The virus registers itself as an NT Service to start upon startup:
[TomDemoService/TomDemoService] [Running/Auto Start] <C: \ CONFIG. EXE> <N/A>
Deletion method:
1. The tool PowerRMV or XDELBOX that can be considered for deleting files first C: \ CONFIG. EXE
C: \ CONFIG. dll is ignored if it does not exist.
C: \ CONFIG_key.dll is ignored if it does not exist.
C: \ CONFIGhook. dll is ignored if it does not exist.
C: \ CONFIG. log is ignored if it does not exist.
2. restart the computer to enter safe mode. Use SREng to delete the registered service. Start the project --> service --> Win32 service application to delete the following items
[TomDemoService/TomDemoService] [Running/Auto Start] <C: \ CONFIG. EXE> <N/A>
We recommend that you use 360 security guard: www.360safe.com to clear (delete) all detected items)
Finally, change the QQ account and password of online games.
Appendix: several cases to suit the remedy:
Copy codeThe Code is as follows: Case 1:
Sender: match510520 (pick you up on the West Station !), Email: Virus
Question: The computer calls every 10 seconds. Please take a look at the log for me. Thank you!
Mailing station: shuimu community (Mon Apr 2 12:37:24 2007), within the station
The interval between every buzz is about 10 seconds. This sound is like a pop-up dialog box where you don't click OK or cancel it, but when you click it elsewhere. I don't know how to solve it? Thank you for your help!
Case 2. Repeated antivirus attempts do not help. Thank you.
Q: The problem has been solved.
Case 3. Repeated antivirus attempts do not help. Thank you.
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.