12   2  /  2  页   跳转

请看日志

晕,是冲击波
我也中过
gototop
 

瑞星官网上有专杀
gototop
 

删除注册表启动项
<5lhyxq8><C:\DOCUME~1\new\LOCALS~1\Temp\c0nime.exe>
[N/A]<upxdnd><C:\WINDOWS\upxdnd.exe> [N/A]
<msccrt><C:\WINDOWS\SVCHOST.EXE> [N/A]
<mppds><C:\WINDOWS\WINLOGON.EXE> [N/A]
<Kvsc3><C:\WINDOWS\RUNDLL32.exe> [N/A]
<Microsoft Autorun5><C:\WINDOWS\system32\mosou.exe> [N/A]
<Microsoft Autorun14><C:\WINDOWS\system32\ztinetzt.exe> [N/A]
<Microsoft Autorun4><C:\WINDOWS\system32\mydata.exe> [N/A]
<Microsoft Autorun12><C:\WINDOWS\system32\nwizzhuxians.exe> [N/A]
<Microsoft Autorun10><C:\WINDOWS\system32\nwizwmgjs.exe> [N/A]
<TIMHost><C:\WINDOWS\TIMHost.exe> [N/A]
<Microsoft Autorun7><C:\WINDOWS\system32\nwizqjsj.exe> [N/A]
<Microsoft Autorun1><C:\WINDOWS\system32\nwizdh.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<MSDEG32><LYLoader.exe> [N/A]
<MSDWG32><LYLoadbr.exe> [N/A]
<MSDCG32 ><LYLeador.exe> [N/A]
<MSDOG32><LYLoador.exe> [N/A]
<MSDSG32><LYLoadar.exe> [N/A]
<MSDMG32><LYLoadmr.exe> [N/A]
<MSDHG32><LYLoadhr.exe> [N/A]
<MSDQG32><LYLoadqr.exe> [N/A]

删除服务
[Win32 Debug Service / MSDebugsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe msdebug.dll,input><Microsoft Corporation>
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<C:\WINDOWS\system32\rundll32.exe windhcp.ocx,input><Microsoft Corporation>
[WinWMServiceNow / WinWMServiceNow][Stopped/Auto Start]
<C:\DOCUME~1\new\LOCALS~1\Temp\RAVWM.EXE><N/A>
删除
[C:\WINDOWS\system32\LYMANGR.DLL] [N/A, N/A]
[C:\DOCUME~1\new\LOCALS~1\Temp\Gjzo0.dll] [N/A, N/A]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, N/A]
[C:\WINDOWS\system32\nwizwmgjs.dll] [N/A, N/A]
[C:\WINDOWS\system32\TIMHost.dll] [N/A, N/A]
[C:\WINDOWS\system32\EBSPI.dll] [N/A, N/A]
[C:\WINDOWS\system32\Winhttps.dll] [N/A, N/A]
[C:\WINDOWS\system32\moyu103.dll] [N/A, N/A]
[C:\WINDOWS\system32\ztinetzt.dll] [N/A, N/A]
[C:\WINDOWS\system32\MOSOU.dll] [N/A, N/A]
[C:\WINDOWS\system32\nwizzhuxians.dll] [N/A, N/A]
[C:\WINDOWS\system32\nwizqjsj.dll] [N/A, N/A]
[C:\WINDOWS\system32\msdebug.dll] [N/A, N/A]
[C:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, N/A]
清空C:\DOCUME~1\new\LOCALS~1\Temp
漏掉的请高手补
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT