我是个小鸟,只看到了这些做为参考
注册表:
<u1g3><C:\DOCUME~1\new\LOCALS~1\Temp\crasos.exe> []
<upxdnd><C:\DOCUME~1\new\LOCALS~1\Temp\upxdnd.exe> []
<cmdbcs><C:\WINDOWS\cmdbcs.exe> []
加载的可疑进程
[C:\DOCUME~1\new\LOCALS~1\Temp\LgSy0.dll] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\Msxo0.dll] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\Gjzo0.dll] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\Rav20.dll] [N/A, ]
[C:\DOCUME~1\new\LOCALS~1\Temp\LgSy1.dll] [N/A, ]
host里面把除了127.0.0.1 localhost以外的都删掉