回复: 中了zczxcx.exe,请求不重装系统清除病毒办法
日志中发现以下异常
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe
C:\WINDOWS\system32\zczxcx.exe> []启动文件夹
[pqqju]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\pqqju.lnk --> [File is missing]><N>
插在E:\360\360se3\360SE.exe
C:\Documents and Settings\MCC\桌面\SReng2.8.2.1321版\SReng2.8.2.1321版\sr-engldr.EXE
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\Explorer.exe
[C:\WINDOWS\system32\pqqju.dll] [N/A, ]插在 C:\WINDOWS\Explorer.exe
[E:\QQ\qdshm.dll] [, 1, 0, 101, 20]QQ网盘的话忽略
Winsock 提供者不是默认的
Autorun.inf
[C:\]
[AutoRun]
shell\open=打开(&O)
shell\open\Command=coes.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=coes.exe
[D:\]
[AutoRun]
shell\open=打开(&O)
shell\open\Command=coes.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=coes.exe
[E:\]
[AutoRun]
shell\open=打开(&O)
shell\open\Command=coes.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=coes.exe
[F:\]
[AutoRun]
shell\open=打开(&O)
shell\open\Command=coes.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=coes.exe