结束如下进程:
C:\DOCUME~1\chi\LOCALS~1\Temp\ho2\ho2.exe
修复
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O4 - 启动项HKLM\\Run: [VCXD Settings] phqg.EXE
O4 - 启动项HKLM\\RunServices: [VCXD Settings] phqg.EXE
O4 - 启动项HKLM\\RunServices: [LOCAL INTERNET WEB DRIVERS FOR WIN32] phqghume.exe
O4 - 启动项HKLM\\RunServices: [WEB DRIVERS FOR WIN32] phqgh.exe
O4 - HKCU\..\Run: [VCXD Settings] phqg.EXE
O8 - IE右键菜单中的新增项目: >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm
O9 - 浏览器额外的按钮: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O9 - 浏览器额外的“工具”菜单项: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
卸载
C:\Program Files\MMSAssist
<若没有卸载程序,这一步不用操作>
删除
C:\Program Files\MMSAssist
C:\DOCUME~1\chi\LOCALS~1\Temp\ho2\ho2.exe
C:\WINDOWS\SYSTEM32\stdup.dll
phqghume.exe
phqgh.exe
phqg.EXE
以及C:\DOCUME~1\chi\LOCALS~1\Temp下的所有文件
stdup.dll无法删除请参考http://forum.ikaka.com/topic.asp?board=67&artid=7423269
找不到文件请参考
附件:
36405220062215219.JPG