回复: 我电脑中了W32.Leave.Worm 病毒,望高手帮忙杀毒,先谢过!
发现以下可疑及流氓项目:
------------------------------------------------------------------------------------------
注册表
[
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<XiaoiDesktop><; C:\Program Files\Incesoft\XiaoiAlerts\XiaoiUpdater.exe /hide> [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<meetim><; C:\Livim\e20.exe -noflash -noshow> [Livim LTD.]服务
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Manual Start]
<"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><CACE Technologies>
驱动程序:
[Apaidi / Apaidi][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\Apaidi.sys><N/A>
浏览器加载项
[]
{672AF8C7-19FA-485A-A82E-2642E15375B6} <E:\新建文件夹\FygIEmon.dll, N/A>[UUPlayerOCX Control]
{77910CD3-5447-4CCB-92DE-35BA8198BE81} <C:\PROGRA~1\COMMON~1\uusee\UUPlayer.ocx, >
[ARMP Control]
{D5CD69C4-F983-46E2-AF79-455E892729FA} <C:\PROGRA~1\COMMON~1\uusee\ARMP.ocx, UUSEE>
-------------------------------------------------------------------------------------
以上蓝色项目为不确定项,请将以下红色显示的文件压缩,并把压缩包发到“可疑文件交流区”鉴定。
C:\Program Files\Incesoft\XiaoiAlerts\XiaoiUpdater.exe
C:\Livim\e20.exe
E:\新建文件夹\FygIEmon.dll