结束C:\WINDOWS\system32\BCUP.exe进程
用HIJACKTHIS修复
O2 - BHO: HB
Object Class - {AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} - C:\PROGRA~1\HBClient\tbhelper.dll
O2 - BHO: DownloadBHO T2BHO - {B1D147E7-873E-4909-8127-695D9BB78728} - C:\WINDOWS\Downloaded Program Files\barhelp24.0.dll
O2 - BHO: Infofo 工具栏 - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\Program Files\Infofo Bar\infofobar.dll
O3 - Toolbar: Infofo 工具栏 - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\Program Files\Infofo Bar\infofobar.dll
O3 - Toolbar: VeryCD超级搜索 - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - C:\Program Files\YOK.com\SuperSearch\YOK_SuperSearch.dll
O4 - HKLM\..\Run: [BCUpdate] C:\WINDOWS\system32\BCUP.exe
O4 - HKLM\..\Run: [Abrada WIN32] C:\WINDOWS\system32\abradaload.dll
O4 - HKLM\..\Run: [RichMedia] C:\WINDOWS\system32\Rundll32.exe "C:\PROGRA~1\HBClient\hbhelper.dll",WaitWindows
O4 - HKLM\..\RunServices: [Abrada WIN32] C:\WINDOWS\system32\abradaload.dll
O4 - HKCU\..\Run: [RegBar] regsvr32.exe /u C:\progra~1\blogmark\bocaitoolbar.dll /s /i /n
O8 - Extra context menu item: VeryCD搜索 - C:\Program Files\YOK.com\SuperSearch\yoksch.htm
O9 - Extra button: Infofo 工具栏 - {8507326C-B5C1-4559-BB91-0919E753836F} - C:\Program Files\Infofo Bar\infofobar.dll
O9 - Extra 'Tools' menuitem: Infofo 工具栏 - {8507326C-B5C1-4559-BB91-0919E753836F} - C:\Program Files\Infofo Bar\infofobar.dll
O23 - Service: Alerter-Sp2 - Unknown - C:\Program Files\Internet Explorer\Connection Wizard\icwtutor1.exe
下载:http://www.cexx.org/lspfix.exe
修复c:\windows\system32\hbmter.dll
修复方法参考图片
注意这次应该选中hbmter.dll
卸载
C:\Program Files\HBClient
C:\Program Files\Infofo Bar
C:\Program Files\YOK.com
C:\Program Files\blogmark
删除
C:\Program Files\HBClient
C:\Program Files\Infofo Bar
C:\Program Files\YOK.com
C:\Program Files\blogmark
C:\WINDOWS\Downloaded Program Files\barhelp24.0.dll
C:\WINDOWS\system32\BCUP.exe
C:\WINDOWS\system32\abradaload.dll
C:\Program Files\Internet Explorer\Connection Wizard\icwtutor1.exe
另外
O23 - Service: Alerter-Sp2 - Unknown - C:\Program Files\Internet Explorer\Connection Wizard\icwtutor1.exe
这一项应该是灰鸽子
具体操作请参考http://forum.ikaka.com/topic.asp?board=28&artid=7713905
附件:
364052200629112257.JPG