Latest virus variants Sxs.exe and Xeklsk.exe (Conan virus) Killing methods _ Virus killing

Source: Internet
Author: User
Through the U disk transmission of the virus Sxs.exe power has always been very large, once n a computer was his downfall ~ ~ Its variant is also increasingly refurbished, the pattern white ~ ~ Computer engine room and poisoned ... Each letter has hidden files, the icon is Conan head Sxs.exe and autorun, virus system into the xeklsk.exe.
Hidden files cannot be displayed through Folder options.
After repeated search, the virus is the latest variant, the online method of killing very little ~ now provides the following, for reference only:
————
Solution:
Tip: During the anti-virus process note that the letter does not double-click, click the right mouse button "open"! ***
1. Closure of the process Xeklsk.exe,sxs.exe and other suspicious processes.
2. Display the hidden system files.
Run--regedit
Hkey_local_machine\software\microsoft\windows\currentversion\explorer\advanced\folder\hidden\showall, Modify the CheckedValue key value to 1
* * Note: The virus will be valid DWORD value CheckedValue deleted, a new invalid string value CheckedValue, and the key value to 0! It's no use changing this to 1.
How to: Delete this CheckedValue key value, right-click the new--dword value-named CheckedValue, and then modify its key value of 1, then select Show all hidden files and show system files in folder-tool-Folder options.
3. Delete the hidden files in the System directory System32 folder Xeklsk.exe (Conan Avatar) and Xeklsk.dll (end Explorer.exe process).
4. Start-run-msconfig to remove the startup entry for the above virus.
5.D, E, F ... Right button select Open, delete the Sxs.exe and Autorun.inf files under each letter.
See if there are processes in the process, if there is a description of the virus did not clear clean, repeat the above steps to antivirus complete!

We can use U disk virus kill Tool Antivirus
U disk virus kill tool USBCleaner4.0 download
Http://www.live-share.com/files/148851/USBCleaner.4.0.blog.egotong.com.rar.html


Virus Behavior Analysis:
Sxs.exe Worm.pabug.ao
To generate a file:
C:\WINDOWS\system32\jvmlts.exe 38,464 bytes
C:\WINDOWS\system32\jvmlts.dll 39,424 bytes
C:\WINDOWS\system32\QQhx.dat 38,464 bytes
U:\sxs.exe
U:\autorun.inf
Hkey_local_machine\software\microsoft\windows\currentversion\explorer\advanced\folder\hidden\nohidden\showall\ CheckedValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Nt\currentversion\winlogon\shell
Explorer.exe C:\windows\system32\jvmlts.exe

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.