【回复“baggioshan”的帖子】
结束C:\Program Files\Common Files\COMM\Network.exe进程
修复
O2 - BHO: QuickBtn - {1A199C20-DE2B-4838-AE3F-B5257ECE2B7E} - C:\Program Files\CoolWebsite\QuickLink.dll
O4 - 启动项HKLM\\Run: [Update] C:\Program Files\Common Files\UPDATE\Update.exe
O4 - 启动项HKLM\\Run: [res] C:\WINDOWS\system32\res.exe
O20 - AppInit_DLLs: 919331AppInit.DLL
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\G_Server.exe
O23 - NT 服务: lsass - Unknown owner - C:\WINDOWS\lsass.exe (file missing)
O23 - NT 服务: Messenger - Unknown owner - C:\WINDOWS\system32\xmoz.exe
O23 - NT 服务: Pigeon_Server (PigeonServer) - Unknown owner - C:\WINDOWS\G_Server.exe
O23 - NT 服务: Network System (Universal Disk Manager) - COMENET TECHNOLOGY - C:\Program Files\Common Files\COMM\Network.exe
卸载
C:\Program Files\CoolWebsite
进入注册表
搜索lsass.exe
找到后删除
注意路径是C:\WINDOWS\lsass.exe
删除
C:\Program Files\CoolWebsite文件夹
C:\Program Files\Common Files\UPDATE文件夹
C:\WINDOWS\system32\res.exe
919331AppInit.DLL
C:\WINDOWS\system32\xmoz.exe
C:\WINDOWS\G_Server.exe
C:\Program Files\Common Files\COMM文件夹
在硬盘中搜索G_Server.dll
G_Serverkey.dll
G_Server_hook.dll
找到后全部删除
================
ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
这一项服务是正常的