这第二个日志看:
你需要干掉下面项目:
启动项目
注册表
<360safe><C:\WINDOWS\Fonts\alg.exe> [360安全中心]
<mysys><C:\Documents and Settings\All Users\OFFLINE\mse.exe> []
<{F1455861-8C40-4095-ABD8-7BEAE5ADF92E}><C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll> []
==================================
驱动程序
[acpidisk / acpidisk][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[dansl / dansl][Stopped/Manual Start]
<\??\C:\WINDOWS\fonts\dansl.sys><N/A>
[pnpmem / pnpmem][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\pnpmem.sys><N/A>
==================================
浏览器加载项
[CAdLogic Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\PushWare\cpush0.dll, >
[Info cache]
{296AB1C6-FB22-4D17-8834-064E2BA0A6F0} <C:\WINDOWS\AMD\google.dll, Hello Loons.Fad>
[google cache]
{296AB1C7-FB22-4D17-8834-064E2BA0A6F0} <C:\WINDOWS\MICROSOFT\winsys.dll, Hello Loons.Fad>
[IETimber]
{489873CE-F3E1-44A3-8E89-04BE26BE4446} <C:\Program Files\Internet Explorer\IETimber\IETimber.dll, (Signed) 北京世纪乾坤软件>
[Yodao Toolbar Helper]
{6516E5BB-1186-4E2B-B8B8-2DC0E35AB1FA} <C:\Program Files\Youdao\Toolbar\ydtbv2.2\YodaoToolbar.dll, (Signed) 网易公司>
[IEFXZ]
{6A49F431-2A2E-41a5-9080-0F41D1A3AEC2} <C:\PROGRA~1\IEfxz\iefxz.dll, >
[IEFXZTool]
{61F0024B-8278-4999-B7E6-2718426D9FE6} <C:\PROGRA~1\IEfxz\iefxz.dll, >
[CAdLogic Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\PushWare\cpush0.dll, >
[Info cache]
{296AB1C6-FB22-4D17-8834-064E2BA0A6F0} <C:\WINDOWS\AMD\google.dll, Hello Loons.Fad>
[google cache]
{296AB1C7-FB22-4D17-8834-064E2BA0A6F0} <C:\WINDOWS\MICROSOFT\winsys.dll, Hello Loons.Fad>
[IETimber]
{489873CE-F3E1-44A3-8E89-04BE26BE4446} <C:\Program Files\Internet Explorer\IETimber\IETimber.dll, (Signed) 北京世纪乾坤软件>
[IEFXZHelper]
{6A49F431-2A2E-41A5-9080-0F41D1A3AEC1} <C:\PROGRA~1\IEfxz\iefxz.dll, >
[IEFXZ]
{6A49F431-2A2E-41A5-9080-0F41D1A3AEC2} <C:\PROGRA~1\IEfxz\iefxz.dll, >
[有道搜索(&Y)]
<res://C:\Program Files\Youdao\Toolbar\ydtbv2.2\YodaoToolbar.dll/158.htm, N/A>
你需要干掉下面文件,请一定要将文件提取压缩发来看:
C:\WINDOWS\Fonts\alg.exe
C:\Documents and Settings\All Users\OFFLINE\mse.exe
C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll
C:\WINDOWS\system32\drivers\acpidisk.sys
C:\WINDOWS\fonts\dansl.sys
C:\WINDOWS\system32\drivers\pnpmem.sys
C:\Program Files\Common Files\PushWare\cpush0.dll
C:\WINDOWS\AMD\google.dll
C:\WINDOWS\MICROSOFT\winsys.dll
C:\PROGRA~1\IEfxz\iefxz.dll
C:\WINDOWS\system32\winlib .dll
C:\WINDOWS\system32\syslib .dll
C:\WINDOWS\system32\Rwad8sdv4e7V8xpKZ.dll
C:\WINDOWS\system32\A2Mon.dll
C:\WINDOWS\system32\A6Mon.dll
C:\WINDOWS\system\Noy53.tmp
C:\WINDOWS\system32\LINKINFO.dll
C:\Documents and Settings\All Users\OFFLINE\httpapi.dll
C:\Documents and Settings\All Users\OFFLINE\mse.exe
C:\WINDOWS\Fonts\tencent.exe
C:\WINDOWS\system32\360trav.exe
C:\Autorun.inf
C:\EOPA.PIF
D:\Autorun.inf
D:\EOPA.PIF
E:\Autorun.inf
E:\EOPA.PIF
F:\Autorun.inf
注意C:\WINDOWS\system32\LINKINFO.dll文件已经不是系统原始文件了。得找原始系统文件替换此文件。
可以在C:\WINDOWS\system32\dllcache文件夹内找找。
还有这文件夹内是什么宝贝东西呢??离它不过日子吗???
D:\1\KuGou2008\