論壇說明 |
歡迎您來到『史萊姆論壇』 ^___^ 您目前正以訪客的身份瀏覽本論壇,訪客所擁有的權限將受到限制,您可以瀏覽本論壇大部份的版區與文章,但您將無法參與任何討論或是使用私人訊息與其他會員交流。若您希望擁有完整的使用權限,請註冊成為我們的一份子,註冊的程序十分簡單、快速,而且最重要的是--註冊是完全免費的! 請點擊這裡:『註冊成為我們的一份子!』 |
主題工具 | 顯示模式 |
2005-03-04, 11:34 AM | #1 |
整個系統會慢到受不了...可是關掉它之後..又會三不五時跑出來.. 試過用kav pro 5.0.20掃毒也完全沒有病毒.. 請問這是甚麼問題呢? |
送花文章: 7,
2005-03-04, 01:00 PM | #4 (permalink) |
When Backdoor.IRC.Zcrew.B is executed, it performs the following actions: Drops the following files in the C:\WINNT\system32\wbem\repository\fs\macromed folder: Spoolsv.exe- a Serv-U FTP server, packed with UPX The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.Disable System Restore (Windows Me/XP). Update the virus definitions. Do one of the following: Windows 95/98/Me: Restart the computer in Safe mode. Windows NT/2000/XP: End the Trojan process. Run a full system scan and delete all the files detected as Backdoor.IRC.Zcrew.B or IRC Trojan. Delete the folder C:\WINNT\system32\wbem\repository\fs\macromed. Reverse the changes that the Trojan made to the registry. |
__________________ |
送花文章: 2188,