O4 - 启动项HKLM\\Run: [Realplayer.exe] C:\WINDOWS\system32\Realplayer.exe
参考顶置...
O23 - NT 服务: Gray_Pigeon_Server1.23 (GrayPigeonServer1.23) - Unknown owner - C:\WINDOWS\G_Server1.23.exe
O23 - NT 服务: host Service For Windows (mshost) - Unknown owner - C:\WINDOWS\mshost.exe (file missing)
安全模式...打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索GrayPigeonServer1.23和mshost 删除..
删除
C:\WINDOWS\G_Server1.23.exe
修复
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4877.dll
O2 - BHO: (no name) - {4BBC1A4D-DD20-4980-A645-2E13F6FC286D} - C:\WINDOWS\system32\3721.1.dll
O2 - BHO: (no name) - {669751ED-D558-49AE-B01A-3B374CC7910E} - C:\WINDOWS\system32\ssup.dll
O2 - BHO: NkkGmujz Class - {7D75E27D-8538-1C29-EDEF-C1BED6568817} - C:\WINDOWS\DOWNLO~1\teqbta.dll
O2 - BHO: NewWeb Controller - {9ACEEE30-143F-471A-AA45-72B061FE7D60} - C:\WINDOWS\system32\AdvSC32.dll (file missing)
O2 - BHO: NewWeb Controller - {9ACEEE31-1440-471B-AA46-72B061FE7D61} - C:\WINDOWS\system32\WinSC.dll (file missing)
O2 - BHO: estAliveObj Class - {A2B7A0F0-B697-4A71-8D91-43443F57D7BB} - C:\WINDOWS\estAlive.dll
O2 - BHO: Flash 8 ocx - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\system32\flash8.dll
O3 - IE工具栏增项: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - 启动项HKLM\\Run: [zt] C:\Program Files\Intel\rundll32.exe
O4 - 启动项HKLM\\Run: [Tray] C:\WINDOWS\command\rundll32.exe
删除
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4877.dll
C:\WINDOWS\system32\3721.1.dll
C:\WINDOWS\system32\ssup.dll
C:\WINDOWS\DOWNLO~1\teqbta.dll
C:\WINDOWS\estAlive.dll
C:\WINDOWS\system32\flash8.dll
C:\Program Files\Intel\rundll32.exe
C:\WINDOWS\command\rundll32.exe
http://www.pctutu.com/srmsdown.asp
下载超级兔子..用超级兔子清理王卸载流氓软件...(安全模式...)