Trojan-Dropper.Win32.Dropkit.a virus removal

Source: Internet
Author: User

One month later, Kaspersky was so annoying to listen to the voice of "pig" every day. Kaspersky was able to delete files only when encountering this virus, but the virus had a system service in the background, A virus file will be generated later. If your machine is infected with this trojan virus, the machine performance will be greatly reduced, a bit like a worm, sometimes blue screen.

Among them are "C:/Windows/system32/Drivers/procserv. sys ", the Internet found more such virus information is," Trojan-Dropper.Win32.Dropkit.a file in C:/Windows/system32/Drivers/nwupspx. sys ", and there is no way to clear the network, I think the above two files are the same type of virus. No way. You can't work well this morning. You can delete procserv in security mode first. sys, deleted and released again. Strong! Go to Regedit to open the registry and find "HKEY_LOCAL_MACHINE/system/controlset001control/safeboot/minimal/procserv". This system service is really available, delete it, refresh it, and the virus service comes out again. No way. You can't delete it. Modify its information. No way. You have to try any methods. set its default registration information to "driver ", you can change it to "0", and then take a closer look at the following registry keys automatically generated by viruses. If you delete them, they are generated,

"HKEY_LOCAL_MACHINE/system/controlset002/Enum/root/legacy_procserv"

"HKEY_LOCAL_MACHINE/system/controlset002/control/safeboot/minimal/procserv"
"HKEY_LOCAL_MACHINE/system/controlset002/control/safeboot/Network/procserv"

Then, I deleted procserv under "HKEY_LOCAL_MACHINE/system/controlset001/services,

Then, set all the Registry Information "ImagePath" items under this registration item. If yes ?? .

After the machine restarts, The procserv. SYS file under the C:/Windows/system32/DRIVERS directory is manually deleted,

If a virus file is automatically generated, its date is the latest. After deletion, the file is not generated and the system speed is much faster,

Although the virus has not been cleared from the root, it is completely unable to run normally, but it has also achieved the purpose of anti-virus.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.