|
|

楼主 |
发表于 2004-10-23 11:20:19
|
显示全部楼层
是这样的,前些日子碰上一个病毒,在dos下都不能删,提示attrib必须在windows下运行。进入windows的安全模式下还是不能删。改注册表是可以让它不运行,可是文件在那里总是个隐患。最后还是在linux下把它给干掉了。
那个病毒的名字好像是:lnasv.exe
; This file is generated by Unionway AppHunter 2003
; Please contact support@unionway.com for more details
[Summary]
Discovered=09/02/2004 21:28:00
ID=900211D7DB3FC1490EAF1AB18D54719B
ID2=101541,1531A3DFA9D87161448EDA7AF178E281
ID3=101029,4FE80E310F8B4E338389E8A3F047D9D3
MD5=47BC0A4145C11EDB081CA5702C3A16C1
Size=101541
Filename=lnasvc.exe
Company=N/A
Risk=8.1
Virus=Spybot.Worm ***
[Risk Analyzer]
AutoRun=12
NonBrand=10
FileCreated=4
FileCreatedInWinSys=4
CloneThreat=4
RunProcess=4
MultiThreads=5
TCPServer=10
TCPClient=8
Symantec=8
McAfee=8
[Virus Known As (McAfee)]
W32/Sdbot.worm=1
[Virus Known As (Symantec)]
W32.Spybot.Worm=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\]
Audio CODEC Pack=lnasvc.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\]
Audio CODEC Pack=lnasvc.exe
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\]
Audio CODEC Pack=lnasvc.exe
[FileCreated]
c:\windows\system32\lnasvc.exe=1
[ProcessCreated]
C:\WINDOWS\system32\Lnasvc.exe=1
[ThreadCreated]
Count=11
[TCPServer] ; Port=Status(Handle)
113=64 (32352)1,1
[TCPClient] ; IP ort=Status(Handle)
255.255.255.255:42420=16 (32368)1,1
TNND国内没有出现的病毒老是到我这,是不是在windows下用QQGAME的原因啊。 |
|