C盘是:[C:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
其它盘是:[AutoRun]
open=svr.exe
shellexecute=svr.exe
shell\Auto\command=svr.exe
还有服务:Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>被改为:[Human Interface Device Access / HidServ][Running/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\sowp.dll><N/A>
恐怕这毒没这么简单.楼主病毒样本发给我了吗,