北京邮电宏福校区贴吧:求救!!中毒了啊!

来源:百度文库 编辑:杭州交通信息网 时间:2024/04/24 13:48:41
我用的是诺顿。
昨天在浏览网页时不幸中招了,杀毒软件提示说发现病毒,但是操作失败,既无法清除也无法隔离!!只能“受感染”。病毒名称“Backdoor.Graybird”目前还没有发现电脑有什么不正常,只是觉得速度稍微有那么一点点慢(不知道是不是心理作用)大家别笑我啊!我对电脑不太在行。请各位高手告诉我现在该怎么办,还有,是不是一般电脑中一些不太恶劣的病毒是正常的事??谢谢了!!

灰鸽子是国内一款著名后门。比起前辈冰河、黑洞来,灰鸽子可以说是国内后门的集大成者。其丰富而强大的功能、灵活多变的操作、良好的隐藏性使其他后门都相形见绌。客户端简易便捷的操作使刚入门的初学者都能充当黑客。当使用在合法情况下时,灰鸽子是一款优秀的远程控制软件。但如果拿它做一些非法的事,灰鸽子就成了很强大的黑客工具。本工具的功能为专门查找计算机上的BlackHole后门程序和灰鸽子后门程序。
http://www.onlinedown.net/soft/43101.htm

1关了服务在杀毒,按 Ctrl+Alt+Delete
Svch0st.exe. 停了。
2然后杀毒
杀好后清除注册表
运行:regedit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
RunServices
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
删了。

For each one, in the right pane, delete any of the following values:

"svchost"="%System%\Svch0st.exe"
"winlogon"="%System%\Winlogon.exe"
"system"="%System%\Explorer.exe"

If you are running Windows NT/2000/XP, navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows

In the right pane, delete the value:

run %system%\svch0st.EXE

Exit the registry editor.

如果你是95、98或者win me
If you are running Windows 95/98/Me, follow these steps:

The function you perform depends on your operating system:
Windows 95/98: Go to step b.
Windows Me: If you are running Windows Me, the Windows Me file-protection process may have made a backup copy of the Win.ini file that you need to edit. If this backup copy exists, it will be in the C:\Windows\Recent folder. Symantec recommends deleting this file before continuing with the steps in this section. To do this:
Start Windows Explorer.
Browse to and select the C:\Windows\Recent folder.
In the right pane, select the Win.ini file and delete it. The Win.ini file will be regenerated when you save your changes to it in step f.

Click Start, and then click Run.

Type the following:

edit c:\windows\win.ini

and then click OK. (The MS-DOS Editor opens.)

NOTE: If Windows is installed in a different location, make the appropriate path substitution.

In the [windows] section of the file, look for a line similar to:

run=C:\WINDOWS\SYSTEM\SVCH0ST.EXE

If this line exists, delete the entire line.

Click File, and then click Save.

Click File, and then click Exit.

老实说,这个不算是病毒,是一个黑客后门程序,他不会象病毒一样到处乱复制,但是有可能造成数据丢失,最好的方法就是安装防火墙,然后进行木马清除

上楼说的好

www.luckfish.net/rising.html