Antivirus software is disabled, hidden files can not be displayed, start command msconfig can not run, a lot of assistive software also can not run, run EXE and SCR files after the virus infection
Code:
C:\WINDOWS\system32\Supervise.exe (This Supervise.exe calls Net.exe an infection of the local domain network and creates the file:%system32%\death.sishen, which writes the virus information into this file)
(This process will also Supervise.exe open port connection network download Trojan!!! That's disgusting.)
C:\WINDOWS\system32\Death.SiShen
C:\WINDOWS\system32\Death.exe (This process generates Supervise.exe files)
C:\WINDOWS\system32\Death.SiShen
And a anto hidden file under each packing directory.
Double-click the hard drive will also cause the virus to run please click on the right button-open
Search for windows that attempt to turn off antivirus and assistive software
Attempt to turn off antivirus and assistive software processes
Search for an infected. exe/.scr file except the system disk.
The infected. exe/.scr file is replaced directly. Size is: 81,928 bytes. All of the. exe/.scr files cannot be recovered. After running the infected EXE file, the virus will be released!
Can be spread through regional networks (Death.exe)
Manual removal Method:
1: Shut down System Restore empty IE Temp folder
2: Into Safe mode
Terminate process Death.exe Process
3: With Xdelbox software hook on the suppression of regeneration after the deletion of the following files:
------Sreng Software in system repair-----------all
-----or open the registry to start running--regedit-modifier straight
Hkey_local_machine\software\microsoft\windows\currentversion\explorer\advanced\folder\hidden\showall, Modify the CheckedValue key value to 1
------Some of the virus variants will directly delete this checkedvalue, just like the following, you can build one again (step: Delete this CheckedValue key value, right-click New--dword value-named "CheckedValue" , modify the key value to 1)
--Back up
------Manually delete the auto hidden file below each disk
------reboot (not to point to the infected EXE, SCR file!!) )
------Safe Mode anti-virus software Scan Delete virus residue infection files and cooperate with 360 repair system
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.