根据该文件下载并运行以下文件
5、下载文件:http://z1.us-2.net/aaa.txt
根据该文件下载并运行以下文件
http://aa1.1a2b3c1.com/*****/1.exe
http://aa1.1a2b3c1.com/*****/2.exe
http://aa1.1a2b3c1.com/*****/3.exe
http://aa1.1a2b3c1.com/*****/4.exe
http://aa1.1a2b3c1.com/*****/5.exe
http://aa1.1a2b3c1.com/*****/6.exe
http://aa1.1a2b3c1.com/*****/7.exe
http://aa1.1a2b3c1.com/*****/8.exe
http://aa1.1a2b3c1.com/*****/9.exe
http://aa1.1a2b3c1.com/*****/10.exe
http://aa2.1a2b3c1.com/*****/11.exe
http://aa2.1a2b3c1.com/*****/12.exe
http://aa2.1a2b3c1.com/*****/13.exe
http://aa2.1a2b3c1.com/*****/14.exe
http://aa2.1a2b3c1.com/*****/15.exe
http://aa2.1a2b3c1.com/*****/16.exe
http://aa2.1a2b3c1.com/*****/17.exe
http://aa2.1a2b3c1.com/*****/18.exe
http://aa2.1a2b3c1.com/*****/19.exe【链接失效】
http://aa2.1a2b3c1.com/*****/20.exe
http://aa3.1a2b3c1.com/*****/21.exe
http://aa3.1a2b3c1.com/*****/22.exe
http://aa3.1a2b3c1.com/*****/23.exe【链接失效】
http://aa3.1a2b3c1.com/*****/24.exe
http://aa3.1a2b3c1.com/*****/25.exe
http://aa3.1a2b3c1.com/*****/26.exe
http://aa3.1a2b3c1.com/*****/27.exe
http://aa3.1a2b3c1.com/*****/28.exe
http://aa3.1a2b3c1.com/*****/29.exe
http://aa3.1a2b3c1.com/*****/30.exe
http://aa3.1a2b3c1.com/*****/31.exe
http://aa3.1a2b3c1.com/*****/32.exe
http://aa3.1a2b3c1.com/*****/33.exe
http://aa3.1a2b3c1.com/*****/34.exe
http://aa3.1a2b3c1.com/*****/35.exe【链接失效】
http://60.190.***.***/080405.exe
6、修改explore.exe,使用户对任务栏的操作失效
7、利用磁盘驱动技术,穿透还原卡保护
二、解决方案
推荐方案:
下载超级巡警机器狗专杀工具,查杀病毒。
下载地址:http://www.dswlab.com/d2.html
手工清除方法:
1、结束explorer.exe进程,拷贝%SystemRoot%\dllcache文件夹下的explorer.exe覆盖%SystemRoot%文件夹下的 explorer.exe
2、删除病毒生成的文件:
%SystemRoot%\temp.dat
3、删除病毒添加的注册表: [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable"=DWORD:00000000
[HKEY_CURRENT_CONFIG\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable"=DWORD:00000000

网友评论