHO: (file missing)
O2 - BHO: YOK超级搜索 - {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} - C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O2 - BHO: CIEHelper
Object - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\system32\ms.dll
O2 - BHO: (file missing)
O3 - Toolbar: YOK超级搜索 - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O4 - HKCU\..\Run: [svc] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [YOKAssiant] Rundll32.exe C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll,YOKAssiant
O4 - HKLM\..\Run: [svc] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [MicrosoftUpdate] C:\WINDOWS\system32\downnew.exe
O4 - HKLM\..\Run: [Systems] C:\WINDOWS\system32\Systems.exe
O4 - HKLM\..\Run: [WindowOut] C:\WINDOWS\system32\outwindow.exe
O4 - HKLM\..\Run: [downfile] C:\WINDOWS\system32\downfile.exe
O4 - HKLM\..\Run: [sysmini] C:\WINDOWS\system32\sysmini.exe
O4 - HKLM\..\Run: [Desktop] C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKLM\..\RunOnce: [{9D0351F9-8E49-4ed1-BBCE-0795F5B9F240}] C:\WINDOWS\system32\richnotify.exe
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O9 - Extra Button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra 'Tools' menuitem: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O21 - SSODL: SysTime - {724C75F1-B757-408D-A50A-4CF99DA35D73} - C:\PROGRA~1\WinKld\WinKld.dll
O21 - SSODL: DelayRun - {5A6F2F95-3191-433B-8533-EB0B596A7BAC} - C:\WINDOWS\system\d9dd3a60.dll
O21 - SSODL: webwork - {4C611512-2C1D-44b2-A044-872AD2AD5A61} - C:\WINDOWS\webwork\webwork.dll
O21 - SSODL: themeadp - {64274C93-3CE7-4663-9C8D-CD2DC8A3590B} - C:\WINDOWS\system32\themeadp.dll
================
开始--控制面板--性能和维护--管理工具--服务
禁用如下服务:
AutoUpgrade (AutoUpgrade)
JMediaService (JMediaService)
COM+ Error Report (Tech)
UpdateService (UpdateService)
XDownloadService (XDownloadService)
开始--运行
输入regedit
确定
进入注册表
依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services](X代表1,2,3,4....)
找到后删除如下文件夹:
AutoUpgrade文件夹
JMediaService文件夹
Tech文件夹
UpdateService文件夹
XDownloadService文件夹
依次展开
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Enum\Root\](X代表1,2,3,4....)
删除如下文件夹:
LEGACY_AutoUpgrade文件夹
LEGACY_JMediaService文件夹
LEGACY_Tech文件夹
LEGACY_UpdateService文件夹
LEGACY_XDownloadService文件夹
===============
断开网络
用LSPFIX修复C:\WINDOWS\system32\quartz32.dll
http://cexx.org/lspfix.htm
下载LSPFix.exe
修复010项中的
修复方法参考图片
注意这次应该选中文件
若用LSPFix.exe修复后还是不能上网
建议用WinsockFix修复注册表
WinsockFix下载:
http://www.winsockfix.nl/
==============
卸载
C:\Program Files\MMSASSIST\
C:\Program Files\WinKld\
C:\Program Files\YOK.com\
C:\Program Files\DeskAdTop\
============
删除
C:\Program Files\MMSASSIST\
C:\Program Files\WinKld\
C:\Program Files\YOK.com\
C:\Program Files\DeskAdTop\
C:\WINDOWS\system32\smflash.ocx
C:\WINDOWS\system32\NBBHO.dll
C:\WINDOWS\system32\ms.dll
C:\WINDOWS\svchost.exe
C:\WINDOWS\system32\downnew.exe
C:\WINDOWS\system32\Systems.exe
C:\WINDOWS\system32\outwindow.exe
C:\WINDOWS\system32\downfile.exe
C:\WINDOWS\system32\sysmini.exe
C:\WINDOWS\system32\richnotify.exe
C:\WINDOWS\system\d9dd3a60.dll
C:\WINDOWS\webwork\webwork.dll
C:\WINDOWS\system32\themeadp.dll
c:\windows\downloader.dll
C:\WINDOWS\system32\updateservice.exe
C:\DOCUME~1\ADMINI~1\TEMPLA~1\aa4663f\1.dll
C:\DOCUME~1\ADMINI~1\TEMPLA~1\aa4663f\
C:\WINDOWS\webwork\
=============
提示:
若正常模式下无法解决
建议进入安全模式下操作
附件:
3640522006817183955.jpg