Dec
25
注册表里好像没有dt.dll,杀毒软件无效,机器变慢,改名后,安全模式删除重启仍然回来,进程里没有看到dt.dll或者dtservice.dll,
木马病毒Trojan-PSW.Win32.OnLineGames.cc
删除病毒文件
%WINDOWS%\Download\svhost32.exe
%system32%\xydll.dll
删除病毒添加的注册表项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
\CurrentVersion\Run\xy
值: 字符串: “C:\WINDOWS\Download\svhost32.exe”
这是我分析的Trojan-PSW.Win32.OnLineGames.ar的报告,和你的cc差不多。
Related Posts:
- January 4, 2008 -- Trojan-PSW.Win32.Delf.tn
- December 26, 2007 -- Trojan-PSW.Win32.OnLineGames.bs
- December 23, 2007 -- trojan-psw.win32.onlinegames.bs
- December 26, 2007 -- Trojan-psw.win32.onlineganme
- December 22, 2007 -- trojan-psw.win32.small.br
- December 19, 2007 -- Trojan-psw32.onlineGames.ux
- January 5, 2009 -- [Active] Win32.Netsky.Q Virus.
- January 4, 2009 -- [Active] win32/tenga.gen virus - it took over
- August 7, 2008 -- Internet careful look at the Olympic Games 10 virus
- January 18, 2008 -- Win32 OR Troj OR PswQQ
written by lina
\\ tags: dt.dll, OnLineGames, svhost32.exe, trojan-psw, Win32, xydll.dll
Comments