引用:
作者: theonlyone
我也中了
有人會解嗎.......
End of file - 16349 bytes
|
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe
O4 - HKCU\..\RunOnce: [FFTI] C:\Documents and Settings\俊宇\Application Data\Mozilla\Firefox\Profiles\umx8mb43.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /DestPath="C:\Documents and Settings\俊宇\Application Data\Mozilla\Firefox\Profiles/umx8mb43.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}"
O9 - Extra button: KeePasser - {C8C06F74-3F06-44a3-BD56-75C39C44973F} - C:\Program Files\KeePass\IE\keepasser.htm (file missing)
勾選並修復上述項目, 重新開機, 以安全模式登入 windows, 搜尋所有硬碟分區並刪除下列檔案:
kavo.exe
autorun.inf
ntdelect.com (注意別刪錯: NTDETECT.COM 是系統檔, ntdelect.com 是木馬)