电脑在浏览一些不安全网站的时候非常容易感染病毒,随着网络的发展,病毒也变得越来越多样化。近日一位网友突然发现自己的电脑感染上一个名为“winlogon.exe”的病毒,对此该怎么办呢?本文就给大家介绍手动清除winlogon.exe电脑病毒的方法。
这只鸽子提示:中招后,贴日志求助的日子即将结束!做好系统基础安全防护是每个用户的当务之急。“基础安全防护”绝不仅仅是打几个补丁的问题。熟悉一两个性能好的安全软件的使用也是必要的。否则,中招后,你自己就着急吧!
这是Movgear.exe中捆绑的一只灰鸽子(Movgear.exe样本来自安全12公里)。winlogon.exe的MD5值为:2de9f62c2b405e16cb66773747cf0f2d。
2、在HKEY_USERS.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\Cmd\Mapping
4、在HKEY_USERS.DEFAULT\Software\Microsoft\Internet\Explorer\Toolbar\WebBrowser
- 01"ITBarLayout"=hex:11,00,00,00,5c,00,00,00,00,00,00,00,34,00,00,00,1f,00,00,00,56,
- 0200,00,00,01,00,00,00,20,07,00,00,a0,0f,00,00,05,00,00,00,62,05,
- 0300,00,26,00,00,00,02,00,00,00,21,07,00,00,a0,0f,00,00,04,00,00,
- 0400,21,01,00,00,a0,0f,00,00,03,00,00,00,20,03,00,00,00,00,00,00,
- 0500,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 0600,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 0700,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 0800,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 0900,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 1000,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 1100,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 1200,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 1300,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 1400,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 1500,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 1600,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 1700,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 1800,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 1900,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 2000,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 2100,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 2200,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 2300,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 2400,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 2500,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 2600,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 2700,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
- 28"{01E04581-4EEE-11D0-BFE9-00AA005B4383}"=hex:81,45,e0,01,ee,4e,d0,11,bf,e9,00,aa,00,5b,43,83,10,00,00,00,00,
- 2900,00,00,01,e0,32,f4,01,00,00,00
- 30"{0E5CBF21-D15F-11D0-8301-00AA005B4383}"=hex:21,bf,5c,0e,5f,d1,d0,11,83,01,00,aa,00,5b,43,83,22,00,1c,00,08,
- 3100,00,00,06,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,
- 3200,00,4c,00,00,00,01,14,02,00,00,00,00,00,c0,00,00,00,00,00,00,
- 3346,81,00,00,00,10,00,00,00,a0,8f,ff,ba,9d,d4,c6,01,00,9e,02,bb,
- 349d,d4,c6,01,a0,8f,ff,ba,9d,d4,c6,01,00,00,00,00,00,00,00,00,01,
- 3500,00,00,00,00,00,00,00,00,00,00,00,00,00,00,5d,01,14,00,1f,50,
- 36e0,4f,d0,20,ea,3a,69,10,a2,d8,08,00,2b,30,30,9d,19,00,2f,43,3a,
- 375c,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,5c,
- 3800,31,00,00,00,00,00,3a,31,09,3c,10,00,44,4f,43,55,4d,45,7e,31,
- 3900,00,44,00,03,00,04,00,ef,be,3a,31,9c,36,2a,35,f7,29,14,00,00,
- 4000,44,00,6f,00,63,00,75,00,6d,00,65,00,6e,00,74,00,73,00,20,00,
- 4161,00,6e,00,64,00,20,00,53,00,65,00,74,00,74,00,69,00,6e,00,67,
- 4200,73,00,00,00,18,00,4c,00,31,00,00,00,00,00,2a,35,cb,2e,16,00,
- 434e,45,54,57,4f,52,7e,31,00,00,34,00,03,00,04,00,ef,be,3a,31,11,
- 4439,2a,35,cb,2e,14,00,00,00,4e,00,65,00,74,00,77,00,6f,00,72,00,
- 456b,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,18,00,56,
- 4600,31,00,00,00,00,00,2a,35,cb,2e,11,00,46,41,56,4f,52,49,7e,31,
- 4700,00,3e,00,03,00,04,00,ef,be,2a,35,cb,2e,2a,35,cb,2e,14,00,28,
- 4800,46,00,61,00,76,00,6f,00,72,00,69,00,74,00,65,00,73,00,00,00,
- 4940,73,68,65,6c,6c,33,32,2e,64,6c,6c,2c,2d,31,32,36,39,33,00,18,
- 5000,30,00,35,00,00,00,00,00,2a,35,f1,2e,10,00,fe,94,a5,63,00,00,
- 511c,00,03,00,04,00,ef,be,2a,35,f1,2e,2a,35,f1,2e,14,00,00,00,fe,
- 5294,a5,63,00,00,14,00,00,00,60,00,00,00,03,00,00,a0,58,00,00,00,
- 5300,00,00,00,6c,69,6e,62,61,6f,68,65,00,00,00,00,00,00,00,00,1e,
- 548c,63,4d,34,72,b3,48,8a,de,83,67,8f,38,be,10,b1,a9,fd,89,90,40,
- 55db,11,b2,29,00,d0,59,c0,b8,59,1e,8c,63,4d,34,72,b3,48,8a,de,83,
- 5667,8f,38,be,10,b1,a9,fd,89,90,40,db,11,b2,29,00,d0,59,c0,b8,59,
- 5700,00,00,00
复制代码
"ITBarLayout"=hex:11,00,00,00,5c,00,00,00,00,00,00,00,34,00,00,00,1f,00,00,00,56,
00,00,00,01,00,00,00,20,07,00,00,a0,0f,00,00,05,00,00,00,62,05,
00,00,26,00,00,00,02,00,00,00,21,07,00,00,a0,0f,00,00,04,00,00,
00,21,01,00,00,a0,0f,00,00,03,00,00,00,20,03,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"{01E04581-4EEE-11D0-BFE9-00AA005B4383}"=hex:81,45,e0,01,ee,4e,d0,11,bf,e9,00,aa,00,5b,43,83,10,00,00,00,00,
00,00,00,01,e0,32,f4,01,00,00,00
"{0E5CBF21-D15F-11D0-8301-00AA005B4383}"=hex:21,bf,5c,0e,5f,d1,d0,11,83,01,00,aa,00,5b,43,83,22,00,1c,00,08,
00,00,00,06,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,4c,00,00,00,01,14,02,00,00,00,00,00,c0,00,00,00,00,00,00,
46,81,00,00,00,10,00,00,00,a0,8f,ff,ba,9d,d4,c6,01,00,9e,02,bb,
9d,d4,c6,01,a0,8f,ff,ba,9d,d4,c6,01,00,00,00,00,00,00,00,00,01,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,5d,01,14,00,1f,50,
e0,4f,d0,20,ea,3a,69,10,a2,d8,08,00,2b,30,30,9d,19,00,2f,43,3a,
5c,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,5c,
00,31,00,00,00,00,00,3a,31,09,3c,10,00,44,4f,43,55,4d,45,7e,31,
00,00,44,00,03,00,04,00,ef,be,3a,31,9c,36,2a,35,f7,29,14,00,00,
00,44,00,6f,00,63,00,75,00,6d,00,65,00,6e,00,74,00,73,00,20,00,
61,00,6e,00,64,00,20,00,53,00,65,00,74,00,74,00,69,00,6e,00,67,
00,73,00,00,00,18,00,4c,00,31,00,00,00,00,00,2a,35,cb,2e,16,00,
4e,45,54,57,4f,52,7e,31,00,00,34,00,03,00,04,00,ef,be,3a,31,11,
39,2a,35,cb,2e,14,00,00,00,4e,00,65,00,74,00,77,00,6f,00,72,00,
6b,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,18,00,56,
00,31,00,00,00,00,00,2a,35,cb,2e,11,00,46,41,56,4f,52,49,7e,31,
00,00,3e,00,03,00,04,00,ef,be,2a,35,cb,2e,2a,35,cb,2e,14,00,28,
00,46,00,61,00,76,00,6f,00,72,00,69,00,74,00,65,00,73,00,00,00,
40,73,68,65,6c,6c,33,32,2e,64,6c,6c,2c,2d,31,32,36,39,33,00,18,
00,30,00,35,00,00,00,00,00,2a,35,f1,2e,10,00,fe,94,a5,63,00,00,
1c,00,03,00,04,00,ef,be,2a,35,f1,2e,2a,35,f1,2e,14,00,00,00,fe,
94,a5,63,00,00,14,00,00,00,60,00,00,00,03,00,00,a0,58,00,00,00,
00,00,00,00,6c,69,6e,62,61,6f,68,65,00,00,00,00,00,00,00,00,1e,
8c,63,4d,34,72,b3,48,8a,de,83,67,8f,38,be,10,b1,a9,fd,89,90,40,
db,11,b2,29,00,d0,59,c0,b8,59,1e,8c,63,4d,34,72,b3,48,8a,de,83,
67,8f,38,be,10,b1,a9,fd,89,90,40,db,11,b2,29,00,d0,59,c0,b8,59,
00,00,00,00
5、在HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState
7、在HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\链接
HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsListC:WINDOWSSystem32WBEMwinlogon.exe
以上便是手动清除winlogon.exe电脑病毒的详细操作,由于操作起来步骤比较多,所以用户在操作的时候一定要注意,不要删除错了注册表,以免影响到其它功能无法正常使用。
发表评论
共0条
评论就这些咯,让大家也知道你的独特见解
立即评论以上留言仅代表用户个人观点,不代表系统之家立场