回复: 各位老师,本人中毒,已上传报告,请帮忙解决
异常项目如下:
==================================
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<ringsig><C:\Documents and Settings\All Users\Application Data\ruixing.exe> []
==================================
正在运行的进程
[PID: 2564 / Administrator][C:\Program Files\svhhos.exe] [N/A, ]
==================================
建议用WINRAR压缩工具找到以下文件,分别压缩,将压缩包提交“可疑文件交流区”鉴定下,在这个板块也上传一份:
C:\Documents and Settings\All Users\Application Data\ruixing.exe
C:\Program Files\svhhos.exe