标题: 这是什么病毒 (急!!!!!!!!) [打印本页] 作者: thm0908 时间: 2005-1-3 11:13 标题: 这是什么病毒 (急!!!!!!!!) 今天我们公司有台电脑中了"troj.hooker.p"这种病毒,请教各位这是什么病毒,该怎么清除,我用的趋势杀毒查杀不了,请各位指教,谢谢了!作者: 790059 时间: 2005-1-3 11:47 标题: re:说明:This password... 说明:<br>
<br>
This password杝tealing Trojan sends user passwords from infected systems to a specified email address using Simple Mail Transfer Protocol (SMTP). It also functions as a keylogger program and sends out other information, such as system information and Remote Access Service (RAS) information.<br>
<br>
解决方案:<br>
<br>
<br>
<br>
Open Registry Editor. Click Start>Run, type REGEDIT then hit the ENTER key. <br>
In the left panel, double click the following:<br>
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows><br>
CurrentVersion>Run <br>
In the right panel, locate and delete the registry entry: <br>
Modem Doctor 揅:\%Windir%\DR_MODEM.EXE?br> *Where %Windir% is the Windows directory, which is usually C:\Windows or C:\WINNT. <br>
Close Registry Editor. <br>
Terminate the malware program:<br>
On Windows 98:<br>
Restart your computer.<br>
On Windows NT\2000\XP:<br>
<br>
Open Task Manager. Press Ctrl+Shift+Esc simultaneously. <br>
Under the Processes tab, look for the process, DR_MODEM.EXE. <br>
Select the process then click the End Process button. <br>
Close Task Manager.<br>
Open Windows Explorer. Right-click Start and click Explore. <br>
Navigate to the Windows directory. <br>
Locate and delete the file:<br>
DR_MODEM.EXE <br>
Navigate to the Windows system directory, which is usually C:\Windows\System or C:\WINNT\System32. <br>
Locate and delete the file:<br>
AMDUPD.DLL <br>
Scan your system with Trend Micro antivirus and delete all files detected as TROJ_HOOKER24.B and TROJ_SCOUT.A. To do this Trend Micro customers must download the latest pattern file and scan their system. Other email users may use HouseCall, Trend Micro's free online virus scanner.<br> 作者: thm0908 时间: 2005-1-3 11:51 标题: re:这个我早试过,这是趋势的发现的另外一种病... 这个我早试过,这是趋势的发现的另外一种病毒,我发现的这种病毒根本在注册表里找不到这些键值,但是又有这种病毒,不知道为何.作者: 790059 时间: 2005-1-3 12:14 标题: re:在安全模式下清除能有用嗎?病毒無非就是以... 在安全模式下清除能有用嗎?病毒無非就是以進程存在的,把進程停了還清不了嗎?我還沒有試過清不了的毒.清完了在清注冊表和啟動項,還有了解這個病毒的發作過程,不是每种病毒清除都是以一种方試進行的,這只是一种思路作者: thm0908 时间: 2005-1-3 13:29 标题: re:是呀,我現在就是不知道這種病毒是哪個進程... 是呀,我現在就是不知道這種病毒是哪個進程,也不知道這個病毒文件,更加不知道注冊表裏面的項目呀,請指教!作者: 790059 时间: 2005-1-3 13:52 标题: re:对了简单一点你可以换一个杀毒软体试一下,... 对了简单一点你可以换一个杀毒软体试一下,比如说瑞星,它的杀毒能力比较强一点.对troj.hooker.p这个毒不是很了解.作者: 790059 时间: 2005-1-3 13:52 标题: re:对了简单一点你可以换一个杀毒软体试一下,... 对了简单一点你可以换一个杀毒软体试一下,比如说瑞星,它的杀毒能力比较强一点.对troj.hooker.p这个毒不是很了解.作者: thm0908 时间: 2005-1-7 09:19 标题: re:谢谢各位指教,我已经解决了,主要是注册表... 谢谢各位指教,我已经解决了,主要是注册表里面多了一些不该有的东西.