触目惊心!!!
1以下启动项:
<9ggvl0253eu><C:\WINDOWS\servicea.exe> [N/A]
<cs><C:\DOCUME~1\ZHANGZ~1\LOCALS~1\Temp\winlog0n.exe> [N/A]
<tgqf1v><C:\DOCUME~1\ZHANGZ~1\LOCALS~1\Temp\rundl132.exe> [N/A]
<svc><C:\DOCUME~1\ZHANGZ~1\LOCALS~1\Temp\byetmr.exe> [N/A]
<t113mzbxq6><C:\DOCUME~1\ZHANGZ~1\LOCALS~1\Temp\iexpl0re.exe> [N/A]
<1dmuerftk><C:\DOCUME~1\ZHANGZ~1\LOCALS~1\Temp\Servere.exe> [N/A]
<t0q><C:\DOCUME~1\ZHANGZ~1\LOCALS~1\Temp\crasos.exe> [N/A]
<1e53rkd3quiw2g><C:\DOCUME~1\ZHANGZ~1\LOCALS~1\Temp\c0nime.exe> [N/A]
<3kk315dj1><C:\DOCUME~1\ZHANGZ~1\LOCALS~1\Temp\iexp1ore.exe> [N/A]
<9btjf118x><C:\DOCUME~1\ZHANGZ~1\LOCALS~1\Temp\cftmon.exe> [N/A]
<VoipStunt><"C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe" -nosplash -minimized> [(Verified)Finarea SA]
<upxdnd><C:\DOCUME~1\ZHANGZ~1\LOCALS~1\Temp\upxdnd.exe>
<4><C:\SysWsj6\svchost.exe> []
<66><C:\SysDayN6\svchost.exe> []
<333><C:\Syswm1h\svchost.exe> []
<50><C:\SysAd5D\svchost.exe> []
SECRETSERVICE><C:\Program Files\macaffe\host\update\s4nn0t.exe>
<NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe> [Ahead Software Gmbh]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>
SDR6_Check><"C:\Program Files\Common Files\DriveCleaner 2006 Free\udcsdr.exe"> []
<PAS_Check><"C:\Program Files\Common Files\DriveCleaner 2006 Free\udcpas.exe"> []
<FYNEWS><C:\DOCUME~1\ZHANGZ~1\LOCALS~1\Temp\sl.exe> [N/A]
<nortons><C:\WINDOWS\nortons.exe> []
<mppds><C:\WINDOWS\mppds.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
<yupxdnd><C:\DOCUME~1\ZHANGZ~1\LOCALS~1\Temp\yupxdnd.exe>
<upxdnd><C:\DOCUME~1\ZHANGZ~1\LOCALS~1\Temp\upxdnd.exe> []
<isamonitor.exe><C:\Program Files\Video ActiveX
Object\isamonitor.exe> [N/A]
<pmsngr.exe><C:\Program Files\Video ActiveX
Object\pmsngr.exe>
2、以下服务项
[36A88A0 / 36A88A0][Stopped/Auto Start]
<C:\WINDOWS\system32\36A88A0.EXE -service><Microsoft Corporation>
[Management Instrumentation Driver Extensions / 6to4][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\winmide32.dll><N/A>
[PsShutdown / PsShutdownSvc][Stopped/Manual Start]
<C:\WINDOWS\System32\PSSDNSVC.EXE><N/A>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\\rundll32.exe windhcp.ocx,input><Microsoft Corporation>
想法杀了吧(先结束进程,再删除注册键值,再重启杀病毒尸体,注意晴空临时文件夹)