rstray.exe被劫持了,
1.建议使用XDelBox删除以下文件:(
XDelBox1.8下载)
使用说明:删除时复制所有要删除文件的路径,在待删除文件列表里点击右键选择从剪贴板导入,导入后在要删除文件上点击右键,选择立刻重启删除,电脑会重启进入DOS界面进行删除操作。运行xdelbox前最好卸载所有可移动存储介质(包括U盘,MP3,手机存储卡等)。
c:\docume~1\admini~1\locals~1\temp\~d28025.tmp
c:\windows\system32\drivers\ajhvy.sys
2.删除重启后使用SREng修复下面各项: 启动项目 -- 注册表之如下项删除:
[{0A2D7F10-1153-4061-AA4B-ACB870212B57}] <>
[{A5CA6C70-7185-4466-AB45-B1C34E7A37CA}] <>
[{9D3E893F-55DA-42BF-94EF-B634AB358A24}] <>
[{F8C6B7B5-DAE0-4B78-BF2A-101C9A9CCA27}] <>
[{76CBCF38-0583-44C7-A1AE-D463DFE625EC}] <>
[{71C4F360-FF1E-413E-B17A-0CA267A78E97}] <>
[{DA112397-5376-4E52-A333-A85284658DEA}] <>
[{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}] <>
[{A23CA53C-731F-4033-92E8-C1DFB4E71D34}] <>
[{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}] <>
[{15882A2F-A06D-486E-8958-E84C86CBF273}] <>
[{C1606DC4-C352-4B1F-A0B5-52DF3204E05D}] <>
[{A761BE8E-C15A-4DDD-A777-2C683E9E96C8}] <>
[{16886058-6A31-4D53-B4AC-4CC7D2248D69}] <>
[{0623DE09-E49D-4695-AA24-88BA7B58A395}] <>
[{CEBB8F8A-308B-43E9-9789-B6FD6BE1BD97}] <>
[{23DA65D2-C696-4EE4-BEE8-B4841DEC3E30}] <>
[{81A00901-A518-45E4-AB3C-5B0179A05D75}] <>
[{93DA1E7D-7C46-4F90-8674-EC90511FCA72}] <>
[{93F33500-527E-4E33-AECA-69B15243A90E}] <>
[{36AC68E6-0C26-4D39-B98E-54B49DAB6BAA}] <>
[{37C5D66A-8B1B-4545-8112-3751194F6A4A}] <>
[{4F5EEDE5-1687-49D2-8A17-FF0B454FB37B}] <>
[{A0C86020-5935-4B87-B20E-0B656D450264}] <>
[{AB900155-F1F0-4165-9E73-67BC13BBCE89}] <>
[{762D618C-E2CB-4217-8275-03302A93073F}] <>
[{69B265A2-A172-4D27-BDF1-917E6D8B1DCC}] <>
[{704C3595-DB85-40F6-A601-8D6F346907BD}] <C:\WINDOWS\system32\704C3595.dll>
[{C8417122-386F-48C7-8900-C82E4694FEBC}] <C:\Documents and Settings\Administrator\Application Data\Spy009.dll>
[IFEO[RsTray.exe]] <svchost.exe>
[IFEO[Thunder5.exe]] <svchost.exe>
启动项目 -- 服务-- 驱动程序之如下项删除:
[zx / zx] <\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~d28025.tmp>
[ajhv / thxmson] <\SystemRoot\system32\drivers\ajhvy.sys>