【回复“xdict”的帖子】
明眼人一看下面这几个启动项,就知道————楼主中的与“橙色八月”毫不相干。怎么就认准是中了“橙色八月”?缘木求鱼?

<tcmdbcs><C:\WINDOWS\tcmdbcs.exe> [N/A]
<upxdnd><; C:\DOCUME~1\stone\LOCALS~1\Temp\win4.exe> []
<shualai><; C:\WINDOWS\shualai.exe /i> []
<{A6011F8F-A7F8-49AA-9ADA-49127D43138F}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.dll> []
另外,这堆病毒动态插入应用程序进程(见啥插啥,下面这些进程就是例子)。
[PID: 1068][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
[C:\Program Files\Common Files\Microsoft Shared\MSINFO\NewInfo.dll] [N/A, ]
[C:\WINDOWS\System32\tcmdbcs.dll] [N/A, ]
[C:\DOCUME~1\stone\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[PID: 1284][D:\AVG Anti-Spyware\avgas.exe] [Anti-Malware Development a.s., 7, 5, 0, 50]
[C:\WINDOWS\System32\tcmdbcs.dll] [N/A, ]
[PID: 1480][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\tcmdbcs.dll] [N/A, ]
[PID: 1760][d:\rising\rfw\RfwMain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
[C:\WINDOWS\System32\tcmdbcs.dll] [N/A, ]
[PID: 3948][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2600.0000 (xpclient.010817-1148)]
[C:\WINDOWS\System32\tcmdbcs.dll] [N/A, ]
[PID: 3864][D:\Thunder\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5, 5, 6, 274]
[C:\WINDOWS\System32\tcmdbcs.dll] [N/A, ]
[PID: 3000][D:\DL\sreng2\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\System32\tcmdbcs.dll] [N/A, ]
杀毒的第一步是“禁止进程创建”,处理干净被插进程中的病毒模块(或直接结束被插进程),然后,删除病毒文件及其启动项。