回复:高手来看看!SREng打开了后说……
附件删除以下文件,提取并病毒样本
C:\root\yxyeaholes\scvhost.exe
C:\WINDOWS\system32\4ff.exe
C:\windows\System32\DRIVERS\9syld3.sys
C:\windows\system32\drivers\o8qbjjy0d2.sys
删除服务
[PnkBstrA / PnkBstrA][Running/Auto Start]
<C:\WINDOWS\system32\PnkBstrA.exe><N/A>
[Logical Disk Manager Amdinistrative oboqyy / oboqyy][Running/Auto Start]
<c:\root\yxyeaholes\scvhost.exe><>
[lxea / lxea][Running/Auto Start]
<C:\WINDOWS\system32\4ff.exe><Microsoft Corporation>
删除驱动
[o8qbjjy0d2 / o8qbjjy0d2][Stopped/Boot Start]
<\SystemRoot\system32\drivers\o8qbjjy0d2.sys><N/A>
[9syld3 / 9syld3][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\9syld3.sys><>