处理建议:
用SREng在“启动项目”-“注册表”中删除以下项目:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<MoveSearch><C:\Program Files\HuaCi\huaci\zsearch.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Desktop><C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<q404uzfu><RunDll32 "C:\WINDOWS\Downlo~1\q404uzfu.dll",Boot>
在“系统修复”-“浏览器加载项”中删除以下项目:
[MonitorURL Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, >
[MyIEHelper Class]
{16A770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper200651_8888.dll, Microsoft Corporation>
[QuickBtn]
{1A199C20-DE2B-4838-AE3F-B5257ECE2B7E} <C:\Program Files\CoolWebsite\QuickLink.dll, Fengcent>
[MMSAssist BHO]
{6671A431-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[Helper Class]
{6E28339B-7A2A-47B6-AEB2-197004272379} <C:\WINDOWS\vchelper.dll, >
[CpapView Class]
{77962960-536E-47EC-9DDB-52651519705F} <C:\WINDOWS\system32\cpap.dll, >
[win32core Class]
{A297EEAE-A541-496B-B2AE-554AD0153B72} <C:\WINDOWS\system32\win32help02.dll, >
[IEhlprObj Class]
{A3803141-3CF5-4D66-B7EA-8D2674FE152C} <C:\WINDOWS\stdie.dll, >
[QuickBtn]
{1D901067-2529-4A9B-9B6B-7A1DB3A44CB5} <C:\Program Files\CoolWebsite\QuickLink.dll, Fengcent>
[MMSAssistMenu]
{6671A433-5C3D-463d-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[MonitorURL Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, >
[MyIEHelper Class]
{16A770A0-0E87-4278-B748-2460D64A8386} <C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper200651_8888.dll, Microsoft Corporation>
[QuickBtn]
{1A199C20-DE2B-4838-AE3F-B5257ECE2B7E} <C:\Program Files\CoolWebsite\QuickLink.dll, Fengcent>
[NaviHelperObj Class]
{3E422F49-1566-40D3-B43D-077EF739AC32} <C:\WINDOWS\system32\NaviHelper.dll, N/A>
[Search Class]
{594BE7B2-23B0-4FAE-A2B9-0C21CC1417CE} <C:\PROGRA~1\HuaCi\huaci\searchm.dll, >
[MMSAssist BHO]
{6671A431-5C3D-463D-A7CF-5587F9B7E191} <C:\PROGRA~1\MMSASS~1\Mmsass~1.dll, >
[Helper Class]
{6E28339B-7A2A-47B6-AEB2-197004272379} <C:\WINDOWS\vchelper.dll, >
[CpapView Class]
{77962960-536E-47EC-9DDB-52651519705F} <C:\WINDOWS\system32\cpap.dll, >
[win32core Class]
{A297EEAE-A541-496B-B2AE-554AD0153B72} <C:\WINDOWS\system32\win32help02.dll, >
[ >> 彩信发送 <<]
<res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm, N/A>
[>>彩信发送<<]
<res://C:\Program Files\MMSAssist\Mmsass~1.dll/mms.htm, N/A>
卸载:
C:\Program Files\HuaCi\
C:\Program Files\DeskAdTop\
C:\Program Files\CoolWebsite\
C:\PROGRA~1\MMSASS~1\
重启后删除:
C:\Program Files\HuaCi\(表示文件夹,下同)
C:\Program Files\DeskAdTop\
C:\Program Files\CoolWebsite\
C:\PROGRA~1\MMSASS~1\
C:\WINDOWS\Downlo~1\q404uzfu.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper200651_8888.dll
C:\WINDOWS\vchelper.dll
C:\WINDOWS\system32\cpap.dll
C:\WINDOWS\system32\win32help02.dll
C:\WINDOWS\stdie.dll
C:\WINDOWS\system32\NaviHelper.dll
除此之外:
在SREng的“启动项目”-“服务”中的这一项:
[Security Machine Manager / MOBILL]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
处理方法参考http://forum.ikaka.com/topic.asp?board=28&artid=7946351
“注册表”中
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SearchNet_Up><"C:\Program Files\SearchNet\ServeUp.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<CdnCtr><>
“浏览器加载项”中
[Remote Log / Remote Log]
<system32\ServeHost.exe><北京中搜在线软件有限公司>
[Zhongsou Browser Helper]
{2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[Zhongsou Browser Helper]
{2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[IE Browser Helper]
{3CE496D1-1746-41CD-9489-3C0B93DF10E2} <C:\WINDOWS\Downlo~1\nvlxt.dll, 中搜在线软件有限公司>
这些项目的详细处理参考http://forum.ikaka.com/topic.asp?board=28&artid=8049319
“服务”中的:
[StdService / StdService]
<C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\STDSVER.DLL,Service><N/A>
“浏览器加载项”中的:
[std software]
{6A512BF7-EC78-4e8d-9841-6C02E8FA9838} <C:\WINDOWS\SYSTEM32\stdup.dll, MStdup Co Ltd.>
[std software]
{6A512BF7-EC78-4E8D-9841-6C02E8FA9838} <C:\WINDOWS\SYSTEM32\stdup.dll, MStdup Co Ltd.>
这些项目的详细处理参考http://forum.ikaka.com/topic.asp?board=28&artid=7971417
“注册表”中的:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<mscfs><RUNDLL32 C:\WINDOWS\system32\msibm\cfsys.DLL,cfs>
“浏览器加载项”中的:
[CBHelper
Object]
{8A4280AD-9B37-4922-A51D-73F3C3A32AF7} <C:\WINDOWS\system32\msibm\cfsbho.dll, N/A>
[CBHelper
Object]
{8A4280AD-9B37-4922-A51D-73F3C3A32AF7} <C:\WINDOWS\system32\msibm\cfsbho.dll, N/A>
这些项目的详细处理参考http://forum.ikaka.com/topic.asp?board=28&artid=7948848
以上有参考帖子的项目,由于参考的帖子中的方法已讲得很详细,在此不再赘述,请楼主仔细参考那些帖子。
总结:楼主的机子的确成了以上流氓软件和广告插件的安乐窝了……