talos - 2007-2-12 17:16:00
每个盘下面都有这两个隐藏文件,卡吧斯基扫描没有结果,请大家指点一下,不胜感激!
姑苏残月 - 2007-2-12 17:25:00
下载SRENG,扫描日志发上来吧.至于,每个盘下面的那个,手动删除好了,危害不大.手工清理就好,不用找专杀
talos - 2007-2-12 20:47:00
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
<MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation]
<IgfxTray><C:\WINDOWS\system32\igfxtray.exe> [(Verified)Intel Corporation]
<HotKeysCmds><C:\WINDOWS\system32\hkcmd.exe> [(Verified)Intel Corporation]
<DAEMON Tools-2052><"D:\Program Files\D-Tools\daemon.exe" -lang 2052> [DAEMON'S HOME]
<KAVPersonal50><"d:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize> [Kaspersky Lab]
<Acrobat Assistant 7.0><"D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"> [Adobe Systems Inc.]
<StormCodec_Helper><"d:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> [N/A]
<IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload> [(Verified)Microsoft Corporation]
<SVCHOST><C:\WINDOWS\MDM.EXE> [N/A]
<Rundll><C:\WINDOWS\system32\rundll.exe> [bit]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Corporation]
一听可乐 - 2007-2-12 22:32:00
帮你顶。我的电脑也中毒了,症状和你的差不多。而且鼠标右键多了自动播放,删了重启后又会出来。
老衲法号星星 - 2007-2-12 22:43:00
安全糢式下,刪除
<Rundll><C:\WINDOWS\system32\rundll.exe>
並到註冊錶刪除相關項目,之后建議下載註冊錶脩復工具進行脩復,謝謝
talos - 2007-2-13 9:27:00
【回复“老衲法号星星”的帖子】
谢谢
© 2000 - 2026 Rising Corp. Ltd.