惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Blog — PlanetScale
Blog — PlanetScale
B
Blog
A
About on SuperTechFans
大猫的无限游戏
大猫的无限游戏
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
H
Help Net Security
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 三生石上(FineUI控件)
有赞技术团队
有赞技术团队
酷 壳 – CoolShell
酷 壳 – CoolShell
WordPress大学
WordPress大学
IT之家
IT之家
D
Docker
Google DeepMind News
Google DeepMind News
罗磊的独立博客
T
The Blog of Author Tim Ferriss
aimingoo的专栏
aimingoo的专栏
博客园 - 叶小钗
Recent Announcements
Recent Announcements
阮一峰的网络日志
阮一峰的网络日志
D
DataBreaches.Net
博客园 - 司徒正美
Engineering at Meta
Engineering at Meta

博客园 - zealsoft

洛谷 P1816 忠诚题解 洛谷 P2384 最短路题解 洛谷 P2725 邮票题解 洛谷 P2722 总分题解 洛谷 P1219 八皇后题解 洛谷 P2921 在农场万圣节Trick or Treat on the Farm题解 洛谷 P1162 填涂颜色题解 洛谷 P1330 封锁阳光大学题解 洛谷 P1032 字串变换题解 洛谷 P1443 马的遍历题解 洛谷 P1280 尼克的任务题解 洛谷 P1020导弹拦截题解 洛谷 P1141 01迷宫题解 VisualSVNServer无法卸载也无法安装,报告不是有效的MOF文件(0x8004401e)错误 视频捕捉的格式问题 一个VxWorks源代码网站 找个轻量级的Log库还挺难 TAU G2中的BitString和OctetString 如何用Visual Studio 2005编译Wireshark的插件
W32.Downadup.autorun病毒的清除
zealsoft · 2009-05-11 · via 博客园 - zealsoft

今天突然发现计算机有点异常,只要一打开Windows资源管理器左侧的文件夹,Explorer.exe就会崩溃,检查了一下发现中了W32.Downadup.autorun病毒。尽管机器安装了最新版本的瑞星杀毒软件,但是根本就检测不到该病毒。Symantec可以检测到,但是单位的涉密计算机就不允许安装国外的杀毒软件,只能用瑞星。在网上搜索了一下,在Symantec的网站上可以下载杀毒软件包。下回来运行了一下,可以把病毒删除了,下面是删除的日志文件:

Symantec W32.Downadup Removal Tool 1.1.0.5
process: svchost.exe, thread: 00000454 (terminated)
process: svchost.exe, thread: 00000B64 (terminated)
process: svchost.exe, thread: 00000BB0 (terminated)
process: svchost.exe, thread: 0000093C (terminated)
process: svchost.exe, thread: 00000BBC (terminated)
process: svchost.exe, thread: 00000BC0 (terminated)
process: svchost.exe, thread: 000000F0 (terminated)
process: svchost.exe (terminated)

G:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx: W32.Downadup.B (unrepairable) (deleted)


registry: HKLM\system\CurrentControlSet\Services\BITS: Start (value set to 0x00000003 (3))
registry: HKLM\system\CurrentControlSet\Services\ERSvc: Start (value set to 0x00000002 (2))
registry: HKLM\system\CurrentControlSet\Services\wscsvc: Start (value set to 0x00000002 (2))
registry: HKLM\system\CurrentControlSet\Services\wuauserv: Start (value set to 0x00000002 (2))

W32.Downadup has been successfully removed from your computer!

Here is the report:

The total number of the scanned files: 356394
The number of deleted threat files: 1
The number of threat processes terminated: 1
The number of threat threads terminated: 7
The number of registry entries fixed: 4

The tool initiated a system reboot.