病毒文件
<svcshare><C:\WINDOWS\system32\drivers\spoclsv.exe> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><C:\windows\system32\wincfgs.exe> [N/A]
<svrhost><; C:\WINDOWS\system32\svrhost.exe> [N/A]
C:\WINDOWS\system32\zsyhide.dll
Autorun.inf
[C:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[D:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[E:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
[F:\]
[AutoRun]
OPEN=setup.exe
shellexecute=setup.exe
shell\Auto\command=setup.exe
用冰刃到注册表下找到
<svcshare><C:\WINDOWS\system32\drivers\spoclsv.exe> [N/A]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><C:\windows\system32\wincfgs.exe> [N/A]
<svrhost><; C:\WINDOWS\system32\svrhost.exe> [N/A]
删除
然后安全模式下用ICESWORD删除每个盘符下的AUTORUN.INF和SETUP.EXE和病毒文件