病毒名称(中文):
恶鹰fu
病毒别名:
威胁级别:
★★☆☆☆
病毒类型:
蠕虫病毒
病毒长度:
16384
影响系统:
Win9xWinMeWinNTWin2000WinXPWin2003
病毒行为:
这是一种通过邮件传播的蠕虫病毒,该病毒会结束大量的安全软件,停止安全软件的进程,删除文件,修改host,对安全类软件做封杀,注入系统进程,对用户带来非常严重的影响。
1.结束大量的安全软件进程:
AckWin32.exe
ALERTSVC.EXE
ALOGSERV.EXE
Anti-Trojan.exe
ANTS.EXE
APVXDWIN.EXE
ashAvast.exe
ashDisp.exe
ashEnhcd.exe
ashMaiSv.exe
ashPopWz.exea
shServ.exe
ashSimpl.exe
ashSkPck.exe
ashWebSv.exe
aswUpdSv.exe
ATCON.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
Avconsol.exe
AVENGINE.EXE
avgcc.exe
AVGCC32.EXE
AVGCTRL.EXE
avgemc.exe
AVGNT.EXE
AVGSERV.EXE
AVGUARD.EXE
AvkServ.exe
AVP.EXE
AVP32.EXE
avpcc.exe
avpm.exe
AVPUPD.EXE
AVSCHED32.EXE
avsynmgr.exe
AVWUPD32.EXE
AVWUPSRV.EXE
AVXMONITOR9X.EXE
AVXMONITORNT.EXE
AVXQUAR.EXE
BackWeb-4476822.exe
bdmcon.exe
bdnews.exe
bdsubmit.exe
bdswitch.exe
blackd.exe
blackice.exe
cafix.exe
ccApp.exe
ccEvtMgr.exe
ccProxy.exe
ccSetMgr.exe
CFIAUDIT.EXE
ClamTray.exe
ClamWin.exe
Claw95.exe
Claw95cf.exe
cleaner.exe
cleaner3.exe
CliSvc.exe
CMGrdian.exe
cpd.exe
DefWatch.exe
DOORS.EXE
DrVirus.exe
drwadins.exe
drweb32w.exe
drwebscd.exe
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
F-AGNT95.EXE
F-PROT95.EXE
F-StopW.EXE
FAMEH32.EXE
FAST.EXE
FCH32.EXE
FIREWALL.EXE
fpavupdm.exe
freshclam.exe
FRW.EXE
fsav32.exe
fsavgui.exe
fsbwsys.exe
fsdfwd.exe
FSGK32.EXE
fsgk32st.exe
fsguiexe.exe
FSM32.EXE
FSMA32.EXE
FSMB32.EXE
fspex.exe
fssm32.exe
gcasDtServ.exe
gcasServ.exe
GUARD.EXE
GUARDGUI.EXE
GuardNT.exe
iamapp.exe
iamserv.exe
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFACE.EXE
INETUPD.EXE
InocIT.exe
InoRpc.exe
InoRT.exe
InoTask.exe
InoUpTNG.exe
IOMON98.EXE
isafe.exe
ISRV95.EXE
ISSVC.exe
JEDI.EXE
KAV.exe
kavmm.exe
KAVPF.exe
LOCKDOWN2000.EXE
LogWatNT.exe
LUALL.EXE
LUCOMSERVER.EXE
Luupdate.exe
MCAGENT.EXE
Mcshield.exe
MCUPDATE.EXE
MINILOG.EXE
MONITOR.EXE
MonSysNT.exe
MOOLIVE.EXE
navapsvc.exe
NAVAPW32.EXE
NavLu32.exe
NAVW32.EXE
NDD32.EXE
NeoWatchLog.exe
NeoWatchTray.exe
NISSERVNISUM.EXE
NMAIN.EXE
nod32.exe
nod32kui.exe
NORMIST.EXE
notstart.exe
NPFMNTOR.EXE
npfmsg.exe
NPROTECT.EXE
NSCHED32.EXE
NTXconfig.exe
NUPGRADE.EXE
NVC95.EXE
Nvcod.exe
Nvcte.exe
Nvcut.exe
NWService.exe
OUTPOST.EXE
PAV.EXE
PavFires.exe
pavProxy.exe
pavsrv51.exe
PAVSS.EXE
pccguide.exe
PCCIOMON.EXE
PcCtlCom.exe
PERSFW.EXE
pertsk.exe
PERVAC.EXE
POP3TRAP.EXE
POPROXY.EXE
QHPF.EXE
Realmon.exe
REALMON95.EXE
Rescue.exe
Rtvscan.exe
RTVSCN95.EXE
RuLaunch.exe
SAVScan.exe
SERVIC~1.EXE
SiteCli.exe
smc.exe
SNDSrvc.exe
SPBBCSvc.exe
SPHINX.EXE
spiderml.exe
Spiderui.exe
SpybotSD.exe
SPYXX.EXE
SS3EDIT.EXE
SWNETSUP.EXE
symlcsvc.exe
SymProxySvc.exe
SymSPort.exe
SymWSC.exe
SYNMGR.EXE
TAUMON.EXE
TC.EXE
tca.exe
TCM.EXE
TDS-3.EXE
TeaTimer.exe
TFAK.EXE
Tmas.exe
Tmntsrv.exe
TmPfw.exe
tmproxy.exe
TNBUtil.exe
TRJSCAN.EXE
Up2Date.exe
UPDATE.EXE
upgrepl.exe
Vba32ECM.exe
Vba32ifs.exe
vba32ldr.exe
Vba32PP3.exe
vcrmon.exe
VetTray.exe
VPTRAY.EXE
vrfwsvc.exe
VRMONNT.EXE
vrmonsvc.exe
VSECOMR.EXE
Vshwin32.exe
vsmon.exe
VsStat.exe
WATCHDOG.EXE
Webscanx.exe
WEBTRAP.EXE
WGFE95.EXE
Winaw32.exe
WRADMIN.EXE
WRCTRL.EXE
zatutor.exe
ZAUINST.EXE
zlclient.exe
zonealarm.exe
_AVP32.EXE
_AVPCC.EXE
_AVPM.EXE
2.删除注册表中的以下键和键值:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
SymantecNetDriverMonitor
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
ccApp
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
NAVCfgWiz
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
SSC_UserPrompt
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
McAfeeGuardian
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
McAfee.InstantUpdate.Monitor
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
APVXDWINHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
KAV50
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
avg7_cc
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
avg7_emc
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,
ZoneLabsClientHKLM\SOFTWARE\Symantec
HKLM\SOFTWARE\McAfee
HKLM\SOFTWARE\KasperskyLab
HKLM\SOFTWARE\Agnitum
HKLM\SOFTWARE\PandaSoftware
HKLM\SOFTWARE\ZoneLabs
HKLM\SOFTWARE\TrendMicro
3.停止并且删除以下服务:
AhnlabtaskScheduler
alerter
AlertManger
AntiVirService
aswUpdSv
AtiHotKeyPoller
avast!Antivirus
AVEService
AVExch32Service
avg7alrt
avg7updsvc
AvgCore
AvgFsh
AvgServ
AVIRAMailService
AVIRAService
avpcc
AVUPDService
AVWUpSrv
AvxIni
awhost32
backwebclient-4476822
BackWebClient-7681197
backwebclient-4476822
bdss
BlackICE
CAISafe
ccEvtMgr
ccPwdSvc
ccSetMgr
ccSetMgr.exe
DefWatch
dvpapi
dvpinit
F-Secure
Gatekeeper
Handler
Starter
fsbwsys
fsdfwd
FSMA
GuardNT
InoRpc
InoRT
InoTask
KAVMonitorService
kavsvc
KLBLMain
McAfeeFirewall
McAfeeFramework
McShield
McTaskManager
mcupdmgr.exe
MCVSRte
MonSvcNT
navapsvc
NetworkAssociatesLogService
nipsvc
NISSERV
NISUM
NOD32ControlCenter
NOD32Service
NormanNJeeves
NormanType-R
NormanZANDA
NortonAntivirusServer
NPFMntor
NProtectService
NSCTOP
nvcoas
NVCScheduler
nwclntc
nwclntd
nwclnte
nwclntf
nwclntg
nwclnth
NWService
OutbreakManager
OutpostFirewall
OutpostFirewall
PASSRV
PAVFNSVR
Pavkre
PavProt
PavPrSrv
PAVSRV
PCCPFW
PersFW
PREVSRV
PSIMSVC
ravmon8
SAVFMSE
SAVScan
SBService
schscnt
SharedAccess
SmcService
SNDSrvc
SPBBCSvc
SpiderNT
SweepNet
SWEEPSRV.SYS
SymantecAntiVirusClient
SymantecCoreLC
Tmntsrv
V3MonNT
V3MonSvc
Vba32ECM
Vba32ifs
Vba32Ldr
Vba32PP3
VexiraAntivirus
VisNeticAntiVirusPlug-in
vsmon
vsserv
wuauserv
xcomm
4.删除以下文件:
AckWin32.exe
ALERTSVC.EXE
ALOGSERV.EXE
Anti-Trojan.exe
ANTS.EXE
APVXDWIN.EXE
ashAvast.exe
ashDisp.exe
ashEnhcd.exe
ashMaiSv.exe
ashPopWz.exea
shServ.exe
ashSimpl.exe
ashSkPck.exe
ashWebSv.exe
aswUpdSv.exe
ATCON.EXE
ATUPDATER.EXE
ATWATCH.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
Avconsol.exe
AVENGINE.EXE
avgcc.exe
AVGCC32.EXE
AVGCTRL.EXE
avgemc.exe
AVGNT.EXE
AVGSERV.EXE
AVGUARD.EXE
AvkServ.exe
AVP.EXE
AVP32.EXE
avpcc.exe
avpm.exe
AVPUPD.EXE
AVSCHED32.EXE
avsynmgr.exe
AVWUPD32.EXE
AVWUPSRV.EXE
AVXMONITOR9X.EXE
AVXMONITORNT.EXE
AVXQUAR.EXE
BackWeb-4476822.exe
bdmcon.exe
bdnews.exe
bdsubmit.exe
bdswitch.exe
blackd.exe
blackice.exe
cafix.exe
ccApp.exe
ccEvtMgr.exe
ccProxy.exe
ccSetMgr.exe
CFIAUDIT.EXE
ClamTray.exe
ClamWin.exe
Claw95.exe
Claw95cf.exe
cleaner.exe
cleaner3.exe
CliSvc.exe
CMGrdian.exe
cpd.exe
DefWatch.exe
DOORS.EXE
DrVirus.exe
drwadins.exe
drweb32w.exe
drwebscd.exe
DRWEBUPW.EXE
ESCANH95.EXE
ESCANHNT.EXE
F-AGNT95.EXE
F-PROT95.EXE
F-StopW.EXE
FAMEH32.EXE
FAST.EXE
FCH32.EXE
FIREWALL.EXE
fpavupdm.exe
freshclam.exe
FRW.EXE
fsav32.exe
fsavgui.exe
fsbwsys.exe
fsdfwd.exe
FSGK32.EXE
fsgk32st.exe
fsguiexe.exe
FSM32.EXE
FSMA32.EXE
FSMB32.EXE
fspex.exe
fssm32.exe
gcasDtServ.exe
gcasServ.exe
GUARD.EXE
GUARDGUI.EXE
GuardNT.exe
iamapp.exe
iamserv.exe
ICLOAD95.EXE
ICLOADNT.EXE
ICMON.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
ICSUPPNT.EXE
IFACE.EXE
INETUPD.EXE
InocIT.exe
InoRpc.exe
InoRT.exe
InoTask.exe
InoUpTNG.exe
IOMON98.EXE
isafe.exe
ISRV95.EXE
ISSVC.exe
JEDI.EXE
KAV.exe
kavmm.exe
KAVPF.exe
LOCKDOWN2000.EXE
LogWatNT.exe
LUALL.EXE
LUCOMSERVER.EXE
Luupdate.exe
MCAGENT.EXE
Mcshield.exe
MCUPDATE.EXE
MINILOG.EXE
MONITOR.EXE
MonSysNT.exe
MOOLIVE.EXE
navapsvc.exe
NAVAPW32.EXE
NavLu32.exe
NAVW32.EXE
NDD32.EXE
NeoWatchLog.exe
NeoWatchTray.exe
NISSERVNISUM.EXE
NMAIN.EXE
nod32.exe
nod32kui.exe
NORMIST.EXE
notstart.exe
NPFMNTOR.EXE
npfmsg.exe
NPROTECT.EXE
NSCHED32.EXE
NTXconfig.exe
NUPGRADE.EXE
NVC95.EXE
Nvcod.exe
Nvcte.exe
Nvcut.exe
NWService.exe
OUTPOST.EXE
PAV.EXE
PavFires.exe
pavProxy.exe
pavsrv51.exe
PAVSS.EXE
pccguide.exe
PCCIOMON.EXE
PcCtlCom.exe
PERSFW.EXE
pertsk.exe
PERVAC.EXE
POP3TRAP.EXE
POPROXY.EXE
QHPF.EXE
Realmon.exe
REALMON95.EXE
Rescue.exe
Rtvscan.exe
RTVSCN95.EXE
RuLaunch.exe
SAVScan.exe
SERVIC~1.EXE
SiteCli.exe
smc.exe
SNDSrvc.exe
SPBBCSvc.exe
SPHINX.EXE
spiderml.exe
Spiderui.exe
SpybotSD.exe
SPYXX.EXE
SS3EDIT.EXE
SWNETSUP.EXE
symlcsvc.exe
SymProxySvc.exe
SymSPort.exe
SymWSC.exe
SYNMGR.EXE
TAUMON.EXE
TC.EXE
tca.exe
TCM.EXE
TDS-3.EXE
TeaTimer.exe
TFAK.EXE
Tmas.exe
Tmntsrv.exe
TmPfw.exe
tmproxy.exe
TNBUtil.exe
TRJSCAN.EXE
Up2Date.exe
UPDATE.EXE
upgrepl.exe
Vba32ECM.exe
Vba32ifs.exe
vba32ldr.exe
Vba32PP3.exe
vcrmon.exe
VetTray.exe
VPTRAY.EXE
vrfwsvc.exe
VRMONNT.EXE
vrmonsvc.exe
VSECOMR.EXE
Vshwin32.exe
vsmon.exe
VsStat.exe
WATCHDOG.EXE
Webscanx.exe
WEBTRAP.EXE
WGFE95.EXE
Winaw32.exe
WRADMIN.EXE
WRCTRL.EXE
zatutor.exe
ZAUINST.EXE
zlclient.exe
zonealarm.exe
_AVP32.EXE
_AVPCC.EXE
_AVPM.EXE
5.屏蔽以下网站:
ad.doubleclick.net
upgrade.bitdefender.com
report.bitdefender.com
ad.fastclick.net
ads.fastclick.net
ar.atwola.com
atdmt.com
avp.ch
avp.com
avp.ru
awaps.net
banner.fastclick.net
banners.fastclick.net
ca.com
www.ca.com
click.atdmt.com
clicks.atdmt.com
customer.symantec.com
dispatch.mcafee.com
download.mcafee.com
download.microsoft.com
downloads-eu1.kaspersky-labs.com
downloads-us1.kaspersky-labs.com
downloads-us2.kaspersky-labs.com
downloads-us3.kaspersky-labs.com
downloads.microsoft.com
downloads1.kaspersky-labs.com
downloads2.kaspersky-labs.com
downloads3.kaspersky-labs.com
downloads4.kaspersky-labs.com
engine.awaps.net
f-secure.com
fastclick.net
ftp.avp.ch
ftp.downloads2.kaspersky-labs.com
ftp.f-secure.com
ftp.kasperskylab.ru
ftp.sophos.com
go.microsoft.com
ids.kaspersky-labs.com
kaspersky-labs.com
kaspersky.com
liveupdate.symantec.com
liveupdate.symantecliveupdate.com
mast.mcafee.com
mcafee.com
media.fastclick.net
msdn.microsoft.com
my-etrust.com
nai.com
networkassociates.com
office.microsoft.com
phx.corporate-ir.net
rads.mcafee.com
secure.nai.com
securityresponse.symantec.com
service1.symantec.com
sophos.com
spd.atdmt.com
support.microsoft.com
symantec.com
trendmicro.com
update.symantec.com
updates.symantec.com
updates1.kaspersky-labs.com
updates2.kaspersky-labs.com
updates3.kaspersky-labs.com
updates4.kaspersky-labs.com
updates5.kaspersky-labs.com
us.mcafee.com
vil.nai.com
viruslist.com
viruslist.ru
windowsupdate.microsoft.com
www.avp.ch
www.avp.com
www.avp.ru
www.awaps.net
www.ca.com
www.f-secure.com
www.fastclick.net
www.grisoft.com
www.kaspersky-labs.com
www.kaspersky.com
www.kaspersky.ru
www.mcafee.com
www.my-etrust.com
www.nai.com
www.networkassociates.com
www.sophos.com
www.symantec.com
www.trendmicro.com
www.viruslist.com
www.viruslist.ru
www3.ca.com
avp.ch
avp.com
avp.ru
awaps.net
ca.com
ca.com
ca.com
ca.com
ca.com
ca.com
f-secure.com
fastclick.net
grisoft.com
kaspersky-labs.com
kaspersky.com
kaspersky.ru
mcafee.com
my-etrust.com
nai.com
networkassociates.com
sophos.com
symantec.com
trendmicro.com
viruslist.com
viruslist.ru
www3.ca.com
84.53.142.6
84.53.142.22
63.210.193.12
212.113.20.69
216.200.68.152
update.symantec.com
ca.com
service1.symantec.com
www.antivir.de
antivir.de
drweb.com
ca.com
www.drweb.com
drweb.ru
www.ravantivirus.com
ravantivirus.com
bitdefender.com
www.bitdefender.com
ca.com
www.clamav.net
clamav.net
pandasoftware.com
www.pandasoftware.com
ftpav.ca.com
upgrade.bitdefender.com
www.bitdefender.ru
bitdefender.ru
open.byvba32.de
www.open.by
sm12.avast.com
sm13.avast.com
rs18.avast.com
rs08.avast.com
sm17.avast.com
sm04.avast.com
sm09.avast.com
sm16.avast.com
rs03.avast.com
rs06.avast.com
sm21.avast.com
rs02.avast.com
rs10.avast.com
rs07.avast.com
sm25.avast.com
rs11.avast.com
sm22.avast.com
rs20.avast.com
sm23.avast.com
sm19.avast.com
sm05.avast.com
rs24.avast.com
sm15.avast.com
downloadhosting.core.ignum.cz
sm01.avast.com
sm14.avast.com
rs18.avast.com
download25.avast.com
www.avast.com
avast.com
avira.com
www.avira.com
zak.avira.com
downloads.avira.com
www.clamwin.com
clamwin.com
213.219.245.4
files.referats.net
database.clamav.net
213.248.60.121
gin.ba.euroweb.sk
www2.eset.com
esetsoftware.com
msk4.drweb.com
drweb.com
www.drweb.com
62.146.66.181
www.hbedv.com
hbedv.com
www.hacksoft.com.pe
ikarus-software.at
download.ikarus.at1
93.69.114.12
niutwo.norman.no
www.anti-virus.by
anti-virus.by
www.vba32.de
ftpav.ca.com