[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Arp保护神><D:\桌面文件1\arp430.exe> []
<WinnetManager><C:\WINDOWS\system32\WinnetManager.exe> []
启动文件夹
[ip]
<C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\ip.bat --> [N/A]><N>
驱动程序
[arp8023 / arp8023][Stopped/Manual Start]
<\SystemRoot\system32\drivers\arp8023.sys><N/A>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
正在运行的进程
[PID: 508][D:\桌面文件1\arp430.exe] [N/A, ]
[E:\temp\E_4\krnln.fnr] [, 1, 0, 0, 1]
[E:\temp\E_4\iext5.fne] [, 1, 0, 0, 1]
[E:\temp\E_4\sock.fne] [N/A, ]
[E:\temp\E_4\eAPI.fne] [, 1, 0, 0, 1]
[E:\temp\E_4\internet.fne] [, 1, 0, 0, 1]
想办法找到这些删吧,楼主是否可以把那个arp430.exe压缩加密码123后发给我,ryx1191@sina.com 谢谢