【回复“小太猫”的帖子】
重启按F8进入安全模式,运行hijackthis修复:
R3 - Default URLSearchHook is missing
F1 - win.ini: run=C:\WINDOWS\SYSTEM\1.exe
O4 - HKLM\..\Run: [url] http://www.dj-mtv.com
O4 - HKCU\..\Run: [IEXPLORE.EXE] IEXPLORE.EXE www.haoyy.net
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\RunServices: [SVCHOST] C:\WINDOWS\SYSTEM\SVCH0ST.EXE(注意“SVCH0ST”中字母‘H’与‘S’之中是数字‘0’)
O4 - HKCU\..\Run: [IEXPLORE.EXE] IEXPLORE.EXE www.haoyy.net
O4 - HKCU\..\Run: [security.exe] C:\WINDOWS\security.exe
O4 - HKCU\..\RunServices: [IEXPLORE.EXE] IEXPLORE.EXE www.haoyy.net
O4 - HKCU\..\RunServices: [security.exe] C:\WINDOWS\security.exe
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} (天下搜索) - http://iebar.t2t2.com/iebar.cab
显示隐藏文件,找到以下删除:
C:\WINDOWS\SYSTEM\1.exe
C:\WINDOWS\SYSTEM\SVCH0ST.EXE(注意“SVCH0ST”中字母‘H’与‘S’之中是数字‘0’)
C:\WINDOWS\security.exe