抢小生的沙发!F3 - REG:win.ini: load=C:\WINDOWS\rundl132.exe
这个就是病毒,资料见:
http://topchn.cnfan.net/?action/viewspace/itemid/72具体说这么清除——
删除
C:\WINDOWS\rundl132.exe
C:\Program Files\svhost32.exe
C:\WINDOWS\System32\ztdll.dll
以下文件如果有,也都删除
C:\WINDOWS\1.com
C:\WINDOWS\1SY.EXE
C:\WINDOWS\smss.exe
C:\WINDOWS\finders.com
C:\WINDOWS\EXP10RER.com
C:\WINDOWS\exerouter.exe
C:\WINDOWS\System32\rund1132.com
C:\WINDOWS\System32\command.pif
C:\WINDOWS\System32\MSCONFIG.COM
C:\WINDOWS\System32\dxdiag.com
C:\WINDOWS\System32\regedit.com
C:\WINDOWS\Debug\DebugProgram.exe
C:\progra~1\intern~1\inexplore.com
C:\progra~1\common~1\inexplore.pif
C:\WINDOWS\2SY.EXE
C:\WINDOWS\LSASS.exe
C:\WINDOWS\EXERT.exe
C:\WINDOWS\System32\MSCONFIG.COM
C:\WINDOWS\System32\dxdiag.com
C:\WINDOWS\System32\regedit.com
C:\WINDOWS\Debug\DebugProgram.exe
C:\progra~1\intern~1\INTEXPLORE.com
C:\progra~1\common~1\INTEXPLORE.pif
D:\command.com
D:\command.com
D:\_desktop.ini
搜索vDll.dll并删除。
在注册表里头清理
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
"load"="C:\WINDOWS\rundl132.exe"
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
"load"="C:\PROGRA~1\svhost32.exe"
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN
"TProgram"="C:\WINDOWS\smss.exe"
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN
"ToP"="C:\WINDOWS\LSASS.exe"
以下注册表项如果能找到,也都清理干净——
HKLM\SOFTWARE\Classes\htmlfile\shell\open\command
(Default)=""C:\Program Files\Internet Explorer\inexplore.com" -nohome"
HKCR\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command
(Default)=""C:\Program Files\Internet Explorer\inexplore.com""
HKCR\ftp\shell\open\command
(Default)=""C:\Program Files\Internet Explorer\inexplore.com" %1"
HKCR\htmlfile\shell\open\command
(Default)=""C:\Program Files\Internet Explorer\inexplore.com" -nohome"
HKCR\htmlfile\shell\opennew\command
(Default)=""C:\Program Files\common~1\inexplore.pif""
HKCR\http\shell\open\command
(Default)=""C:\Program Files\common~1\inexplore.pif" -nohome"
HKLM\SOFTWARE\Classes\http\shell\open\command
(Default)=""C:\Program Files\common~1\inexplore.pif" -nohome"
HKCR\Drive\shell\find\command
(Default)="%SystemRoot%\EXP10RER.com"
HKLM\SOFTWARE\Classes\htmlfile\shell\open\comman
(Default)=""C:\Program Files\Internet Explorer\inexplore.com" -nohome"
HKCR\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command
(Default)=""C:\Program Files\Internet Explorer\inexplore.com""
HKCR\ftp\shell\open\command
(Default)=""C:\Program Files\Internet Explorer\inexplore.com" %1"
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Cookies="C:\Documents and Settings\jjwen1\Cookies"
HKCR\htmlfile\shell\open\command
(Default)=""C:\Program Files\Internet Explorer\inexplore.com" -nohome"
HKCR\htmlfile\shell\opennew\command
(Default)=""C:\Program Files\common~1\inexplore.pif""
HKCR\http\shell\open\command
(Default)=""C:\Program Files\common~1\inexplore.pif" -nohome"
HKLM\SOFTWARE\Classes\http\shell\open\command
(Default)=""C:\Program Files\common~1\inexplore.pif" -nohome"
HKCR\WindowFiles\shell\open\command
(Default)="C:\WINDOWS\EXERT.exe "%1" %*"
HKCR\.exe
(Default)="WindowFiles"
完了。
另外:
O23 - Service: Supplicant Service - Unknown owner - C:\WINDOWS\system32\SuService.exe
这个网上没人说明白了它是什么,但是
http://help.lockergnome.com/general/default-ftopict17023.html 和
http://www.castlecops.com/modules.php?name=Forums&file=viewtopic&p=136133 两个大佬级论坛都建议修复掉。
又及:
楼兰的卡巴是直接安装在D盘根目录下面的?很特别。