回复:autorun.inf+隐藏进程。附上日志
下载费尔木马删除工具,勾选抑制再生删除下面文件:
http://bbs.ikaka.com/attachment.aspx?attachmentid=446804删除:
C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\msn.exe
C:\Autorun.inf
C:\msn.exe
D:\Autorun.inf
D:\msn.exe
E:\Autorun.inf
E:\msn.exe
不论删除结果如何,重启电脑
————————————————————————————
下面项目不认识,自己看文件判断去。
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<msconfig><C:\WINDOWS\system32\msconfig.exe /ALL> [Microsoft Corporation]
<><C:\Program Files\Internet Explorer\Connection Wizard\Explorer.exe> [File is missing
==================================
服务
[NT LM Security Support(RPC) / NT LM Security Support(RPC)][Stopped/Auto Start]
<C:\WINDOWS\system32\mmutilse.exe runsrv /name:"NT LM Security Support(RPC)" /prinum:"32" /cmdline:"C:\WINDOWS\system32\mcvcea.exe"><N/A>
请尽量将C:\msn.exe文件压缩发来