[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Torjan Program><C:\WINDOWS\WINLOGON.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<Torjan Program><C:\WINDOWS\WINLOGON.EXE>
虚假的WINLOGON.EXE 你怎么删启动项都会有的...瑞星恐怕开不起来咯..
参考:http://forum.ikaka.com/topic.asp?board=28&artid=7495863
处理起来比较麻烦..