结束进程:C:\Program Files\Common Files\COMM\Network.exe
修复:
R3 - URLSearchHook: SgUrlSearHook Class - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - C:\WINDOWS\system32\socul.dll
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_1100.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: HB
Object Class - {AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} - C:\PROGRA~1\HBClient\tbhelper.dll
O4 - 启动项HKLM\\Run: [RichMedia] C:\WINDOWS\system32\Rundll32.exe "C:\PROGRA~1\HBClient\tbhelper.dll",WaitWindows
O4 - 启动项HKLM\\Run: [supdate2.dll] RUNDLL32.EXE C:\WINDOWS\system32\supdate2.dll,Run
O4 - 启动项HKLM\\Run: [WINS] C:\WINDOWS\guanggao.exe
O4 - 启动项HKLM\\Run: [spoolsv] C:\WINDOWS\system32\spoolsv\spoolsv.exe -printer
O8 - IE右键菜单中的新增项目: >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O9 - 浏览器额外的按钮: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - 浏览器额外的“工具”菜单项: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O23 - NT 服务: Network System (Universal Disk Manager) - COMENET TECHNOLOGY - C:\Program Files\Common Files\COMM\Network.exe
O23 - NT 服务: Network Management Center Task (W32Tasks) - Unknown owner - C:\WINDOWS\system32\taskman32.exe
卸载:
C:\PROGRA~1\MMSASS~1\
C:\PROGRA~1\HBClient\
删除:
C:\PROGRA~1\MMSASS~1\(文件夹,下同)
C:\PROGRA~1\HBClient\
C:\WINDOWS\system32\socul.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_1100.dll
C:\WINDOWS\SYSTEM32\stdup.dll
C:\WINDOWS\guanggao.exe
C:\Program Files\Common Files\COMM\
C:\WINDOWS\system32\taskman32.exe
C:\WINDOWS\system32\spoolsv\
C:\WINDOWS\SYSTEM32\stdup.dll若删不掉则参考
http://forum.ikaka.com/topic.asp?board=67&artid=7423269C:\PROGRA~1\HBClient\是很棒小秘书流氓软件,参考
http://forum.ikaka.com/topic.asp?board=28&artid=7795226C:\WINDOWS\system32\spoolsv\的处理请务必参考
http://forum.ikaka.com/topic.asp?board=28&artid=7948848将里面列的所有项目删除干净。
最后也是最重要的:
O23 - NT 服务: Network Management Center Task (W32Tasks) - Unknown owner - C:\WINDOWS\system32\taskman32.exe
这一项是灰鸽子,参考
http://forum.ikaka.com/topic.asp?board=28&artid=7713905