启动项目:
<upxdnd><E:\DOCUME~1\msi\LOCALS~1\Temp\upxdnd.exe> []
<System><E:\Program Files\Common Files\System\Updaterun.exe> []
<RegNetPass><E:\WINDOWS\system32\regcsp.exe> []
------------------------------------------------------------------------
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><userinit.exe,> [(Verified)Microsoft Windows Publisher]
PS这一项,userinit键的值好像有问题!
--------------------------------------------------------------------------
服务:
[Application Accelerator / Patterns][Running/Auto Start]
注意F盘的autorun.inf
<E:\WINDOWS\System32\svchost.exe -k netsvcs-->E:\WINDOWS\system32\dnsgj.dll><Microsoft Corporation>
[Routing Protect Access / SHipING][Running/Auto Start]
<E:\WINDOWS\SYSTEM32\RUNDLL2000.EXE E:\WINDOWS\SYSTEM32\WBEM\PAQXB.DLL,Export 1087><Microsoft Corporation>
---------------------------------------------
驱动:
[mrtxnjtg / mrtxnjtg][Stopped/Auto Start]
<\??\E:\WINDOWS\system32\drivers\mrtxnjtg.sys><N/A>
----------------------------------------------------------
删驱动,服务,再删对应文件
PS:中毒不浅