可疑项目如下:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<w><%SystemRoot%\WinRaR.exe> [N/A]
<wm><%SystemRoot%\winlogor.exe> []
<wl><%SystemRoot%\intent.exe> [N/A]
<mm><%SystemRoot%\sourro.exe> [N/A]
<zx><%SystemRoot%\winadr.exe> [N/A]
<rx><%SystemRoot%\winnt.exe> [N/A]
<aa><%SystemRoot%\SVchont.exe> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<RavRuneip><C:\WINDOWS\system32\RacvSvc.EXE wdkqbgmsye.dll,HHanMa> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systewww.gexing.commroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook\Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[15867609 / 15867609][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\Drivers\15867578.sys><N/A>
解决方法:
1、将以下文件上传到多引擎杀毒网上,如果有毒则安全模式下都删除掉。
C:\WINDOWS\WinRaR.exe>
C:\WINDOWSwinlogor.exe
C:\WINDOWS\intent.exe
C:\WINDOWSsourro.exe
C:\WINDOWS\winadr.exe
C:\WINDOWS\winnt.exe
C:\WINDOWS\SVchont.exe
C:\WINDOWS\system32\RacvSvc.EXE wdkqbgmsye.dll
C:\ProgramFiles\Outlook\Express\setup50.exe
2、貌似感染的文件挺多的,安全模式下全盘杀杀毒试试吧。