Winsys16_070307.dll,windowsupdate.exe Removal method _ virus killing

Source: Internet
Author: User
First, ask questions:
IE has been hijacked, Userinit.exe has been changed (log slightly)

Second, analysis

1. Turn off System Restore before antivirus (Win2000 system can be ignored): Right button My Computer, properties, System Restore, turn off System Restore tick on all drives.
Clear IE Temporary files: Open IE point tool-->internet option: Internet temporary files, click the "Delete Files" button, will delete all offline content tick, click OK Delete.

Close applications such as QQ. Do not do any double-click to open the disk until you do the following. All downloaded tools are placed directly on the desktop.

2. Delete the files listed below using the Force Removal Tool Xdelbox (file deletion terminator).

"Copy all the paths to delete files when you delete them, right-click on the file list you want to delete, and select Import from Clipboard. After the import to delete the file on the right click, choose to restart the deletion immediately, the computer will restart into the DOS interface for deletion, delete the completion will automatically restart into your installed operating system. Remember to save the document you are opening on your computer before you operate. For more information on Xdelbox, please see Help.chm in the xdelbox1.2 directory. 】

"There is no hint to find, please file a file in the input" file path ", the absence of the ignore can be"
C:\WINDOWS\system32\winsys16_070307.dll
G:\program Files\tencent\qq\hgtghrgp.dll
C:\Program Files\Internet Explorer\xsgcilqf.dll
C:\WINDOWS\WindowsUpdate.exe


3. After restarting the computer, use the tool Sreng to do the following operations

The contents of the "Sreng reminder after opening" function do not match the expected value they may be modified by some malicious software "Please ignore the error, install the normal modification after the soft." 】
Also: Please pay special attention to some items mentioned in the link above are edited and cannot be deleted.
==================================
(1) Start Project--> the registry of the following key edit [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
<userinit><c:\windows\system32\userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_070307.dll Start > [n/A]
For initial point <Userinit><C:\WINDOWS\System32\userinit.exe,> note commas cannot be omitted
(2) Startup item--> the registry with the following deletion

[Hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
<{4dec9b29-f08f-4cbc-b179-592b9283fab1}><g:\program files\tencent\qq\hgtghrgp.dll> [n/A]
<{05397e9d-30d1-4216-aacb-f9ea1f1e4e85}><c:\program files\internet explorer\xsgcilqf.dll> [n/A]

==================================
Start the project--> service-->win32 The following item deletion of the service application
[Windowsupdate/windowsupdate] [Stopped/auto Start]
<C:\WINDOWS\WindowsUpdate.exe><N/A>

QQ is best to reload after unloading. Pay attention to the change of QQ password.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.