|
|
re:说明:This password...
说明:<br>
<br>
This password杝tealing Trojan sends user passwords from infected systems to a specified email address using Simple Mail Transfer Protocol (SMTP). It also functions as a keylogger program and sends out other information, such as system information and Remote Access Service (RAS) information.<br>
<br>
解决方案:<br>
<br>
<br>
<br>
Open Registry Editor. Click Start>Run, type REGEDIT then hit the ENTER key. <br>
In the left panel, double click the following:<br>
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows><br>
CurrentVersion>Run <br>
In the right panel, locate and delete the registry entry: <br>
Modem Doctor 揅:\%Windir%\DR_MODEM.EXE?br> *Where %Windir% is the Windows directory, which is usually C:\Windows or C:\WINNT. <br>
Close Registry Editor. <br>
Terminate the malware program:<br>
On Windows 98:<br>
Restart your computer.<br>
On Windows NT\2000\XP:<br>
<br>
Open Task Manager. Press Ctrl+Shift+Esc simultaneously. <br>
Under the Processes tab, look for the process, DR_MODEM.EXE. <br>
Select the process then click the End Process button. <br>
Close Task Manager.<br>
Open Windows Explorer. Right-click Start and click Explore. <br>
Navigate to the Windows directory. <br>
Locate and delete the file:<br>
DR_MODEM.EXE <br>
Navigate to the Windows system directory, which is usually C:\Windows\System or C:\WINNT\System32. <br>
Locate and delete the file:<br>
AMDUPD.DLL <br>
Scan your system with Trend Micro antivirus and delete all files detected as TROJ_HOOKER24.B and TROJ_SCOUT.A. To do this Trend Micro customers must download the latest pattern file and scan their system. Other email users may use HouseCall, Trend Micro's free online virus scanner.<br>
|
|