重启时按F8键,选safe mode 进安全模式
修复:
R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)
R3 - URLSearchHook: SgUrlSearHook Class - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - C:\WINDOWS\system32\socul.dll
O2 - BHO: QuickBtn - {1A199C20-DE2B-4838-AE3F-B5257ECE2B7E} - C:\Program Files\CoolWebsite\QuickLink.dll
O4 - HKLM\..\Run: [SonudMan] C:\WINDOWS\system32\WNILOGON.exe
O23 - Service: Network System (Universal Disk Manager) - COMENET TECHNOLOGY - C:\Program Files\Common Files\COMM\Network.exe
删除:
C:\WINDOWS\system32\socul.dll
文件夹C:\Program Files\CoolWebsite\
C:\WINDOWS\system32\WNILOGON.exe(注意不是:winlogon)
文件夹C:\Program Files\Common Files\COMM\
如果有不言放弃朋友说得QW.EXE也删了
楼主居然把hijackthis放在外挂里面

建议搂住不要用外挂,那东西绑毒挺多