Trojan.PSW.QQPass(QQéè¡è¯)åæå解å³æ¹æ³
http://www.pcav.cn/Article/aqff/200608/6476.html å
ä½ è§£å³é®é¢ã
å¦ï¼æ¯ä¸æ¯ææ¯è½¯ä»¶ä¸è½å¯å¨ï¼é£å¯è½æ¯ä¸äºç
æ¯äºï¼è¿äºç
æ¯å
æ¬âä¼ å¥ç»ç»è
ï¼Trojan.PSW.LMirï¼âãâQQéè¡è¯ï¼Trojan.PSW.QQPassï¼â以åâå¯è¥¿æ¨é©¬ï¼Trojan.PSW.Miscï¼âçç
æ¯çææ°åç§ã
é对æ¤ç±»ç
æ¯ï¼å¯ç¨ç®åçä¸ä¸ªæ¹æ³å¯¹å®ä»¬è¿è¡è¯å«ï¼
第ä¸æ
æå¼âæççµèâï¼éæ©èåâå·¥å
·â-ãâæ件夹é项âï¼ç¹å»âæ¥çâï¼åæ¶âéèåä¿æ¤çæä½ç³»ç»æ件âåç对å¾ï¼å¹¶å¨âéèæ件åæ件夹â项ä¸éæ©âæ¾ç¤ºæææ件åæ件夹âï¼åæ¶åæ¶æâéèå·²ç¥æ件类åçæ©å±åâåç对å¾ï¼ç¶åç¹å»âç¡®å®âã
è¿å
¥C:\windows\system32ç®å½ä¸ï¼Windows2000ç³»ç»ä¸ºC:\WINNTç®å½ï¼ï¼è¥åç°æå为âcommandâãâdxdiaq.comâãâfinder.comâãâMSCONFIG.COMâãâregedit.comâ以åârundll32.comâçæ件çæï¼å说ææ¯ä¸äºâå¯è¥¿æ¨é©¬ï¼Trojan.PSW.Miscï¼âæå
¶åç§ç
æ¯ã
第äºæ
ç¹å»âå¼å§âæé®ï¼éæ©âè¿è¡âï¼è¾å
¥âregeditâ并确å®ï¼å¯å¨æ³¨å表ç¼è¾å¨ãæå¼âHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windowsâ项ï¼å¨å³è¾¹ççªå£ä¸æ¥æ¾AppInit_DLLsãè¥å
¶å¼ä¸ºâKBï¼ä¸é´å
ä½æ°åï¼M.LOGâï¼å¦âKB896588M.LOGâãâKB235780M.LOGâãâKB75976M.LOGâçï¼å说ææ¯ä¸äºæ°çâä¼ å¥ç»ç»è
ï¼Trojan.PSW.LMirï¼âåå
¶åç§ç
æ¯ã
第ä¸æ
åæ¶æä¸é®çCTRL+ALT+DELé®ï¼æå³é®ç¹å»ä»»å¡æ ï¼éæ©âä»»å¡ç®¡çå¨âãåå»âè¿ç¨âæ ç¾ãå¦ææ¾å°å为âSVOHOST.EXEâçè¿ç¨ï¼å说æå·²ææäºâQQéè¡è¯ï¼Trojan.PSW.QQPassï¼âç
æ¯æå
¶åç§ã