!!!求npxovwq.exe/oaqxnfs.exe病毒专杀或解决办法

来源:百度知道 编辑:UC知道 时间:2024/05/26 09:19:11
病毒名称是:upnpsvc.exe\oaqxnfs.exe\npxovwq.exe\oiykikm.exe\sysauto.exe

非法进程名为oiykikm/tjfldjj

表现为:上网搜索资料时,只要关键字中含有"瑞星"或是用病毒的名称的话,IE就会自动关闭,

而且是只要你双击打开文件夹时就会主动发作,右键打开文件夹时不会主动发作!

不知道大家有没有遇到过,遇到过的话,就给小生一个快捷的清除方法!

谢谢了!

卡巴斯基杀毒软件会把该病毒报告为:Trojan-PSW.Win32.Agent.dt

以下是该病毒的一些详细信息:

Size: 60416 bytes
File Version: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
MD5: 9F824AC6579F83A1645F4FE9EA21BCE5
SHA1: AA2EF274179E773FC42020E20575F3F65A078FCD
CRC32: 26F8C997

添加服务Asynchronous UPnP Support Services

服务涉及到的注册表项目如下

HKLM\SYSTEM\ControlSet001\Services\Asynchronous UPnP Support Services\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
HKLM\SYSTEM