长弓无敌
===========================================================
机器不幸中毒,ws2_64.dll PWSteal.Trojan,心里真烦。
===========================================================

机器不幸中毒,ws2_64.dll PWSteal.Trojan;结过导致Oracle起动不起来,真郁闷。看到一些解决问题的方法,还得修改注册表,好几个地方,希望Norton 能够早日解决这个病毒。现在,只好停止norton的实时防护,才能起动Oracle。

具体解决方案见http://securityresponse.symantec.com/avcenter/venc/data/trojan.redfall.html


junsheng 发表于:2004.11.16 18:58 ::分类: ( 应用 ) ::阅读:(3168次) :: 评论 (3)
解决方案 [回复]

Click Start, and then click Run. (The Run dialog box appears.)

Type regedit

Then click OK. (The Registry Editor opens.)

Navigate to the key:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries

Click on the first subkey. It will be named 000000000001.

In the right pane, double-click the name PackedCatalogItem. An "Edit Binary Value" dialog appears. If the text on the right-hand side of this window contains the string "ws2_64.dll" (an example is shown in the picture below), then Trojan.Redfall has changed this value, and therefore must be restored. Close the dialog by clicking Cancel, and then proceed to the next step.

To restore the value, perform steps i - xii.

Navigate to the key:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesWinsock2Winsock

In the right pane, double-click on the name:

1001

A window entitled "Edit String" will appear. An example of the window is shown in the picture below.

Carefully count the number of characters in the string listed. In this example, the string is 31 characters long, but your system may vary. Write this information down, as you will need it in step 9.

Write down the Value data, or Highlight and copy it, and then paste it into Notepad for future reference.

--------------------------------------------------------------------------------
Note: You can copy the original value data, but when it comes time to replace the changed data, you will be unable to paste it in. You will need to type the value in by hand, so be sure to copy it some place for reference, or write it down exactly as it appears, using proper case, like capitalization.
--------------------------------------------------------------------------------

Click Cancel.

Navigate to the key:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries

and click on the subkey 000000000001.

In the right pane, double-click the name PackedCatalogItem. An "Edit Binary Value" dialog appears.

In the Value data box, place the cursor immediately to the left of the first character in the block of text, to the right of the box, as shown in the picture below:

Using the character count from step 3, delete that number of characters from the beginning of the text displayed in the Value data box. The easiest way to do this is to put the cursor at the beginning of the text values, and then hit the delete key the correct number of times.

With the cursor at the beginning of the text area (where it should still be after the previous step), type the value you copied in step 4 exactly as it appeared.

After entering the correct value, scroll to the bottom of the Value data. It should look exactly like the picture below. If it does not, you have deleted or typed in the wrong number of characters. In this case, click Cancel and return to step 1. If the box appears exactly as shown in the picture below, click OK.

You have now finished restoring the value of one subkey. To complete the removal, you must repeat steps C through F for each subkey under the key:
HKEY_LOCAL_MACHINESystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries

Note: Each subkey that Trojan.Redfall has changed will have a corresponding value under the key:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesWinsock2Winsock

where the original data is stored.

For example, the key:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries00000000002

has the corresponding value 1002 in the key:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesWinsock2Winsock

and the key:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries00000000003

has the corresponding value 1003, and so forth.

Once you have examined the PackedCatalogItem values for each subkey under:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries

and restored those values that Trojan.Redfall modified, delete the key:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesWinsock2Winsock.

Exit the Registry Editor.

Restart the computer.
按照如上步骤修改注册表,把诺顿的病毒库更新到最新,重启后,发现病毒已经消除.

junsheng 评论于: 2004.11.21 11:12
我是英语盲!! [回复]

不好意思。英语看不懂啊~
能不能翻译一下呀~~

平子 评论于: 2004.11.24 16:13
汗颜…… [回复]

按照如上步骤修改注册表,把诺顿的病毒库更新到最新,重启后,发现病毒已经消除.
——这是真的吗???

CCFAN 评论于: 2005.05.21 10:06

发表评论
标题

在此添加评论
表情符号: smile laughing tongue angry crying sad wassat wink

称呼

邮箱地址(可选)

个人主页(可选)

 authimage


自我介绍
切换风格
新闻聚合
博客日历
文章归档...
最新发表...
最新评论...
最多阅读文章...
最多评论文章...
博客统计...
Blog信息
网站链接...