回复:很邪乎的毒
建议删除
c:\documents and settings\administrator\application data\dk.sys
c:\windows\system32\msctfime.iem
c:\windows\system32\dbr06020.ocx
c:\program files\common files\system\kb037637.dmp
c:\program files\common files\system\kb088751.cpu
c:\program files\common files\system\kb212268.mak
c:\program files\common files\system\kb349523.uce
c:\program files\common files\system\kb614833.dla
c:\program files\common files\system\kb766286.tad
c:\program files\common files\system\kb947527.nvu
c:\program files\common files\system\kb975074.dma
c:\windows\system32\bhoexe.dll ----- <<查询这是鬼影病毒释放的文件 建议楼主下载XueTr查看mbr是否被修改 必要时下载鬼影专杀试试>>
c:\documents and settings\all users\「开始」菜单\程序\启动\desktop
c:\documents and settings\all users\「开始」菜单\程序\启动\desktop.file
[RunShadowTip] <C:\WINDOWS\system32\shadow\ShadowTip.exe> c:\windows\system32\shadow\shadowtip.exe ----“”影子系统的相关文件吗“”
禁用启动项目
[des] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\desktop>
[desktop.] <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\desktop.file>
驱动
[360FkAdv / 360FkAdv] <>---不存在还运行? 用XT删除之
附xt下载地址:
http://www.xuetr.com/鬼影专杀:
http://down.tech.sina.com.cn/content/47368.html http://sd.keniu.com/zt/ztguiying.html