结束C:\WINDOWS\System32\dll.exe进程
修复
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\System32\wmpdrm.dll
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_8160.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O2 - BHO: BHelper - {8A4280AD-9B37-4922-A51D-73F3C3A32AF7} - C:\WINDOWS\System32\msibm\cfsbho.dll
O2 - BHO: DownloadBHO T2BHO - {B1D147E7-873E-4909-8127-695D9BB78728} - C:\WINDOWS\Downloaded Program Files\barhelp24.0.dll
O3 - IE工具栏增项: 天下搜索 - {56A7DC70-E102-4408-A34A-AE06FEF01586} - C:\WINDOWS\Downloaded Program Files\iebar23.0.dll
O3 - IE工具栏增项: 电鹰工具栏 - {1BC0B497-3010-43BF-AD78-5858A70907A2} - c:\windows\system32\dytoolband.dll
O4 - 启动项HKLM\\Run: [spoolsv] C:\WINDOWS\System32\spoolsv\spoolsv.exe -printer
O4 - 启动项HKLM\\Run: [mscfs] RUNDLL32 C:\WINDOWS\System32\msibm\cfsys.dll,cfs
O8 - IE右键菜单中的新增项目: >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O9 - 浏览器额外的按钮: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - 浏览器额外的“工具”菜单项: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O15 - “受信任的站点”中添加项: http://www.icbc.com.cn
O23 - NT 服务: system32 - Unknown owner - C:\WINDOWS\system32.exe
卸载
C:\Program Files\MMSAssist
删除
C:\Program Files\MMSAssist
C:\WINDOWS\System32\wmpdrm.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_8160.dll
C:\WINDOWS\System32\msibm\cfsbho.dll
C:\WINDOWS\Downloaded Program Files\barhelp24.0.dll
C:\WINDOWS\Downloaded Program Files\iebar23.0.dll
c:\windows\system32\dytoolband.dll
C:\WINDOWS\System32\spoolsv\spoolsv.exe
C:\WINDOWS\System32\msibm\cfsys.dll
C:\WINDOWS\system32.exe
在硬盘中搜索system32.dll
system32key.dll
system32_hook.dll
找到后全部删除
C:\WINDOWS\System32\dll.exe
================
文件找不到或无法删除请参考
http://www.xfilt.com/tech/trojan-horse.htm
另外图片参考
附件:
36405220062360028.JPG