史上超强磁碟机病毒 中毒之后解决思路

互联网 | 编辑: 杨剑锋 2008-03-20 00:30:00转载 一键看全文

病毒难以删除

9.运行autoruns,发现Appinit_dlls有异常加载,文件为c:windowssystem32dnsq.dll,这个正是磁碟机病毒注入的dll文件,在很多系统进程中都有注入,强行删除或结束该线程会立即导致蓝屏重启。

尝试用autoruns删除病毒修改的加载项,刷新后很快发现又回来了,证明在清除病毒前,修改注册表键是毫无用处的。
screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.style.cursor='hand'; this.alt='Click here to open new windownCTRL+Mouse wheel to zoom in/out';}" onclick="if(!this.resized) {return true;} else {window.open('http://bbs.duba.net/attachments/month_0802/20080228_1fcef0e52e6265d525f6rUsU4lXoPwZQ.png');}" height=375 alt="" src="http://bbs.duba.net/attachments/month_0802/20080228_1fcef0e52e6265d525f6rUsU4lXoPwZQ.png" width=500 onload="if(this.width>screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.alt='Click here to open new windownCTRL+Mouse wheel to zoom in/out';}" border=0>

10.准备使用Process Explorer,结果很快该程序失去响应。
screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.style.cursor='hand'; this.alt='Click here to open new windownCTRL+Mouse wheel to zoom in/out';}" onclick="if(!this.resized) {return true;} else {window.open('http://bbs.duba.net/attachments/month_0802/20080228_2413412f53124a9c1971ermAuVk8phJP.png');}" height=375 alt="" src="http://bbs.duba.net/attachments/month_0802/20080228_2413412f53124a9c1971ermAuVk8phJP.png" width=500 onload="if(this.width>screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.alt='Click here to open new windownCTRL+Mouse wheel to zoom in/out';}" border=0>

11.运行AV终结者专杀,发现安全模式被破坏,硬盘根目录有autorun.inf,以及(AV终结者变种av_killer.j的感染信息)
screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.style.cursor='hand'; this.alt='Click here to open new windownCTRL+Mouse wheel to zoom in/out';}" onclick="if(!this.resized) {return true;} else {window.open('http://bbs.duba.net/attachments/month_0802/20080228_5b26e99856e030ccd4d5PVLYhf4pS4RE.png');}" height=375 alt="" src="http://bbs.duba.net/attachments/month_0802/20080228_5b26e99856e030ccd4d5PVLYhf4pS4RE.png" width=500 onload="if(this.width>screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.alt='Click here to open new windownCTRL+Mouse wheel to zoom in/out';}" border=0>

12.运行冰刃和Sreng均宣告失败,运行毒霸打狗棒未发现任何异常,以此可以排除机器狗病毒。

提示:试试键盘 “← →” 可以实现快速翻页 

一键看全文

本文导航

相关阅读

每日精选

点击查看更多

首页 手机 数码相机 笔记本 游戏 DIY硬件 硬件外设 办公中心 数字家电 平板电脑