Sunway logo1_.exe Complete removal technique [original]_ virus killing

Source: Internet
Author: User
Logo1_.exe files on the computer recently
Run the following file first
Copy Code code as follows:

@echo off
If exist%windir%\rundl132.exe echo found Sunway!
Pause
taskkill/f/im Rundl132.exe
taskkill/f/im Logo_1.exe
taskkill/f/im Logo1_.exe
taskkill/f/im Ravmon.exe
taskkill/f/im Eghost.exe
taskkill/f/im Mailmon.exe
taskkill/f/im KAVPFW. Exe
taskkill/f/im Iparmor. Exe
taskkill/f/im Ravmond.exe
taskkill/f/im 0sy.exe
taskkill/f/im 1sy.exe
taskkill/f/im 2sy.exe
taskkill/f/im 3sy.exe
taskkill/f/im 4sy.exe
taskkill/f/im 5sy.exe
taskkill/f/im 6sy.exe
taskkill/f/im 7sy.exe
taskkill/f/im 8sy.exe
taskkill/f/im 9sy.exe
taskkill/f/im 10sy.exe
taskkill/f/im 11sy.exe
taskkill/f/im 12sy.exe
taskkill/f/im 13sy.exe
taskkill/f/im 15sy.exe
taskkill/f/im 25sy.exe

:: Above to end the virus process.


attrib%windir%\logo1_.exe-s-r-h
attrib%windir%\rundl132.exe-s-r-h
attrib%windir%\0sy.exe-s-r-h
attrib%windir%\vdll.dll-s-r-h
attrib%windir%\1sy.exe-s-r-h
attrib%windir%\2sy.exe-s-r-h
attrib%windir%\rundll32.exe-s-r-h
attrib%windir%\3sy.exe-s-r-h
attrib%windir%\5sy.exe-s-r-h
attrib%windir%\1.com-s-r-h
attrib%windir%\exerouter.exe-s-r-h
attrib%windir%\exp10rer.com-s-r-h
attrib%windir%\finders.com-s-r-h
attrib%windir%\shell.sys-s-r-h
attrib%windir%\kill.exe-s-r-h
attrib%windir%\sws.dll-s-r-h
attrib%windir%\sws32.dll-s-r-h
attrib%windir%\uninstall\rundl132.exe-s-r-h
attrib c:\windows\SVCHOST.exe-s-r-h
attrib c:\windows\WINLOGON.exe-s-r-h
attrib c:\windows\RUNDLL32. Exe-s-r-h
attrib c:\ "program Files" \svchost.exe-s-r-h
attrib c:\ "program Files" \ "Internet Explorer" \svchost.exe-s-r-h
attrib%windir%\download\svchost.exe-s-r-h
attrib%windir%\system32\wldll.dll-s-r-h
attrib c:\windows\system32\Microsoft\svchost.exe-s-r-h


del/f/s/q/A%systemdrive%\rundl132.exe
del/f/s/q/A%systemdrive%\rundll32.exe
del/f/s/q/A%systemdrive%\dll.dll
del/f/s/q/A%systemdrive%\vdll.dll
del/f/s/q/A%systemdrive%\logo_1.exe
del/f/s/q/A%systemdrive%\logo1_.exe
del/f/s/q/A%systemdrive%\logo1.exe
del/f/s/q/A%systemdrive%\?sy.exe
del/f/s/q/A%windir%\logo1_.exe
del/f/s/q/A%windir%\rundl132.exe
del/f/s/q/A%windir%\0sy.exe
del/f/s/q/A%windir%\vdll.dll
del/f/s/q/A%windir%\1sy.exe
del/f/s/q/A%windir%\2sy.exe
del/f/s/q/A%windir%\rundll32.exe
del/f/s/q/A%windir%\3sy.exe
del/f/s/q/A%windir%\5sy.exe
del/f/s/q/A%windir%\1.com
del/f/s/q/A%windir%\exerouter.exe
del/f/s/q/A%windir%\exp10rer.com
del/f/s/q/A%windir%\finders.com
del/f/s/q/A%windir%\shell.sys
del/f/s/q/A%windir%\kill.exe
del/f/s/q/A%windir%\sws.dll
del/f/s/q/A%windir%\sws32.dll
del/f/s/q/A%windir%\uninstall\rundl132.exe
del/f/s/q/A C:\windows\SVCHOST.exe
del/f/s/q/A C:\windows\WINLOGON.exe
del/f/s/q/A c:\windows\RUNDLL32. Exe
del/f/s/q/A C:\ "program Files" \svchost.exe
del/f/s/q/A C:\ "program Files" \ "Internet Explorer" \svchost.exe
del/f/s/q/A C:\windows\Download\svchost.exe
del/f/s/q/A C:\windows\system32\Microsoft\svchost.exe
del/f/s/q/A C:\windows\system32\wldll.dll
del/f/s/q/A C:\_desktop.ini
del/f/s/q/A D:\_desktop.ini
del/f/s/q/A E:\_desktop.ini
del/f/s/q/A F:\_desktop.ini

:: Above to delete virus related files.

NET share C $/del
NET share d$/del
NET share e$/del
NET share f$/del
NET share admin$/del
NET share ipc$/del
Pause
taskkill/f/im Conime.exe
Exit

The files provided include the execution sequence Killlogo1.bat Logo1 immune patch. BAT prohibits running Logo1.exe virus. reg
Download this file
The most important:
This Trojan hates the place is, even if redo the system, the virus still exists, it will make all the EXE files in the hard drive and the virus files merged into a file, when you run other executable files, it will also run. So when you see your original file icon change, it means you're in it, but , just look at it and you can easily solve it.
Upgrade your anti-virus software to the latest version, you can clear this file things, I use is rising to 12.1
1, the operating system security mode method: When the system starts to press F8 key, enters the safe mode, because enters the safe mode to be able to load the least process, also effectively prevents the virus the operation,
2, after the start of your antivirus software, to kill, if your hard drive exe executable file more words, will be very slow, but no way, it is so painful.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.