瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 向前来求助的朋友呼吁一下【建议】

123456   2  /  6  页   跳转

向前来求助的朋友呼吁一下【建议】

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
另外不言
我想问一下
这个路径找到后,下面要怎么修改呢?
gototop
 

谢谢提示。
gototop
 

【回复“baohe”的帖子】
Worm.Brontok.ea

病毒类型:蠕虫
病毒行为:
1、加入启动菜单:empty

2、添加如下注册表键值:

HKLM\software\microsoft\windows\currentversion\run\
Bron-Spizaetus = "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Shell = "Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe""

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\
AlternateShell = "cmd-brontok.exe"

HKCU\software\microsoft\windows\currentversion\Policies\System\
DisableCMD = 0x0

HKCU\software\microsoft\windows\currentversion\Policies\Explorer\
NoFolderOptions = 0x1

HKCU\software\microsoft\windows\currentversion\run\
Tok-Cirrhatus-1464 = "C:\Documents and Settings\Admin\Local Settings\Application Data\br3951on.exe"

HKCU\software\microsoft\windows\currentversion\run\
Tok-Cirrhatus = ""

HKCU\software\microsoft\windows\currentversion\explorer\advanced\
Hidden = 0x0

HKCU\software\microsoft\windows\currentversion\explorer\advanced\
HideFileExt = 0x1

HKCU\software\microsoft\windows\currentversion\explorer\advanced\
ShowSuperHidden = 0x0

HKCU\software\microsoft\windows\currentversion\Policies\System\
DisableRegistryTools = 0x1

3、生成如下病毒文件

C:\Documents and Settings\Admin\Local Settings\Application Data\目录下:

services.exe; lsass.exe; winlogon.exe; smss.exe; inetinfo.exe; csrss.exe;

br3951on.exe; Loc.Mail.Bron.Tok\caishanfeng@yahoo.com.cn.ini; Ok-SendMail-Bron-tok\; Bron.tok-16-24\;

C:\Documents and Settings\Admin\Templates\6084-NendangBro.com

C:\Documents and Settings\Admin\My Documents\My Pictures\about.Brontok.A.html

系统目录下:%systemroot%\ShellNew\Rakyatkelaparan.exe;

%systemroot%\KesenjanganSosial.exe;

%system%\cmd-brontok.exe;

4、调用at.exe将C:\Documents and Settings\Admin\Templates\6084-NendangBro.com设定为计划任务

gototop
 

现在开机总是会出现
下面这两个图
请问是怎么回事?

附件附件:

下载次数:139
文件类型:image/pjpeg
文件大小:
上传时间:2006-5-10 8:59:51
描述:



gototop
 


中毒
gototop
 

我的机子用瑞星查不出病毒,但是有很多不对劲的地方,最近启动速度变很慢了,原来1分钟现在要5分钟,还有就是IE主页始终是空白页,变的不能更改了
gototop
 

进来看戏   吃西瓜的狮子快被逼疯了
gototop
 

【回复“如晨雪花2008”的帖子】
开始--运行
输入regedit
确定
进入注册表

修改
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe"C:\WINDOWS\KesenjanganSosial.exe">

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>

修改
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\
AlternateShell = "cmd-brontok.exe"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\
AlternateShell = "cmd.exe"

修改
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\explorer\advanced
"Hidden"="0"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\explorer\advanced
"Hidden"="2"

修改
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\explorer\advanced
"HideFileExt"="1"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\explorer\advanced
"HideFileExt"="0"

删除如下自启动项:
HKLM\software\microsoft\windows\currentversion\run\
Bron-Spizaetus = "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"

HKCU\software\microsoft\windows\currentversion\run\
Tok-Cirrhatus-1464 = "C:\Documents and Settings\用户名\Local Settings\Application Data\br3951on.exe"

HKCU\software\microsoft\windows\currentversion\run\
Tok-Cirrhatus = ""

HKLM\SoftWare\Microsoft\Windows\CurrentVersionWinlogon\Shell
Bron-Spizaetus="C:\WINDOWS\ShellNew\RakyatKelaparan.exe"

============

删除如下文件:
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\br8241on.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\csrss.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\inetinfo.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\services.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\smss.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\svchoost.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\lsass.exe
C:\DocumentsandSettings\administrator\LocalSettings\ApplicationData\winlogon.exe
C:\WINDOWS\System32\administrator'ssetting.exe
C:\WINDOWS\System32\cmd-brontok.exe
C:\WINDOWS\KesenjanganSosial.exe
C:\WINDOWS\ShellNew\RakyatKelaparan.exe
C:\DocumentsandSettings\administrator\[开始]菜单\程序\启动\empty.pif
gototop
 

不言
我找到了相关的目录
但是不知道怎么进行修改
如图

等待您的回复
谢谢
辛苦了

附件附件:

下载次数:143
文件类型:image/pjpeg
文件大小:
上传时间:2006-5-10 15:48:13
描述:



gototop
 

【回复“如晨雪花2008”的帖子】
在注册表进行修改操作时:
在待修改的名称上右击--修改

在注册表中进行删除操作时:
在待删除的名称上右击--删除
gototop
 
123456   2  /  6  页   跳转
页面顶部
Powered by Discuz!NT