【求助】请问这份扫描报告如何解读?
我用木马杀客和微软的Windows Defender都查出了在F盘WINDOWS\Installer\68da6c.msi下有木马,不过无法删:
以下是报告。
Category:
Spyware
Description:
This program has potentially unwanted behavior.
Advice:
Remove this software immediately.
Resources:
regkey:
HKCU@S-1-5-21-1873363398-1158903941-3698187583-500\software\3721
file:C:\WINDOWS\Installer\68da6c.msi->(MSI Stream 63)->(WiseSfx)->(wise0019)
file:C:\WINDOWS\Installer\68da6c.msi->(MSI Stream 63)->(WiseSfx)->(wise0018)
file:C:\WINDOWS\Installer\68da6c.msi->(MSI Stream 63)->(WiseSfx)->(wise0017)
file:C:\WINDOWS\Installer\68da6c.msi->(MSI Stream 63)->(WiseSfx)->(wise0016)
file:F:\System Volume Information\_restore{F4E28266-5B76-48BF-AFB4-431B85B359C3}\RP245\A0071767.exe->(WiseSfx)->(wise0019)
file:F:\System Volume Information\_restore{F4E28266-5B76-48BF-AFB4-431B85B359C3}\RP245\A0071767.exe->(WiseSfx)->(wise0018)
file:F:\System Volume Information\_restore{F4E28266-5B76-48BF-AFB4-431B85B359C3}\RP245\A0071767.exe->(WiseSfx)->(wise0017)
file:F:\System Volume Information\_restore{F4E28266-5B76-48BF-AFB4-431B85B359C3}\RP245\A0071767.exe->(WiseSfx)->(wise0016)
View more information about this item online
---------------------------------------------------
请问该如何删除?我查了百度,有人说是要关了系统还原,可是我是WIN 2003企业版的,没有系统还原功能。
我用EWIDO分析启动项,找到一个怪怪的:
应用程序 位置 路径
%1 %* Registry\HKCR\exefile\shell\runas %1 %*
这是什么启动程序?
谢谢