清除步骤
1. 使用IceSword(http://www.motoyi.com/Down/Noted/200704/Down_10.shtml下载)结束木马进程: %Windows%\system\SMSS.exe
2. 删除文件(如遇提示无法删除文件,下载费尔木马强制删除器工具(http://www.motoyi.com/Down/Noted/200706/Down_68.shtml)进行强制删除: %Windows%\system\SMSS.exe %Windows%\system\hook.dll
3. 删除木马启动项(详细步骤:打开SREng-启动项目-注册表):SREng软件下载:http://www.motoyi.com/Down/Noted/200705/Down_28.shtml
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QQREST"="%Windows%\system\SMSS.exe"
4. 删除注册表中木马添加的驱动信息(详细步骤:打开SREng-启动项目-驱动程序): [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fOxkb]
5. 删除木马释放的驱动文件(如遇提示无法删除文件,下载费尔木马强制删除器工具(http://www.motoyi.com/Down/Noted/200706/Down_68.shtml)进行强制删除: fOxkb.sys
|