瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 开机出现找不到ehuupdate.exe然后就自动安装酷桌面等狂泪【求助】斑竹

123   1  /  3  页   跳转

开机出现找不到ehuupdate.exe然后就自动安装酷桌面等狂泪【求助】斑竹

开机出现找不到ehuupdate.exe然后就自动安装酷桌面等狂泪【求助】斑竹

网上有人说要重装系统。请问各位大虾。。有更好地解决办法嘛?
谢谢。俄。。
最后编辑2006-08-19 23:40:12
分享到:
gototop
 

什么问题,大概地讲一下吧

gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 13:46:22, on 2006-8-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\Explorer.EXE
C:\windows\SOUNDMAN.EXE
D:\Program Files\SkyNet\FireWall\PFW.exe
D:\Program Files\ewido anti-spyware 4.0\ewido.exe
D:\Program Files\NavNT\vptray.exe
C:\windows\system32\ctfmon.exe
D:\Program Files\NavNT\defwatch.exe
D:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\UpdateService.exe
C:\windows\system32\MsgSys.EXE
C:\windows\system32\svchost.exe
D:\Program Files\Tencent\QQ\QQ.exe
D:\Program Files\Tencent\QQ\TIMPlatform.exe
D:\Program Files\Maxthon\Maxthon.exe
C:\windows\system32\rundll32.exe
C:\windows\system32\conime.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.547\HijackThis.exe

R3 - URLSearchHook: YOK Search Class - {88351CEF-BAC0-4A9B-8380-31A173E2926F} - C:\Program Files\YOK.com\SuperSearch\YOK_SuperSearch.dll
F2 - REG:system.ini: UserInit=C:\windows\Media\update.exe,C:\WINDOWS\Media\update.exe,C:\WINDOWS\system32\Userinit.exe,
O2 - BHO: MonitorURL Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\PROGRA~1\DESKAD~1\deskipn.dll
O2 - BHO: XBTP03129 - {6029B367-250A-4696-925C-641709CA7381} - C:\PROGRA~1\KUAISO~1\KUAISO~1.DLL
O2 - BHO: YOK超级搜索 - {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} - C:\Program Files\YOK.com\SuperSearch\YOK_SuperSearch.dll
O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\windows\system32\CoolBho.dll
O3 - Toolbar: Kuaiso Toolsbar - {6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} - C:\Program Files\Kuaiso Toolsbar\kuaiso_06040.dll
O3 - Toolbar: YOK超级搜索 - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - C:\Program Files\YOK.com\SuperSearch\YOK_SuperSearch.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SKYNET Personal FireWall] D:\Program Files\SkyNet\FireWall\PFW.exe
O4 - HKLM\..\Run: [!ewido] "D:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [vptray] D:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [YOKAssiant] Rundll32.exe C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll,YOKAssiant
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnnt] C:\windows\Updated.exe
O8 - Extra context menu item: YOK超级搜索 - C:\Program Files\YOK.com\SuperSearch\yoksch.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: YOK超级搜索 - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - http://www.yok.com (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O17 - HKLM\System\CCS\Services\Tcpip\..\{E47F34E9-4D44-47E8-A7E6-69F9F293694D}: NameServer = 61.233.65.3 211.98.192.3
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: DefWatch - Symantec Corporation - D:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - D:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus 客户端 (Norton AntiVirus Server) - Symantec Corporation - D:\Program Files\NavNT\rtvscan.exe
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\windows\system32\spoolsv.exe (file missing)
O23 - Service: UpdateService - Unknown owner - C:\WINDOWS\system32\UpdateService.exe

gototop
 

谢谢各位大侠辣。。。
gototop
 

我用ewido anti-spyware扫描后。也都处理了。。也卸载了好几次yok,酷桌面。。。但是只要上网。就会出现"找不到ehuupdate.exe"然后就会自动安装酷桌面,快搜,yok。。。。。。。。恐怖阿
gototop
 

运行HijackThis,把下面的选中打上钩,修复
R3 - URLSearchHook: YOK Search Class - {88351CEF-BAC0-4A9B-8380-31A173E2926F} - C:\Program Files\YOK.com\SuperSearch\YOK_SuperSearch.dll
F2 - REG:system.ini: UserInit=C:\windows\Media\update.exe,C:\WINDOWS\Media\update.exe,C:\WINDOWS\system32\Userinit.exe,
O2 - BHO: MonitorURL Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\PROGRA~1\DESKAD~1\deskipn.dll
O2 - BHO: XBTP03129 - {6029B367-250A-4696-925C-641709CA7381} - C:\PROGRA~1\KUAISO~1\KUAISO~1.DLL
O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:\windows\system32\CoolBho.dll
O4 - HKCU\..\Run: [msnnt] C:\windows\Updated.exe
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\windows\system32\spoolsv.exe (file missing)

控制面板--管理工具---服务---查找UpdateService,关闭这个服务
重启到安全模式下删除
C:\WINDOWS\system32\UpdateService.exe
C:\windows\Updated.exe

控制面板--添加删除---卸载掉YOK超级搜索
gototop
 

刚才我把一个spoolsv删除掉了。。有影响马?
gototop
 

还有一项安全模式下
C:\windows\Media\update.exe
gototop
 

引用:
【菜鸟啊我的贴子】刚才我把一个spoolsv删除掉了。。有影响马?
………………



这个是木马病毒
gototop
 

C:\windows\Media\update.exe
大哥。。这个我删除不掉。。。。。
下面是新的进程。。大哥看看还有没有毛病。。。。
Logfile of HijackThis v1.99.1
Scan saved at 14:13:17, on 2006-8-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\Explorer.EXE
C:\windows\SOUNDMAN.EXE
D:\Program Files\SkyNet\FireWall\PFW.exe
D:\Program Files\ewido anti-spyware 4.0\ewido.exe
D:\Program Files\NavNT\vptray.exe
C:\windows\system32\ctfmon.exe
D:\Program Files\NavNT\defwatch.exe
D:\Program Files\ewido anti-spyware 4.0\guard.exe
D:\Program Files\NavNT\rtvscan.exe
C:\windows\system32\svchost.exe
C:\windows\system32\MsgSys.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.031\HijackThis.exe
D:\Program Files\Maxthon\Maxthon.exe
C:\windows\system32\wuauclt.exe

F2 - REG:system.ini: UserInit=C:\windows\Media\update.exe,C:\windows\SYSTEM32\Userinit.exe,
O3 - Toolbar: Kuaiso Toolsbar - {6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} - C:\Program Files\Kuaiso Toolsbar\kuaiso_06040.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SKYNET Personal FireWall] D:\Program Files\SkyNet\FireWall\PFW.exe
O4 - HKLM\..\Run: [!ewido] "D:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [vptray] D:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - D:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: YOK超级搜索 - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - http://www.yok.com (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O17 - HKLM\System\CCS\Services\Tcpip\..\{E47F34E9-4D44-47E8-A7E6-69F9F293694D}: NameServer = 61.233.65.3 211.98.192.3
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: DefWatch - Symantec Corporation - D:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - D:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus 客户端 (Norton AntiVirus Server) - Symantec Corporation - D:\Program Files\NavNT\rtvscan.exe
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\windows\system32\spoolsv.exe (file missing)

gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT