致:“孤独更可靠”——关于你发来的ghost.pif
1、运行后,SRENG日志可见下列异常:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{0CB68AD9-FF66-3E63-636B-B693E62F6236}><C:\Program Files\Internet Explorer\romdrivers.dll> [Microsoft Corporation]
==================================
正在运行的进程
[PID: 1264][C:\windows\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\Internet Explorer\romdrivers.dll] [Microsoft Corporation, 1. 0. 0. 1]
2、病毒文件可以删除(图1)。