你在胡扯,这个病毒在注册表里是加在 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcPatch and HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcTftpd blaster 才加在上述键位,不要想当然
s*o
2 楼
FYI: Manual Removal Instructions To remove this virus "by hand", follow these steps: 1.Apply the MS03-026 patch from http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bu lletin/MS03-026.asp 2.Terminate the following services : WINS Client Network Connections Sharing Delete the DLLHOST.EXE and SVCHOST.EXE files from the WINS directory with your WINDOWS SYSTEM32 directory. For example, c:\winnt\system32\wins\svchost.exe. Note: a legitimate system file exists with the file