【回复“北极大白熊”的帖子】
建议用IceSword手工杀毒。操作流程如下:
1、禁止进程创建。
2、结束下列进程:
[PID: 1552 / Administrator][C:\WINDOWS\system32\crsss.exe] [N/A, ]
[PID: 1688 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1748 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2004 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2036 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 152 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 176 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 248 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1784 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 360 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1204 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1324 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1696 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1736 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1872 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1120 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1880 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1940 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1508 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1992 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 980 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1168 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1248 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1428 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1732 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1316 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1240 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1892 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 420 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1292 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1904 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1308 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1808 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2076 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2112 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2144 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2176 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2200 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2224 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2248 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2280 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2304 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2328 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2352 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2396 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2432 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2464 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2500 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2524 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2548 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2572 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2596 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2636 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2660 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2696 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2728 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2752 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2792 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2844 / Administrator][C:\WINDOWS\system32\REG.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
3、删除下列文件:
C:\WINDOWS\system32\crsss.exe
CDE分区根目录下的Autorun.inf和niu.exe
4、删除下列注册表项:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]分支下的:
crsss(指向C:\WINDOWS\system32\crsss.exe)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options分支下的所有指向C:\WINDOWS\system32\crsss.exe的子键。
5、取消IceSword的“禁止进程创建”。