|
論壇說明 |
歡迎您來到『史萊姆論壇』 ^___^ 您目前正以訪客的身份瀏覽本論壇,訪客所擁有的權限將受到限制,您可以瀏覽本論壇大部份的版區與文章,但您將無法參與任何討論或是使用私人訊息與其他會員交流。若您希望擁有完整的使用權限,請註冊成為我們的一份子,註冊的程序十分簡單、快速,而且最重要的是--註冊是完全免費的! 請點擊這裡:『註冊成為我們的一份子!』 |
|
主題工具 | 顯示模式 |
2003-11-29, 11:51 PM | #1 |
|
中毒了..T_T..怎麼辦....
我中毒了~早上起來開電腦時NORTON顯示中毒警示,
病毒名稱Backdoor.Graybird,無法存取檔案也無法刪除 檔案~那我該怎麼辦啊~怎麼刪都刪不掉,有哪位大大可以 教教我吗~謝謝... ps.該病毒在C:\WINDOWS\SYSTEM32\SVCHOST.EXE |
送花文章: 0,
|
2003-11-30, 12:09 AM | #2 (permalink) |
長老會員
|
隔離...
然後再到隔離區刪除這檔案 <試試吧> |
__________________ 地獄變現記 [人身得來不易,願大家能尊重生命--勿傷胎命][好淫者請好自為之吧--割鳥] 南泉禪師道: 「道不屬知,不屬不知。知是妄覺,不知是無記。若真達不疑之道,猶如太虛,廓然蕩豁,豈可強是非邪?」 德山宣鑒禪師: 「如果明白無事,則勿妄求,妄求而得,亦非得也。汝但無事於心,無心於事,則虛而靈,空而妙。若毛端許,言之本末者,皆為自欺。何故?毫氂繫念,三塗業因。瞥爾情生,萬劫羈鎖。聖名凡號,盡是虛聲。殊相劣形,皆是幻色。汝欲求之,得無累乎?」 |
|
送花文章: 5469,
|
2003-11-30, 05:58 PM | #7 (permalink) |
|
http://www.so-net.net.tw/service/announcement/virus/
這個網址看看,應該是疾風的變種 如果你沒有在執行輸入 shutdown -a 你從裝置管理員關掉它就會重新啟動電腦 很難搞的,如果你的作業系統沒有更新 殺掉病毒後馬上又會中 |
送花文章: 0,
|
2003-11-30, 09:07 PM | #9 (permalink) |
長老會員
|
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit Then click OK. (The Registry Editor opens.) Navigate to each of these the keys: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run NOTE: All the keys do not exist on all the systems. For each one, in the right pane, delete any of the following values: "svchost"="%System%\Svch0st.exe" "winlogon"="%System%\Winlogon.exe" "system"="%System%\Explorer.exe" If you are running Windows NT/2000/XP, navigate to the key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows In the right pane, delete the value: run %system%\svch0st.EXE Exit the registry editor. 4. Reversing the changes made to the Win.ini file If you are running Windows 95/98/Me, follow these steps: The function you perform depends on your operating system: Windows 95/98: Go to step b. Windows Me: If you are running Windows Me, the Windows Me file-protection process may have made a backup copy of the Win.ini file that you need to edit. If this backup copy exists, it will be in the C:\Windows\Recent folder. Symantec recommends deleting this file before continuing with the steps in this section. To do this: Start Windows Explorer. Browse to and select the C:\Windows\Recent folder. In the right pane, select the Win.ini file and delete it. The Win.ini file will be regenerated when you save your changes to it in step f. For each one, in the right pane, delete any of the following values: "svchost"="%System%\Svch0st.exe" "winlogon"="%System%\Winlogon.exe" "system"="%System%\Explorer.exe" If you are running Windows NT/2000/XP, navigate to the key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows In the right pane, delete the value: run %system%\svch0st.EXE Exit the registry editor. 開始->執行->regedit 然後到 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 這三各地方看看有無以下直,若有按滑鼠右鍵刪除 "svchost"="%System%\Svch0st.exe" "winlogon"="%System%\Winlogon.exe" "system"="%System%\Explorer.exe" 若是NT/2000/XP則到 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows 刪除以下值 run %system%\svch0st.EXE 離開 Click Start, and then click Run. Type the following: edit c:\windows\win.ini and then click OK. (The MS-DOS Editor opens.) NOTE: If Windows is installed in a different location, make the appropriate path substitution. In the [windows] section of the file, look for a line similar to: run=C:\WINDOWS\SYSTEM\SVCH0ST.EXE If this line exists, delete the entire line. Click File, and then click Save. Click File, and then click Exit. 開始->執行->edit c:\windows\win.ini 到[windows]這區找找有無此行run=C:\WINDOWS\SYSTEM\SVCH0ST.EXE? 若有刪除此行,然後存檔,注意win.ini是隱藏加唯讀檔喔 <參考看看啦,因為小弟也是各英痴> |
送花文章: 5469,
|
2003-11-30, 10:29 PM | #10 (permalink) | |
|
引用:
|
|
送花文章: 0,
|