新病毒像威金一样
Autorun.inf
[C:\]
[AutoRun]
open=rising.exe
shellexecute=rising.exe
shell\Auto\command=rising.exe
(c:\windows\system32\rising.exe)
[1344] C:\WINDOWS\system32\winsock.exe
[3748] C:\WINDOWS\system32\k11150495839.exe
[C:\WINDOWS\system32\msccrt.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbs.dll] [N/A, ]
[C:\WINDOWS\system32\winform.dll] [N/A, ]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\WINDOWS\system32\31C3E83C.DLL] [Microsoft Corporation, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
<Kvsc3><C:\WINDOWS\Kvsc3.exe> []
<junhui><C:\WINDOWS\junhui.exe /i> []
<cmdbs><C:\WINDOWS\cmdbs.exe> []
<msccrt><C:\WINDOWS\msccrt.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<WoptiClean><rundll32.exe "C:\Program Files\Wopti\WoptiCleanDll.dll",CleanNextBoot "C:\Program Files\Wopti\\WoptiClean"> [N/A]
[Ctrl2cap / Ctrl2cap][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\Ctrl2cap.sys><N/A>
[dump_wmimmc / dump_wmimmc][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\drivers\dump_wmimmc.sys><N/A>
[31C3E83C / 31C3E83C][Stopped/Auto Start]
<C:\WINDOWS\system32\31C3E83C.EXE -k><Microsoft Corporation>
[Wireless Zero Conflguration / inetsvr][Stopped/Auto Start]
<C:\WINDOWS\system32\buchehuo.exe><Cutting Edge Custom Software>(这个是你装的吗??)
[oreans32 / oreans32][Running/System Start]
<\??\C:\WINDOWS\system32\drivers\oreans32.sys><N/A>