控制面板--管理工具--服务--查找Svchost Service For Windows ,,ATI Smart --启动类型--禁止这二个服务
运行HIJACKTHIS,把下面的选中打上钩,修复
O4 - HKLM\..\Run: [WMC_AutoUpdate] 8V?
O4 - HKCU\..\Run: [sys001] C:\windows\winlog.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll
O18 - Protocol: mbox - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll
O21 - SSODL: DVDBurn - {790448C3-4239-45AF-C98B-367991A8B103} - C:\WINDOWS\Downloaded Program Files\AfxEdit.dll (file missing)
O21 - SSODL: DLMon - {590498A3-4131-4D8F-BA4B-36791A0803B1} - C:\WINDOWS\system32\DLMain.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - (no file)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Svchost Service For Windows (svchost) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
删除
C:\WINDOWS\svchost.exe
C:\windows\winlog.exe
请按九楼的方法使用超级兔子,重启后,请扫描上来