瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】发现新的顽固软件更本无法删除,请专家帮忙啊.

12   2  /  2  页   跳转

【求助】发现新的顽固软件更本无法删除,请专家帮忙啊.

晕,O23 - Service: Resin Web Server (Resin) - Unknown owner - C:\sfda_licence\resin\bin\httpd.exe" -service -env-classpath "C:\DOCUME~1\何志捷\LOCALS~1\Temp\I1151830875\InstallerData\IAClasses.zip;C:\DOCUME~1\何志捷\LOCALS~1\Temp\I1151830875\Windows\resource\jdglue.zip;C:\DOCUME~1\何志捷\LOCALS~1\Temp\I1151830875\InstallerData\Installer.zip;C:\DOCUME~1\何志捷\LOCALS~1\Temp\I1151830875\Windows\InstallerData\Installer.zip;C:\DOCUME~1\何志捷\LOCALS~1\Temp\I1151830875\InstallerData;C:\DOCUME~1\何志捷\LOCALS~1\Temp\I1151830875\Windows\InstallerData;" "-java_home" "C:\sfda_licence\j2sdk1.4.2_01 (file missing)
这是个什么东西?哈哈,第一次见
gototop
 

修复
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4572.dll
O2 - BHO: IE Address Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\Program Files\SearchNet\SNHpr.dll
O2 - BHO: IE Browser Helper - {3CE496D1-1746-41CD-9489-3C0B93DF10E2} - C:\WINDOWS\Downlo~1\xtkq.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO: MonitorURL Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\PROGRA~1\DESKAD~1\deskipn.dll (file missing)
O2 - BHO: NewWeb Controller - {9ACEEE31-1440-471B-AA46-72B061FE7D61} - C:\WINDOWS\system32\WinSC32.dll
O2 - BHO: Yahoo Bar - {A697BC46-BC93-4833-93F5-1E365011E88A} - C:\WINDOWS\DBINT.dll
O2 - BHO: Flash 8 ocx - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\system32\flash8.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\WINDOWS\system32\CoolBho.dll
O2 - BHO: BHelper Class - {F2E37336-BFDB-409B-8D0E-6F013C438B20} - C:\WINDOWS\system\ecfoa8a0.dll
O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (no file)
O4 - HKLM\..\Run: [MSService_v1.0] C:\WINDOWS\system\realsched.exe
O4 - HKLM\..\Run: [YDTMain.exe] C:\PROGRA~1\YDT\YDTMain.exe
O4 - HKLM\..\Run: [BCUpdate] C:\WINDOWS\system32\BCUP.exe
O4 - HKLM\..\Run: [ADShow] C:\WINDOWS\system32\bcsysnote.exr
O4 - HKCU\..\Run: [Kuro_M3] ??
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\QQ2006\QQ.EXE (file missing)
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\QQ2006\QQ.EXE (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: 易趣购物 - {EE60714F-AC17-427e-861A-FD60CBDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=86 (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {EE60714F-AC17-427e-861A-FD60CBDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=86 (file missing)
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll
O18 - Filter: text/html - {E7009873-0D40-45B1-8D59-5B9AE98C7D38} - C:\Program Files\Internet Explorer\Connection Wizard\icwnet.dll

O21 - SSODL: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O21 - SSODL: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll (file missing)
O21 - SSODL: DelayRun - {5A6F2F95-3191-433B-8533-EB0B596A7BAC} - C:\WINDOWS\system32\ecfda8a0.dll
O23 - Service: Resin Web Server (Resin) - Unknown owner - C:\sfda_licence\resin\bin\httpd.exe" -service -env-classpath "C:\DOCUME~1\何志捷\LOCALS~1\Temp\I1151830875\InstallerData\IA Classes.zip;C:\DOCUME~1\何志捷\LOCALS~1\Temp\I1151830875\Windo ws\resource\jdglue.zip;C:\DOCUME~1\何志捷\LOCALS~1\Temp\I11518 30875\InstallerData\Installer.zip;C:\DOCUME~1\何志捷\LOCALS~1\ Temp\I1151830875\Windows\InstallerData\Installer.zip;C:\DOCUME~1\何志 ;捷\LOCALS~1\Temp\I1151830875\InstallerData;C:\DOCUME~1\何志&# 25463;\LOCALS~1\Temp\I1151830875\Windows\InstallerData;" "-java_home" "C:\sfda_licence\j2sdk1.4.2_01 (file missing)


删除文件
C:\WINDOWS\SYSTEM32\stdup.dll
C:\WINDOWS\system32\flash8.dll
C:\WINDOWS\system32\WinSC32.dll
C:\WINDOWS\BHOBJ.dll
C:\WINDOWS\Downlo~1\xtkq.dll
C:\Program Files\SearchNet\SNHpr.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_4572.dll

都是IE助手有病毒。下载超级兔子轻松搞定

酷桌面处理方式:

参考http://forum.ikaka.com/topic.asp?board=36&artid=8131157
gototop
 

感谢11楼的解决,谢谢.
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT