O1 - Hosts: 124.238.254.113
www.10280011.com
O1 - Hosts: 124.238.254.113 10280011.com
O1 - Hosts: 124.238.254.113
www.10289900.com
O1 - Hosts: 124.238.254.113 10289900.com
O1 - Hosts: 124.238.254.113
www.78877788.com
O1 - Hosts: 124.238.254.113 78877788.com
O1 - Hosts: 124.238.254.113
www.11051122.com
O1 - Hosts: 124.238.254.113 11051122.com
O1 - Hosts: 124.238.254.113 1.ehai01.com
O1 - Hosts: 124.238.254.113 da.ehai01.com
O1 - Hosts: 124.238.254.113 ehai01.com
O1 - Hosts: 124.238.254.113 2008.sekart.cn
O1 - Hosts: 124.238.254.113
www.sekart.cn
O1 - Hosts: 124.238.254.113 sekart.cn
O1 - Hosts: 124.238.254.113
www.11309988.com
O1 - Hosts: 124.238.254.113
www.12100088.com
O1 - Hosts: 124.238.254.113
www.12108899.com
O1 - Hosts: 124.238.254.113 d2.llsging.com
O1 - Hosts: 124.238.254.113 llsging.com
O1 - Hosts: 124.238.254.113 dd.749571.com
O1 - Hosts: 124.238.254.113 749571.com
O1 - Hosts: 124.238.254.113 pr.749571.com
O1 - Hosts: 124.238.254.113 txwm1204.com
O1 - Hosts: 124.238.254.113
www.txwm1204.com
O2 - BHO: (no name) - {471B15AD-7A9C-491D-9C19-4E15B12DCE00} - C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Sys
O2 - BHO: (no name) - {4B23A8E5-CC9C-4A15-81F3-9B902C00AF4B} - C:\Program Files\Internet Explorer\PLUGINS\NvSys_55.Sys
O2 - BHO: (no name) - {9963387B-212E-4643-B207-82DAEA0E713D} - C:\Program Files\Internet Explorer\PLUGINS\Wn_Sys8x.Sys
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinForm] C:\WINDOWS\WinForm.exE
O4 - HKLM\..\Run: [WSockDrv32] C:\WINDOWS\WSockDrv32.exe
O4 - HKLM\..\Run: [Kvsc3] C:\WINDOWS\Kvsc3.exE
O4 - HKLM\..\Run: [AVPSrv] C:\WINDOWS\AVPSrv.exE
O4 - HKLM\..\Run: [mppds] C:\WINDOWS\mppds.exe
O4 - HKLM\..\Run: [DbgHlp32] C:\WINDOWS\DbgHlp32.exe
O4 - HKLM\..\Run: [MsPrint32D] C:\WINDOWS\gzpzjq.exe
O4 - HKLM\..\Run: [upxdnd] C:\WINDOWS\upxdnd.exe
O4 - HKLM\..\Run: [cmdbcs] C:\WINDOWS\cmdbcs.exe
O4 - HKLM\..\Run: [WinSysM] C:\WINDOWS\455373M.exe
O4 - HKLM\..\Run: [MsIMMs32] C:\WINDOWS\MsIMMs32.exE
O4 - HKLM\..\Run: [PTSShell] C:\WINDOWS\PTSShell.exe
O4 - HKLM\..\Run: [LotusHlp] C:\WINDOWS\LotusHlp.exe
O4 - HKLM\..\Run: [NVDispDrv] C:\WINDOWS\vpbuhx.exe
O4 - HKLM\..\Run: [NAVMon32] C:\WINDOWS\NAVMon32.exE
O4 - HKLM\..\Run: [WINSvr32] C:\WINDOWS\WINSvr32.exE
O4 - HKLM\..\Run: [RegSrv64D] C:\WINDOWS\vxrbdy.exe
O4 - HKLM\..\Run: [WinSysW] C:\WINDOWS\455373L.exe
O4 - HKLM\..\Run: [msccrt] C:\WINDOWS\msccrt.exe
O4 - HKLM\..\Run: [SHAProc] C:\WINDOWS\SHAProc.exe
O4 - HKLM\..\Run: [TBMonEx] C:\WINDOWS\Fonts\system\ati2evxx.EXE
O4 - HKLM\..\Run: [inudhya] C:\WINDOWS\Fonts\system\soundma.exe
O4 - HKLM\..\Run: [WSockx2_32] C:\WINDOWS\ylwuyd.exe
O4 - HKLM\..\Run: [InternetExe] C:\Documents and Settings\Administrator\motou.exe
O4 - HKLM\..\Run: [kermer] C:\WINDOWS\FONTS\SYSTEM\DD.EXE
O4 - HKLM\..\Run: [kkaddmin] C:\WINDOWS\FONTS\SYSTEM\FBD.EXE
O4 - HKLM\..\Run: [SSLDyn] C:\WINDOWS\SSLDyn.exE
O4 - HKLM\..\Policies\Explorer\Run: [zfyrspnum] zfyrspnum.exe
O23 - Service: 8F4CCCCD - Unknown owner - C:\WINDOWS\system32\A3BF51DF.EXE
嘆為觀止.....
勾選並修復上述項目
P.S
裝套防毒軟體. 掃描一次, 把病毒檔案全部清除
若嫌麻煩, 那就....format + 重裝作業系統吧