返回   华枫论坛 > ◆ 工作学习◆ > IT交流



发表新主题 回复
 
只看楼主 主题工具
旧 Jul 1st, 2008, 16:13     #1
举目有亲
Senior Member
级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时
 
注册日期: Jul 2004
帖子: 1,436
举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute
默认 【求助】lol.exe是病毒吗?

每次开机都在运行程序里面,而且有时候挡住不让别的程序运行,电脑像假死状态。中断其运行后电脑如常。是病毒吗?如何杀掉?

多谢!
举目有亲 当前离线  
回复时引用此帖
旧 Jul 1st, 2008, 16:44   只看该作者   #2
ChinaSmileJoe
Senior Member
级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时
 
ChinaSmileJoe 的头像
 
注册日期: Jul 2004
帖子: 79,350
积分:163
精华:102
声望: 25766633
ChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond repute
默认

Lol.exe is Trojan/Backdoor W32.HLLW.Reckus.
Kill the process lol.exe and remove lol.exe from Windows startup.

Description: File lol.exe is located in the folder C:\Windows. The file size on Windows XP is 77824 bytes.
There is no file information. The program is not visible. lol.exe is located in the Windows folder, but it is not a Windows core file. The file is not a Windows core file. The process listens for or sends data on open ports to LAN or Internet. lol.exe is able to record inputs, hide itself, monitor applications. Therefore the technical security rating is 86% dangerous.

If lol.exe is located in the folder C:\Windows\System32 then the security rating is 100% dangerous. File size is 88788 bytes. The process has no file description. The program is not visible. File lol.exe is located in the Windows folder, but it is not a Windows core file. The application starts upon Windows startup (see Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Runonce, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run). It is not a Windows system file. The program listens for or sends data on open ports to LAN or Internet. lol.exe is able to hide itself, monitor applications.

中文:

描述:
lol.exe是Backdoor.Win32.SdBot.aad木马相关程序,建议立即删除。
帅哥 ChinaSmileJoe 当前离线  
回复时引用此帖
感谢 ChinaSmileJoe
此篇文章之用户:
举目有亲 (Jul 1st, 2008)
旧 Jul 1st, 2008, 16:50   只看该作者   #3
举目有亲
Senior Member
级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时
 
注册日期: Jul 2004
帖子: 1,436
声望: 1979867
举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute
默认

引用:
作者: ChinaSmileJoe 查看帖子
Lol.exe is Trojan/Backdoor W32.HLLW.Reckus.
Kill the process lol.exe and remove lol.exe from Windows startup.

Description: File lol.exe is located in...
老大,是不是说这个病毒依附于startup里的程序?只要把startup里的程序删除,没有了依附,自然就没事了?

我用杀毒程序查不出来。
举目有亲 当前离线  
回复时引用此帖
旧 Jul 1st, 2008, 17:24   只看该作者   #4
ChinaSmileJoe
Senior Member
级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时级别:92 | 在线时长:8924小时 | 升级还需:97小时
 
ChinaSmileJoe 的头像
 
注册日期: Jul 2004
帖子: 79,350
积分:163
精华:102
声望: 25766633
ChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond reputeChinaSmileJoe has a reputation beyond repute
默认

我提供的资料是从google来的,具体我不清楚是否可以通过清除startup里面的程序来达到目的。你可以google一下看看有没有其它方案。
帅哥 ChinaSmileJoe 当前离线  
回复时引用此帖
旧 Jul 1st, 2008, 18:48   只看该作者   #5
美好的今天
通信专家
级别:33 | 在线时长:1221小时 | 升级还需:71小时级别:33 | 在线时长:1221小时 | 升级还需:71小时级别:33 | 在线时长:1221小时 | 升级还需:71小时级别:33 | 在线时长:1221小时 | 升级还需:71小时级别:33 | 在线时长:1221小时 | 升级还需:71小时
 
注册日期: Jun 2005
帖子: 5,384
声望: 6745275
美好的今天 has a reputation beyond repute美好的今天 has a reputation beyond repute美好的今天 has a reputation beyond repute美好的今天 has a reputation beyond repute美好的今天 has a reputation beyond repute美好的今天 has a reputation beyond repute美好的今天 has a reputation beyond repute美好的今天 has a reputation beyond repute美好的今天 has a reputation beyond repute美好的今天 has a reputation beyond repute美好的今天 has a reputation beyond repute
默认

引用:
作者: 举目有亲 查看帖子
每次开机都在运行程序里面,而且有时候挡住不让别的程序运行,电脑像假死状态。中断其运行后电脑如常。是病毒吗?如何杀掉?

多谢!
试一试system restore,恢复到比较干净的时间。
美好的今天 当前离线  
回复时引用此帖
旧 Jul 1st, 2008, 19:24   只看该作者   #6
举目有亲
Senior Member
级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时级别:34 | 在线时长:1338小时 | 升级还需:27小时
 
注册日期: Jul 2004
帖子: 1,436
声望: 1979867
举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute举目有亲 has a reputation beyond repute
默认

引用:
作者: 美好的今天 查看帖子
试一试system restore,恢复到比较干净的时间。...
遇到问题不要躲着走,万一再中招再restore?
举目有亲 当前离线  
回复时引用此帖
发表新主题 回复


发帖规则
不可以发表新主题
不可以发表回复
不可以上传附件
不可以编辑自己的帖子

启用 BB 代码
论坛启用 表情符号
论坛启用 [IMG] 代码
论坛禁用 HTML 代码



所有时间均为格林尼治时间 -4。现在的时间是 14:37

请尊重文章原创者,转帖请注明来源及原作者。
凡是本站用户自行发布的任何信息,皆不代表本站的立场,
华枫网站不确保各类信息的正确性和可靠性,也不承担由此而导致的任何直接或间接损失以及任何法律责任。

Copyright © 1999-2024 Chinasmile