设为首页
收藏本站
本站论坛
   
3
3
   
  文章列表      

病毒查杀-OSO.EXE 美女游戏.PIF 重要文件.EXE 成人小说.exe 广谱查杀法

OSO.exe">exe">exe">exe 美女游戏.PIF 重要文件.exe">exe">exe">exe 成人小说.exe">exe">exe">exe 广谱查杀法


    先使用流行U盘病毒全面专杀工具(USBCleaner)【下载地址:http://bbs.360safe.com/attachment.php?aid=13567   置顶的索引帖子里也有】的U盘病毒免疫功能,这很重要!
  
下载一种叫ICESWORD【下载地址:http://bbs.360safe.com/attachment.php?aid=6090   顶的索引帖子里也有】的工具, 改下名字比如123.exe">exe">exe">exe 要设置里选定 禁止进程创建 结束几个进程.
   有两个进程是固定的
   C:\WINDOWS\system32\drivers\conime.exe">exe">exe">exe
   C:\WINDOWS\system32\severe.exe">exe">exe">exe

   还有一个进程名称是随机的,一般是6位字母随机组成,比如C:\WINDOWS\system32\gfosdg.exe">exe">exe">exe 但都是在C:\WINDOWS\system32\下,其图标一般是记事本的图标.

   再用ICESWORD,将进程里结束的这几个文件删除掉,除了这三个文件在C:\WINDOWS\system32\drivers\下应该还有一个病毒文件,它和 C:\WINDOWS\system32\drivers\conime.exe">exe">exe">exe大小是一样的,同样是记事本图标,

打开C:\WINDOWS\system32\drivers\etc\Hosts 将内容清空,也可删除.
再用ICESWORD,查看注册表:将下列项目删除
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\360Safe.exe">exe">exe">exe
Debugger
C:\windows\system32\drivers\mpnxyl.exe">exe">exe">exe 都是指向此项,以下不一一列述
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\adam.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\avp.com
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\avp.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\IceSword.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\iparmo.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\kabaload.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\KRegEx.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\KvDetect.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\KVMonXP.kxp
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\KvXP.kxp
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\MagicSet.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\mmsk.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\msconfig.com
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\msconfig.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\PFW.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\PFWLiveUpdate.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\QQDoctor.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\Ras.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\Rav.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\RavMon.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\regedit.com
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\regedit.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\runiep.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\SREng.exe">exe">exe">exe
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\TrojDie.kxp
HKEY_LOCAL_MACHINE\SOFTWARE\MicrOSOft\Windows NT\CurrentVersion\Image File exe">exe">exe">execution Options\WoptiClean.exe">exe">exe">exe

运行MSCONFIG,将指向病毒文件的启动项删除

使用专杀工具的广谱扫描功能,修复注册表! 将日期修复!

这只是一种广谱查杀的方法,大家可以试一下!
 
 
   
 
网上赚钱申请指南
 

友情链接
个人主页
 
 
 
 

wel come to . 欢迎光临
宇宙浪仔