One month later, Kaspersky was so annoying to listen to the voice of "pig" every day. Kaspersky was able to delete files only when encountering this virus, but the virus had a system service in the background, A virus file will be generated later. If your machine is infected with this trojan virus, the machine performance will be greatly reduced, a bit like a worm, sometimes blue screen.
Among them are "C:/Windows/system32/Drivers/procserv. sys ", the Internet found more such virus information is," Trojan-Dropper.Win32.Dropkit.a file in C:/Windows/system32/Drivers/nwupspx. sys ", and there is no way to clear the network, I think the above two files are the same type of virus. No way. You can't work well this morning. You can delete procserv in security mode first. sys, deleted and released again. Strong! Go to Regedit to open the registry and find "HKEY_LOCAL_MACHINE/system/controlset001control/safeboot/minimal/procserv". This system service is really available, delete it, refresh it, and the virus service comes out again. No way. You can't delete it. Modify its information. No way. You have to try any methods. set its default registration information to "driver ", you can change it to "0", and then take a closer look at the following registry keys automatically generated by viruses. If you delete them, they are generated,
"HKEY_LOCAL_MACHINE/system/controlset002/Enum/root/legacy_procserv"
"HKEY_LOCAL_MACHINE/system/controlset002/control/safeboot/minimal/procserv"
"HKEY_LOCAL_MACHINE/system/controlset002/control/safeboot/Network/procserv"
Then, I deleted procserv under "HKEY_LOCAL_MACHINE/system/controlset001/services,
Then, set all the Registry Information "ImagePath" items under this registration item. If yes ?? .
After the machine restarts, The procserv. SYS file under the C:/Windows/system32/DRIVERS directory is manually deleted,
If a virus file is automatically generated, its date is the latest. After deletion, the file is not generated and the system speed is much faster,
Although the virus has not been cleared from the root, it is completely unable to run normally, but it has also achieved the purpose of anti-virus.