原帖由 mini8mimi 于 2008-8-27 8:33:00 发表
删除注册表
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto.exe]
<IFEO[auto.exe]><AUTOGUARDER GUARDED.> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSDOS.bat]
<IFEO[MSDOS.bat]><AUTOGUARDER GUARDED.> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntldr.exe]
<IFEO[ntldr.exe]><AUTOGUARDER GUARDED.> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pagefile.pif]
<IFEO[pagefile.pif]><AUTOGUARDER GUARDED.> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sos.exe]
<IFEO[sos.exe]><AUTOGUARDER GUARDED.> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sxs.exe]
<IFEO[sxs.exe]><AUTOGUARDER GUARDED.> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\test.exe]
<IFEO[test.exe]><AUTOGUARDER GUARDED.> [N/A]
删除服务
[KEHWDPTAA / HQOICKKYL][Running/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k LGGQKYFED-->C:\WINDOWS\vHfCSnHbtLID2010.DLL><N/A>
[Intel Chip Group / IntelChip][Running/Auto Start]
<C:\WINDOWS\system32\hhcmd.exe><>
删除驱动
[Atheros AR5008 Wireless Network Adapter Service / AR5416][Stopped/Manual Start]
<system32\DRIVERS\ar5416.sys><N/A>
1、以上红色项目为安全工具创建的IFEO项目,作用是对病毒文件进行映相劫持,不需删除;
2、以上蓝色项目个人认为是正常驱动程序,不需删除;
3、个人认为以下服务项目有问题:
[DNS Service / DNSService][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k NetSvr-->C:\WINDOWS\System32\dnssvr.dll><N/A>
[KEHWDPTAA / HQOICKKYL][Running/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k LGGQKYFED-->C:\WINDOWS\vHfCSnHbtLID2010.DLL><N/A>
[Intel Chip Group / IntelChip][Running/Auto Start]
<C:\WINDOWS\system32\hhcmd.exe><>
4、麻烦楼主将以下三个文件分别用WINRAR压缩,把压缩包上传:
C:\WINDOWS\System32\dnssvr.dll
C:\WINDOWS\vHfCSnHbtLID2010.DLL
C:\WINDOWS\system32\hhcmd.exe