+ -
当前位置:首页 → 问答吧 → 中左INCREDIBAR毒

中左INCREDIBAR毒

时间:2012-08-04

来源:互联网

引用:
原帖由 SILVESTERABEND 於 2012-8-3 08:09 PM 发表



重有冇IncrediBar出现?
1. 楼主要勾选MBAM扫到所有感染档案 > 按Remove Selected删除。
2. 建议去新増/移除程式,移除:
Thunder Netowork
Babylon
Web Assistant
我都中左
麻烦师兄睇睇hijackthis 扫瞄报告
http://www.sendspace.com/file/nw7ajh
唔该哂

作者: 63087416   发布时间: 1970-01-01

1.执行Hijackthis > Do a system scan only > 勾选下列项目 > 按Fix Checked (fix checked时关闭所有browsers/程式) > 按"是"。
引用:

O2 - BHO: Incredibar.com Helper Object - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll
O2 - BHO: XunleiBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - (no file)
O3 - Toolbar: Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Abyssus] C:\Program Files\Razer\Abyssus\razerhid.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [DriverGenius] C:\Program Files\MyDrivers\DriverGenius2010\DriverGenius.exe -static
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKCU\..\Run: [Funshion] C:\Program Files\Funshion Online\Funshion\funshion.exe startbywindows tray
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Documents and Settings\Administrator\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun

2. 下载/执行 OTM做删除。
copy & paste 以下项目於Paste Instructions for Items to be Moved的框格内。
按MoveIt > OK > 重启电脑。
引用:

:files
C:\Program Files\Funshion Online\Funshion\FunshionService.exe
C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll
C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll
C:\Program Files\Funshion Online\Funshion\funshion.exe startbywindows tray
3.下载/安装Malwarebytes Anti-Malware 免费版扫毒。更新后做全面扫瞄(唔使选用30天试用),扫完毒按Remove Selected删除感染档案。

请把MBAM扫毒报告及新Hijackthis log贴上。

作者: SILVESTERABEND   发布时间: 1970-01-01