瀏覽單個文章
mokog123
*停權中*
 

加入日期: Dec 2001
您的住址: 台中市位台灣中部,舊名「大墩」
文章: 3,106
引用:
Originally posted by TheRock
謝謝你們的回答
我也順便補充資料~
該台電腦有裝SYMANTEC的諾頓防毒軟體~
不過還是中了四種病毒~目前我已經把疾風跟WELCHIA變種~以及另外一個
病毒(忘記名稱)給移除了~

修補程式我也使用了KB(應該是疾風的修正檔)開頭的那一個~另外一個修正檔
因為昨天在朋友家上網都找不到~只找到FOR SP4 英文版~
而家裡電腦裡兩個修正檔都有了~所以今天或明天再幫朋友補一下修正檔就OK了



TO 3210兄~
謝謝你的回答~那我再去下載相關REMOVER

TO mokog123兄
我昨天有用Symantec的線上掃毒軟體~確認只剩下PWSteal病毒~
謝謝您~

在趨勢找到的資料
http://www.trendmicro.com/vinfo/zh-...eal&alt=PWSteal
裡面有解決方法,如下

這是一隻特洛依木馬型病毒。它不會感染任何檔案或複製,但就像那些會偷竊密碼的特洛依木馬型病毒一樣,它對系統的安全構成威脅;因為只要誰擁有該使用者的密碼,誰就有可能存取 (駭客入侵) 該使用者的系統。

解決方案:



Delete all instances of TROJ_PWSTEALE as detected by our product to ensure re-infection does not occur. To do this Trend customers must download the latest pattern file and scan their system. Other email users may use Trend HouseCall, a free online virus scanner.
In the Windows Start menu, click on “Shut Down”, and choose “Restart in MS-DOS mode”. This will bring you to the DOS prompt “c:\Windows\”.
Type the command below, then press “Enter”
Del win32sys.exe
Type “exit” to return to Windows. Upon entering Windows, you will receive an error message, stating that the file win32sys.exe could not be found. Just press “Ok”.
At the Windows Start menu again, click “run”, then type sysedit.
In sysedit, go to the “win.ini” window, and look for the line load=c:\Windows\win32sys.exe. Delete this whole line.
Click on File, then Save on the sysedit menu bar to save the win.ini file.
Reboot. Now the Trojan will no longer gain immediate access. Now, re-scan the system, and delete any files detected as TROJ_PWSTEALE.
舊 2003-08-22, 11:14 AM #5
回應時引用此文章
mokog123離線中