结束如下进程
C:\WINDOWS\System32\ServeHost.exe
C:\Program Files\SearchNet\SearchNet.exe
C:\Program Files\HuaCi\huaci\zsearch.exe
C:\Program Files\zcom\zPlatform.exe
C:\Program Files\zcom\skin.dll
修复
R3 - 默认的URLSearchHook丢失。用HijackThis修复
O2 - BHO: MonitorURL Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\PROGRA~1\DESKAD~1\deskipn.dll
O2 - BHO: Zhongsou Browser Helper - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\Program Files\SearchNet\SNHpr.dll
O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Program Files\Accoona\ASearchAssist.dll
O2 - BHO: HB
Object Class - {AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} - C:\PROGRA~1\HBClient\hbhelper.dll
O3 - IE工具栏增项: Accoona - {364B6276-C6C1-40B6-A6D7-6C48871FD707} - C:\Program Files\Accoona\atoolbar.dll
O4 - 启动项HKLM\\Run: [res] C:\WINDOWS\System32\res.exe
O4 - 启动项HKLM\\Run: [MoveSearch] C:\Program Files\HuaCi\huaci\zsearch.exe
O4 - 启动项HKLM\\Run: [RichMedia] C:\WINDOWS\System32\Rundll32.exe "C:\PROGRA~1\HBClient\hbhelper.dll",WaitWindows
O4 - 启动项HKLM\\Run: [zcom] C:\Program Files\zcom\zPlatform.exe MIN
O4 - 启动项HKLM\\Run: [PigUpdate] C:\Program Files\Qyule\DownLoadPig.exe
O4 - 启动项HKLM\\Run: [SearchNet_Up] "C:\Program Files\SearchNet\ServeUp.exe"
O4 - 启动项HKLM\\Run: [Desktop] C:\WINDOWS\System32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKCU\..\Run: [3721] C:\$NtUninstallQ14944$\3721.bat
O4 - Startup: 划词搜索.lnk = C:\Program Files\HuaCi\huaci\zsearch.exe
O23 - NT 服务: Decondary (Decondary Logon) - Unknown owner - C:\WINDOWS\alertter.exe
O23 - NT 服务: Remote Log - Unknown owner - C:\WINDOWS\System32\ServeHost.exe
下载:http://www.cexx.org/lspfix.exe
修复c:\windows\system32\hbmter.dll
修复方法参考图片
注意这次应该选中hbmter.dll
关闭杀软监控
卸载
C:\Program Files\Accoona
C:\Program Files\HBClient
C:\Program Files\zcom
C:\Program Files\Qyule
C:\Program Files\SearchNet
C:\Program Files\DeskAdTop
C:\Program Files\HuaCi
删除
C:\Program Files\Accoona
C:\Program Files\HBClient
C:\Program Files\zcom
C:\Program Files\Qyule
C:\Program Files\SearchNet
C:\Program Files\DeskAdTop
C:\Program Files\HuaCi
C:\WINDOWS\System32\ServeHost.exe
C:\WINDOWS\System32\res.exe
C:\$NtUninstallQ14944$
C:\WINDOWS\alertter.exe
附件:
364052200628152519.JPG