|
发表于 2021-8-18 15:04:44
|
显示全部楼层
本帖最后由 q24655 于 2021-8-18 15:09 编辑
该文件为病毒 如不幸感染 处置建议如下 其次该程序还有远控
杀死进程
C:\Windows\System32\cmd.exe
删除服务
删除自启动注册表项
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Synaptics Pointing Device Driver
删除文件
- %HOMEPATH%\AppData\Local\Temp\ya5ABPvv.xlsm
- %HOMEPATH%\AppData\Local\Temp\短信测压.exe
- %HOMEPATH%\AppData\Local\Temp\ces.exe
- C:\tmp2gn2gx\._cache_ces.exe
- C:\tmp2gn2gx\._cache_短测.exe
- %HOMEPATH%\AppData\Local\Temp\短信测压.exe
- %HOMEPATH%\AppData\Local\Temp\Dm5PLxS9.ico
- %HOMEPATH%\AppData\Local\Temp\AGpyYBf.ini
- %HOMEPATH%\AppData\Local\Temp\E_4\krnln.fnr
- %HOMEPATH%\AppData\Local\Temp\ces.exe
- %HOMEPATH%\AppData\Local\Temp\ya5ABPvv.xlsm
- %HOMEPATH%\AppData\Local\Temp\E_4\shell.fne
- %HOMEPATH%\AppData\Local\Temp\短信测压.exe
- %HOMEPATH%\AppData\Local\Temp\ces.exe
- C:\tmp2gn2gx\._cache_ces.exe
- C:\tmp2gn2gx\._cache_短测.exe
|
|