R3 - 默认的URLSearchHook丢失。用HijackThis修复
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,devgt.exe
O2 - BHO: BHOHelper Class - {67A90DD5-128D-43AB-B97C-565D2DD42A28} - C:\Program Files\adx\atloader.dll (file missing)
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
修复
O4 - 启动项HKLM\\Run: [Intranet] C:\WINDOWS\intranet.exe
O4 - 启动项HKLM\\Run: [xy] C:\WINDOWS\Download\svhost32.exe
O4 - 启动项HKLM\\Run: [r] C:\WINDOWS\down\rundll32.exe
O4 - 启动项HKLM\\Run: [sys] C:\WINDOWS\Intel\rundll32.exe
O4 - 启动项HKLM\\Run: [mhs2] C:\DOCUME~1\csl\LOCALS~1\Temp\smss.exe
O4 - HKCU\..\Run: [Taskmor.exe] C:\WINDOWS\taskmor.exe
O4 - HKCU\..\Run: [Explore.exe] C:\WINDOWS\explore.exe
O4 - HKCU\..\Run: [svc] C:\DOCUME~1\csl\LOCALS~1\Temp\relpop.exe
修复
删除
C:\WINDOWS\intranet.exe
C:\WINDOWS\Download\svhost32.exe
C:\WINDOWS\down\rundll32.exe
C:\WINDOWS\Intel\rundll32.exe
C:\DOCUME~1\csl\LOCALS~1\Temp\smss.exe
C:\WINDOWS\taskmor.exe
C:\WINDOWS\explore.exe
C:\DOCUME~1\csl\LOCALS~1\Temp\relpop.exe
删除 C:\WINDOWS\Download\ C:\WINDOWS\down\ C:\WINDOWS\Intel\ 这三个文件夹
清空临时文件和TEMP下所有文件
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
修复
O23 - NT 服务: Network Services - Unknown owner - C:\WINDOWS\System\services.exe
O23 - NT 服务: System Set Service (SystemSet) - Unknown owner - C:\WINDOWS\system32\service.exe
O23 - NT 服务: Windows Createddos (Windows Processdos) - Unknown owner - C:\WINDOWS\System32\3721.exe
三只鸽子
到瑞星主页下专杀