回复: 我的电脑中木马了,杀不掉
日志中异常项目如下:
=============================
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><acdess.dll,xsisco.dll kandawf.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.exe]
<IFEO[360safe.exe]><svchost.exe>
………………(此处省略一堆病毒添加的IFEO项)……
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_AVPM.exe]
<IFEO[_AVPM.exe]><svchost.exe>
服务
[Security Control / seiuctol][Stopped/Auto Start]
<c:\windows\system32\rundll32.exe vcript32.dll,test><Microsoft Corporation>
[Task Scheduler / Schedule][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%systemroot%\system32\winsysdwn.dll><N/A>
[System Restore Service / srservice][Running/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%systemroot%\system32\winsysdwn.dll><N/A>
[Windows Image Acquisition (WIA) / stisvc][Stopped/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k imgsvc-->%systemroot%\system32\winsysdwn.dll><N/A>[System Audio / System Audio][Stopped/Auto Start]
<C:\Program Files\Outlook Express\audio.exe><Twain Working Group>驱动程序
[epfwtdir / epfwtdir][Stopped/System Start]
<system32\DRIVERS\epfwtdir.sys><N/A>
[NsReSDev1 / NsReSDev1][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Nskhelper2.sys><N/A>=================================
蓝色项目不认识,红色项目原为系统服务,现已被病毒修改,其它个人认为是病毒添加的……
PS:个人认为该病毒修改和伪装了多个系统服务注册表项,麻烦……