O23 - NT 服务: onServer (nServer) - Unknown owner - C:\WINDOWS\system.dll
灰鸽子..安全模式...打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索 nServer 删除...
删除
C:\WINDOWS\system.dll
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\IEHelper\IEHelper_0400.dll (file missing)
参考:http://csc.rising.com.cn/KnowledgeBase/detailInfo.aspx?Action=ViewInfo&InfoID=718&Channel=RSV
[Ken32 Driver Service / Ken32 Driver Service]
<C:\WINDOWS\System32\SVCH0ST><N/A>
灰鸽子..安全模式...打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索 Ken32 Driver Service 删除...
删除
C:\WINDOWS\System32\SVCH0ST
用sreng
删除启动项目=>注册表
<RavUpes><C:\WINDOWS\system32\agetltfes.exe> [N/A]
<RavUpsr><C:\WINDOWS\system32\agetltfets.exe> [N/A]
<{F3D0D422-CE6D-47B3-9CE6-C54DD63F1ADB}><C:\Program files\Internet Explorer\PLUGINS\new123.sys> [N/A]
<{25E1EECB-E580-4032-97A2-A456D33820D1}><C:\Program Files\Outlook Express\mqq.dll> [N/A]
<{8A238B14-A6FF-11E0-9A84-00C04FD8DBD8}><C:\WINDOWS\system32\sysldr.dll> [N/A]
<{08315C1A-9BA9-4B7C-A432-26885F78DF28}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp> [N/A]
删除
C:\WINDOWS\system32\agetltfes.exe
C:\WINDOWS\system32\agetltfets.exe
C:\Program files\Internet Explorer\PLUGINS\new123.sys
C:\Program Files\Outlook Express\mqq.dll
C:\WINDOWS\system32\sysldr.dll
C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysInfo.wmp