电脑网络销售与维修

查看完整版本: [分享]新手也能对付病毒:清除svch0st.exe

holly0708 2007-9-12 15:57

[分享]新手也能对付病毒:清除svch0st.exe

<p class="MsoNormal" align="left" style="MARGIN: 0cm 0cm 0pt 24.1pt; TEXT-INDENT: -24.1pt; TEXT-ALIGN: left; mso-pagination: widow-orphan; mso-char-indent-count: -2.0;"><b style="mso-bidi-font-weight: normal;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"><span lang="EN-US"></span></span></b><b style="mso-bidi-font-weight: normal;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><p></p></span></b></p><p class="MsoNormal" align="left" style="MARGIN: 0cm 0cm 0pt 24pt; TEXT-INDENT: -24pt; TEXT-ALIGN: left; mso-pagination: widow-orphan; mso-char-indent-count: -2.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><br/></span><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt; mso-ascii-font-family: 宋体;"><font face="Times New Roman">&nbsp;</font></span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"> &nbsp;&nbsp; &nbsp; 如果安装了傻瓜式的雨过天晴电脑保护系统,只要恢复还原一下就可以彻底的清楚病毒了,但是如果没有的话,就需要按照以下的步骤来操作了:</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><p></p></span></p><p class="MsoNormal" align="left" style="MARGIN: 0cm 0cm 0pt 23.95pt; TEXT-INDENT: 36pt; TEXT-ALIGN: left; mso-pagination: widow-orphan; mso-char-indent-count: 3.0; mso-para-margin-left: 2.28gd;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;">svch0st.exe和系统进程svchost.exe只差一个字符,注意svch0st.exe中的0这个是数字零,而系统进程svchost.exe中的o是字母O。</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><br/><br/></span><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt; mso-ascii-font-family: 宋体;"><font face="Times New Roman">&nbsp;</font></span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"> &nbsp;&nbsp; &nbsp; 该病毒运行后在系统文件夹System下创建自身的副本,文件名为svch0st.exe。</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><br/></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;">(其中,<span lang="EN-US">System在Windows 95/98/Me 下为C:\Windows\System,在Windows NT/2000下为C:\Winnt\System32,在Windows XP下为 C:\Windows\System32)</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><br/><br/></span><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt; mso-ascii-font-family: 宋体;"><font face="Times New Roman">&nbsp;</font></span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"> &nbsp;&nbsp; &nbsp; 随后病毒修改注册表,以达到随系统启动而自动运行的目的,在</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><br/></span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;">HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Current Version\Run下创建:</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><br/></span><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt; mso-ascii-font-family: 宋体;"><font face="Times New Roman">&nbsp;</font></span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"> &nbsp; "svch0st.exe" = "System</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;">\</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;">svch0st.exe" <br/>&nbsp; &nbsp; "taskmgr.exe" = "System</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;">\</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;">svch0st.exe" <br/><br/>&nbsp; &nbsp;&nbsp; &nbsp;病毒运行后检查IE窗口标题栏,判定当前窗口是否为网上银行的登陆页面,涉及到国内多家银行的网上交易系统。一旦发现当前IE窗口为上述银行的登陆页面,病毒立即开始记录键盘输入的所有键值,记录的键值几乎包括了所有可能的键盘录入。窃取的用户信息包括网上银行的帐号、密码、验证码等。当病毒截获被感染计算机所输入的键盘值后,将其窃取到的信息发送到指定的地址。</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><br/><br/></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;">清除方法:</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><br/><br/></span><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt; mso-ascii-font-family: 宋体;"><font face="Times New Roman">&nbsp;</font></span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"> &nbsp;&nbsp; &nbsp;关闭系统还原,开始-运行:msconfig (运行系统配置程序)。</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><br/><br/></span><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt; mso-ascii-font-family: 宋体;"><font face="Times New Roman">&nbsp;</font></span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"> &nbsp;&nbsp; &nbsp;在启动项中取消"svch0st.exe" = "%System%\svch0st.exe"和 "taskmgr.exe" = "%System%\svch0st.exe" 两项前面的勾。</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><br/><br/></span><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt; mso-ascii-font-family: 宋体;"><font face="Times New Roman">&nbsp;</font></span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"> &nbsp;&nbsp; &nbsp;打开任务管理器终止svch0st.exe,要看清楚不要弄错了。</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><br/><br/></span><span lang="EN-US" style="FONT-SIZE: 12pt; mso-font-kerning: 0pt; mso-ascii-font-family: 宋体;"><font face="Times New Roman">&nbsp;</font></span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-font-kerning: 0pt;"> &nbsp;&nbsp; &nbsp;运行系统搜索功能,并打开高级选项,查找隐藏的文件,查找svch0st.exe并删除。</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-hansi-font-family: &quot;Times New Roman&quot;; mso-font-kerning: 0pt;"><p></p></span></p>

feng2007 2007-9-12 17:59

<p>为什么沙发也扣!</p>

jeonson 2007-9-16 12:57

走累了也没有沙发坐,消极啊!!!!!!!!!!!!
页: [1]
查看完整版本: [分享]新手也能对付病毒:清除svch0st.exe