运行Hijackthis,选择"扫描系统并保存日志",在下列选项前打上勾,点“修复选项”,出现提示时点“是”
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - Startup: desktop.ini
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O23 - NT 服务: 1eass - Unknown owner - C:\WINDOWS\leasss.exe
O23 - NT 服务: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe (file missing)
O23 - NT 服务: windows software - Unknown owner - C:\WINDOWS\windows software.exe
修复后;解压ha-killbox20017+.rar,运行并删除:
C:\WINDOWS\leasss.exe
C:\WINDOWS\windows software.exe