典型的IFEO劫持.(使用卡巴要及时升级!)
下载冰刃1.22地址:http://www.onlinedown.net/soft/53325.htm
改名为2.com运行-文件-设置-禁止进程创建
删除文件
C:\Program Files\Common Files\Microsoft Shared\dtajxne.exe
C:\Program Files\Common Files\System\akpfhtq.exe
每个分区的
xiwiiuy.exe和autorn.inf
用改了名的SRENG.EXE
删除注册表中:
<mqovgwi><C:\Program Files\Common Files\System\akpfhtq.exe> []
<xiwiiuy><C:\Program Files\Common Files\Microsoft Shared\dtajxne.exe> []
还有所有的IFEO劫持项
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppSvc32.exe]
<IFEO[AppSvc32.exe]><C:\Program Files\Common Files\Microsoft Shared\dtajxne.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp.exe]
<IFEO[ArSwp.exe]><C:\Program Files\Common Files\Microsoft Shared\dtajxne.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AST.exe]
<IFEO[AST.exe]><C:\Program Files\Common Files\Microsoft Shared\dtajxne.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe]
<IFEO[autoruns.exe]><C:\Program Files\Common Files\Microsoft Shared\dtajxne.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastU3.exe]
<IFEO[AvastU3.exe]><C:\Program Files\Common Files\Microsoft Shared\dtajxne.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe]
<IFEO[avconsol.exe]><C:\Program Files\Common Files\Microsoft Shared\dtajxne.exe> []
...
修复安全模式
关于SRENG的操作,参看:http://forum.ikaka.com/topic.asp?board=28&artid=8270267&page=1
最后
打开我的电脑-工具-文件夹选项-查看-显示隐藏文件-隐藏受保护的系统文件(勾去掉)-确定
重起进入安全模式(开机不停的按F8,选择安全模式启动) 清空临时文件夹:
C:\Documents and Settings\用户名\Local Settings\Temporary Internet Files
C:\Documents and Settings\用户名\Local Settings\Temp