用HijackThis(下载地址:
http://forum.ikaka.com/topic.asp?board=28&artid=6979213第1楼附件)修复以下几项:
O2 - BHO: BdSearchHook Class - {02496EBD-8455-48db-B3C7-5DAC97D9F5A7} - C:\PROGRA~1\baidu\iexp\BDSrHook.dll
O2 - BHO: CPub
Object - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - (file missing)
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\windows\system32\wmpdrm.dll (file missing)
O2 - BHO: MyIEHelper Class - {16A770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_1100.dll
O2 - BHO: CaiShowBH Class - {3AF40CB8-B3BA-4E2D-8968-4BF8DB172997} - C:\Program Files\CaiShow Tech\CaiShow\BrowerHelper.dll (file missing)
O2 - BHO: NewWebController Class - {9ACEEE30-143F-471A-AA45-72B061FE7D60} - C:\WINDOWS\system32\WinSC.dll
O4 - HKLM\..\Run: [supdate2.dll] RUNDLL32.EXE C:\windows\system32\supdate2.dll,Run
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
删除:
C:\PROGRA~1\baidu\iexp\BDSrHook.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_1100.dll
C:\WINDOWS\system32\WinSC.dll
C:\windows\system32\supdate2.dll
——————————————————————
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\windows\SYSTEM32\stdup.dll
O23 - Service: StdService (StdService) - - C:\windows\system32\rundll32.exe c:\windows\system32\stdsver.dll,service(这项HijackThis通常看不到)
这两项参考
http://forum.ikaka.com/topic.asp?board=67&artid=7423269处理。
——————————————————————
O2 - BHO: HB
Object Class - {AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} - C:\PROGRA~1\HBClient\hbhelper.dll
O4 - HKLM\..\Run: [RichMedia] C:\windows\system32\Rundll32.exe "C:\PROGRA~1\HBClient\hbhelper.dll",WaitWindows
这是很棒小秘书流氓软件,参考
http://forum.ikaka.com/topic.asp?board=28&artid=7795226——————————————————————
O23 - Service: Security Machine Manager (MOVEESS) - - C:\windows\system32\rundll32.exe c:\windows\system32\wbem\irjit.dll,export 1087
这一项HijackThis通常看不到,参考
http://forum.ikaka.com/topic.asp?board=67&artid=7926199处理。
另外C:\Program Files\CaiShow Tech\CaiShow\是什么软件?如果不是自己安装的,建议卸载。