1   1  /  1  页   跳转

smoked.exe这个病毒怎么弄掉啊

smoked.exe这个病毒怎么弄掉啊

我中了这个病毒,上网后QQ,资源管理器全不能用,这个怎么杀,杀毒说没有病毒啊
最后编辑2005-11-01 09:10:20
分享到:
gototop
 

【回复“失落的真心”的帖子】

请把此文件压缩加密为virus发到我的邮箱  rsvirus@163.com 并注明此贴地址我会尽快做处理,谢谢合作。

》》如何压缩加密?----http://forum.ikaka.com/topic.asp?board=67&artid=7241343
gototop
 

请将该文件打包发送至fangrensong@yahoo.com.cn
gototop
 

我在注册表里还有MSCONFIG里将他删了,进安全模式下这个文件不见了,让我郁闷,摸不着头脑了
gototop
 

病毒资料——W32/Rbot-ALN
  
  This section is for technical experts who want to know more.
  
  W32/Rbot-ALN is a worm and IRC backdoor Trojan for the Windows platform.
  
  W32/Rbot-ALN spreads:
  
  
  
  - to other network computers infected with W32/MyDoom
  - to other network computers by exploiting common buffer overflow vulnerabilites, including: LSASS (MS04-011), RPC-DCOM (MS04-012) and WKS (MS03-049) (CAN-2003-0812)
  - by copying itself to network shares protected by weak passwords
  
  
  
  The following patches for the operating system vulnerabilities exploited by W32/Rbot-ALN can be obtained from the Microsoft websites:
  
  
  
  MS03-049
  
  
  
  MS04-011
  
  
  
  MS04-012
  
  
  
  When first run W32/Rbot-ALN copies itself to <System>\Smoked.exe and creates the file <Temp>\C27D8FEF-D7AE-42c0-82E6-F30598265639.exe.
  
  
  
  The following registry entries are created to run Smoked.exe on startup:
  
  
  
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  MicroedSoft Toolbar
  Smoked.exe
  
  
  
  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
  Smoked.exe
  
  
  
  The following registry entry is set:
  
  
  
  HKCU\Software\Microsoft\OLE
  MicroedSoft Toolbar
  Smoked.exe
  
  
  
  W32/Rbot-ALN runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
  
  
  
  W32/Rbot-ALN can be instructed t
  
  
  
  Scan for remote computers to spread to
  Act as an HTTP or an FTP proxy server
  Log any keystrokes made on an infected computer
  Steal product leys
  Upload, download, search for, and execute files
  Participate in distributed denial-of-service (DDoS) attacks
  Create, delete, start, and stop services
gototop
 

我照上面的把注册表的关联,还有文件本身全删了,可是还是有问题,不会让我重做系统吧,我要疯了,瑞星查不出问题
gototop
 

把可疑的文件夹删掉呢?比如说网页缓存之类的?试下哈?
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT