C:\WINDOWS\services.exe
F3 - REG:win.ini: run=C:\WINDOWS\services.exe
O4 - 启动项HKLM\\Run: [services] C:\WINDOWS\services.exe
O4 - 启动项HKLM\\RunServices: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\RuunServices:[services] C:\WINDOWS\services.exe
木马.
试试:
1.启动到安全模式(启动电脑,开机检测完后,按[F8]键(可以一直按到启动菜单出来为止),选择安全模式进入Windows).
用HijackThis修复:
F3 - REG:win.ini: run=C:\WINDOWS\services.exe
O4 - 启动项HKLM\\Run: [services] C:\WINDOWS\services.exe
O4 - 启动项HKLM\\RunServices: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\RuunServices:[services] C:\WINDOWS\services.exe
2.终止木马进程services.exe(推荐用IcesWord,新版卡卡也不错,可以看到进程的路径.同时按下CTRL+ALT+DELETE任务管理器看不到路径,有个同名的正常进程,小心!)
3.删除木马文件C:\WINDOWS\services.exe(注意路径,C:\WINDOWS\system32\services.exe是正常的).
4.进入注册表清理:
HKLM\\Run: [services] C:\WINDOWS\services.exe
HKLM\\RunServices: [services] C:\WINDOWS\services.exe
HKCU\..\Run: [services] C:\WINDOWS\services.exe
HKCU\..\RuunServices:[services] C:\WINDOWS\services.exe
重启到正常模式.