Solution to changing the color of all the exe icons caused by the Witkin Worm

Source: Internet
Author: User

After computer poisoning, all the exe icons become blurred and color-changing. After Kingsoft's exclusive killer tool, all the exe icons are changed to the asked icon. After you double-click the icon, the system prompts "unable to find the running Link Library FTKernelAPI. dll in the specified path D: \ Wool; C: \ WINNT \ system32; C: \ WINNT \ system; C: \ WINNT \ system32; C: \ WINNT;
C: \ WINNT \ system \ Wbem; C: \ Program Files \ AEI Technologies \ ATI Control Panel"

Solution:

Unfortunately, the Vikin virus was killed for a few days. After studying it for two days, I finally wiped out the virus! I'm so excited.
All kinds of anti-virus software and dedicated killing tools on the Internet cannot cure the virus, and the methods are too simple to introduce, next I will introduce a set of software that combines antivirus software and manual treatment to completely eliminate the maintenance fund!

1. the computer is restarted immediately after the computer is disconnected due to viruses. If advanced anti-virus software is available on the computer after the computer is restarted (Kaspersky is recommended. I tried three anti-virus software and finally found that only Kabbah can detect a large number of viruses, others can only be found a little bit, and they cannot be killed. Kaba downloads are cracked everywhere, so it is not troublesome. You just need to be careful not to download the files to the virus) use anti-virus (remember not to connect to the Internet during this period, otherwise the virus will automatically download the Trojan). If there is no advanced anti-virus software in the computer, after the Internet connection, download a cracked kaback (we recommend that you download a security guard and a vijin rising killer), and then upgrade and disconnect the network! Vikin has a very fast copy. The faster you get, the easier it is to destroy him.

2. After anti-virus software is ready, you can discover that there are many viruses and trojans on your computer. In addition, Kabbah cannot be eliminated once, but the Vikin virus is a little amazing! Your Kabbah can only be used once, and the second Vikin will restrain your Kabbah from making it unavailable (so this time you must kill all the information you have found ), if the security guard and exclusive killing tool are prepared in step 1, convert the computer to safe mode after Kaba is killed (Press F8 at startup to enter ), use the above two tools to kill the virus (these two tools are not very useful, but they can also be eliminated at most ).

3. After the above steps are completed, the initial work will be basically completed. Next, Go to manual antivirus: the virus is generated in the Windows directory dll.dll,logo=.exe,rundl132.exe.

Dll.dllinjection into assumer.exeis completed by logocompute.exe. The virus will automatically add rundl132.exe to start my computer! Select a tool-Folder option-view (press the shortcut key ALT + T and then press O) the "Hide protected operating system files (recommended)" check box to cancel, select "show all files and folders!
Token)
[2]. Because the DLL. dll module is written to explorer, it cannot be deleted. However, there is a way to delete it. Open the task management to end the assumer.exe in the process, and then the desktop disappears! Select "file (F)" -- "new task (run...)" in the task manager ..) (N)" again! Delete the DLL. dll in the C: disk (press CTRL + F to find it and then delete it)
[3]. Enter regedit in the operation to find the registry key value:
[HKEY_LOCAL_MACHINE \ Software \ Soft \ downloadwww]delete it. Then, press ctrlw.fto check the registration table key value rundl132.exe and delete all the key values in this table.
[4 ]. press CTRL + F on my computer and search for _ desktop. ini. delete ini (after deletion, the icon is also displayed. Do not worry about it. Check whether there is any icon after it is turned off)

4. after completing all the above steps, the virus will no longer be able to be copied. The next step is to delete the original Kabbah, re-install Kabbah, and restart, you only need to delete the remaining Trojans. After the virus is eliminated, restart the system and search for any _ desktop in my computer. if the ini file does not exist, congratulations on eliminating all the viruses. If there are other files, repeat the above steps until all the viruses are eliminated.
5. prevent re-infection and run gpedit. msc to open the Group Policy
Choose "user configuration"> "management module"> "system"> "do not enable windows programs. Then, click" add logo=exe ", which is the virus source file.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.