回复:那位高手有空帮我看看!先谢谢了
说明一下遇到什么问题了
附件里边文档内容就是
病毒名称 时间 活动的进程 相关文件
Malicious Code(恶意代码) 2009-03-19 18:34:36 C:\WINDOWS\SOFTWAREDISTRIBUTION\DOWNLOAD\712C2FB8025128CD0F10C323C54D07A9\UPDATE\UPDATE.EXE(2932);C:\WINDOWS\$NTUNINSTALLKB898461$\SPUNINST\UPDSPAPI.DLL;C:\WINDOWS\SOFTWAREDISTRIBUTION\DOWNLOAD\712C2FB8025128CD0F10C323C54D07A9\UPDATE\UPDATE.EXE;C:\WINDOWS\$HF_MIG$\KB898461\SPUNINST.EXE;C:\WINDOWS\$NTUNINSTALLKB898461$\SPUNINST\SPUNINST.EXE;
Malicious Code(恶意代码) 2009-03-19 13:56:58 C:\DOCUME~1\ADMINI~1.LEN\LOCALS~1\TEMP\FMNJKIVPUQXY.EXE(2856); C:\WINDOWS\SYSTEM32\DRIVERS\RKREVEAL150.SYS;C:\DOCUME~1\ADMINI~1.LEN\LOCALS~1\TEMP\FMNJKIVPUQXY.EXE;
Malicious Code(恶意代码) 2009-03-18 01:53:28 C:\DOCUME~1\ADMINI~1.LEN\LOCALS~1\TEMP\YQB.EXE(1392);F:\新建文件夹\ROOTKITREVEALER汉化.EXE(3624);F:\新建文件夹\ROOTKITREVEALER汉化.EXE;C:\DOCUME~1\ADMINI~1.LEN\LOCALS~1\TEMP\YQB.EXE;
Malicious Code(恶意代码) 2009-03-18 01:53:21 C:\DOCUME~1\ADMINI~1.LEN\LOCALS~1\TEMP\FW.EXE(568); C:\DOCUME~1\ADMINI~1.LEN\LOCALS~1\TEMP\FW.EXE;C:\WINDOWS\SYSTEM32\DRIVERS\RKREVEAL150.SYS;
Malicious Code(恶意代码) 2009-03-18 01:53:00 C:\DOCUME~1\ADMINI~1.LEN\LOCALS~1\TEMP\ALMEJWVTMBZR.EXE(2796); C:\DOCUME~1\ADMINI~1.LEN\LOCALS~1\TEMP\ALMEJWVTMBZR.EXE;C:\WINDOWS\SYSTEM32\DRIVERS\RKREVEAL150.SYS;
Malicious Code(恶意代码) 2009-03-17 12:10:22 C:\WINDOWS\SYSTEM32\RUNDLL32.EXE(476);C:\WINDOWS\SYSTEM32\NVSVC32.EXE(1644);C:\WINDOWS\SYSTEM32\NVSVC32.EXE;
Malicious Code(恶意代码) 2009-03-17 01:23:07 C:\WINDOWS\SYSTEM32\RUNDLL32.EXE(408);C:\WINDOWS\SYSTEM32\NVSVC32.EXE(1416);C:\WINDOWS\SYSTEM32\NVSVC32.EXE;
Malicious Code(恶意代码) 2009-03-16 12:47:11 C:\WINDOWS\SYSTEM32\NVSVC32.EXE(740);C:\WINDOWS\SYSTEM32\RUNDLL32.EXE(1856);C:\WINDOWS\SYSTEM32\NVSVC32.EXE;
Malicious Code(恶意代码) 2009-03-16 12:23:18 G:\SETUP.EXE(692); C:\DOCUME~1\ADMINI~1.LEN\LOCALS~1\TEMP\{3AF0D07E-07F9-4269-851D-18171F72CD08}\ISSETUP.DLL;G:\SETUP.EXE;C:\DOCUME~1\ADMINI~1.LEN\LOCALS~1\TEMP\_IS4.EXE;
Malicious Code(恶意代码) 2009-03-16 12:11:41 E:\PROGRAM FILES\CHINANET\MEMOPAD.EXE(2576); E:\PROGRAM FILES\CHINANET\MEMOPAD.EXE;
Malicious Code(恶意代码) 2009-03-16 12:09:41