【原创】关于超级垃圾木马alewiangyu872.exe的清除方法.★★★★
木马行为:
运行后,释放一个services.exe到C:\windows\下.
注册表多处修改.
HJ日志表现:
O4 - HKLM\..\Run: [services] C:\windows\services.exe
O4 - HKLM\..\RunServices: [services] C:\windows\services.exe
O4 - HKCU\..\Run: [services] C:\windows\services.exe
O4 - HKCU\..\RunServices: [services] C:\windows\services.exe
开始菜单中添加:
phedzzhizi.exe
yiyujrdhj.exe
(靠,练我的英文输入啊.)
清除方法:
用HJ修复:
O4 - HKLM\..\Run: [services] C:\windows\services.exe
O4 - HKLM\..\RunServices: [services] C:\windows\services.exe
O4 - HKCU\..\Run: [services] C:\windows\services.exe
O4 - HKCU\..\RunServices: [services] C:\windows\services.exe
最好用SSM阻止C:\windows\services.exe运行
删除:C:\windows\services.exe
清理开始菜单..
剩下的,用瑞星杀吧...
------------------
PS:此木马会在任何文件夹下都生成副本.导致硬盘空间极速减少....
偶只开了single shadow,DEF盘都没保护.....
偶先用瑞星杀毒去了呵.....