msusvc.exe(Backdoor.Win32.RBot.gen卡巴斯基命名)是个后门。查杀方法如下:
1、结束病毒进程msusvc.exe。
2、删除%system%文件夹中的病毒文件msusvc.exe。
3、清理注册表:
(1)展开:HKEY_CURRENT_USER\Software\Microsoft\OLE
删除:"Microsoft Winsock Service"="msusvc.exe"
(2)展开:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
删除:"Microsoft Winsock Service"="msusvc.exe"
(3)展开:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices
删除:"Microsoft Winsock Service"="msusvc.exe"
(4)展开:HKEY_CURRENT_USER\SYSTEM\CurrentControlSet\Control\Lsa
删除:"Microsoft Winsock Service"="msusvc.exe"
(5)展开:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole
删除:"Microsoft Winsock Service"="msusvc.exe"
(6)展开:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
删除:"Microsoft Winsock Service"="msusvc.exe"
(7)展开:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
删除:"Microsoft Winsock Service"="msusvc.exe"
(8)展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
删除:"Microsoft Winsock Service"="msusvc.exe"
4、删除hosts文件中下列内容:
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 kaspersky-labs.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 pandasoftware.com
127.0.0.1 www.pandasoftware.com
127.0.0.1 www.trendmicro.com
127.0.0.1 www.grisoft.com
127.0.0.1 www.microsoft.com
127.0.0.1 microsoft.com
127.0.0.1 www.virustotal.com
127.0.0.1 virustotal.com
5、运行WINDOWS UPDATE,打全系统补丁。