| 引用: |
【深圳阿平的贴子】救命呀 ........................... |
C:\WINNT\system32\NTdhcp.exe
打开任务管理器,结束进程“NTdhcp.exe
删除隐藏文件“%SYSTEM%\NTdhcp.exe
打开注册表编辑器,删除注册表启动项
HKEY_LOCAL_MACHINE\SoftWare\Microsoft\Windows\CurrentVersion\Run
下的值:"NTdhcp"="%SYSTEM%\NTdhcp.exe"
如果程序恢复后,请先在安全模式下用最新版杀毒软件彻底查杀
O23 - NT 服务: Gray_Pigeon (GrayPigeonServer) - Unknown owner - C:\WINNT\lasss.exe (file missing)
O23 - NT 服务: Logical Disk Managesir - Unknown owner - C:\WINNT\G_Server2.0.exe
O23 - NT 服务: Remote Piocedure Call - Unknown owner - C:\WINNT\system2.0.exe
O23 - NT 服务: Spplication Layer Gateway Serv - Unknown owner - C:\WINNT\bdc.exe
O23 - NT 服务: Telnet Shell - Unknown owner - C:\WINNT\BDC.exe
查杀参考http://forum.ikaka.com/topic.asp?board=28&artid=6202404
还有
O4 - 启动项HKLM\\Run: [csrss] C:\WINNT\csrss.exe
O4 - 启动项HKLM\\RunServices: [csrss] C:\WINNT\csrss.exe
O4 - HKCU\..\Run: [csrss] C:\WINNT\csrss.exe
O4 - HKCU\..\RuunServices:[csrss] C:\WINNT\csrss.exe比较可疑