Newest Virus Variant sxs.exeand xeklsk.exe (CONAN virus) detection and removal methods

Source: Internet
Author: User

The virus sxs.exe, which passes through the USB flash drive, has always been very powerful. He had killed n computers ~~ Its variants are also being updated, and the pattern is white ~~ .
You cannot hide a file by using the folder option.
After repeated searches, this virus is the latest variant, and there are very few methods for detection and removal on the Internet ~ The following are provided for reference only:
----
Solution:
* ** Note: Do not double-click the drive letter during the antivirus process. Right-click and choose "open "! ***
1.20.process xeklsk.exe, sxs.exe, and other suspicious processes.
2. display the hidden system file.
Run -- regedit
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ windows \ CurrentVersion \ explorer \ Advanced \ Folder \ Hidden \ SHOWALL, change the CheckedValue to 1
** Note: the virus will delete the valid DWORD Value CheckedValue, create an invalid string value CheckedValue, and change the key value to 0! It is useless to change this to 1.
Modification Method: Delete the CheckedValue, right-click New -- Dword Value -- name it CheckedValue, and modify its key value to 1, then, select "show all hidden files" and "Show System Files" in the folder -- tools -- folder option ".
Worker Process ).
4. Start-run-msconfig to delete the startup items of the above virus.
5.d、e0000f..open the right-click option and delete the sxs.exe and autorun. inf files on each drive.
Check whether there are any of the above processes in the process. If there are other instructions that the virus is not cleared, repeat the above steps to complete the antivirus process!

You can use the USB flash drive virus exclusive tool to kill viruses.
USB flash drive virus exclusive tool USBCleaner4.0 download
Http://www.live-share.com/files/148851/USBCleaner.4.0.blog.egotong.com.rar.html

Virus behavior analysis:
Sxs.exe worm. pabug. ao
Generate file:
C: \ WINDOWS \ system32 \ jvmlts.exe 38,464 bytes
C: \ WINDOWS \ system32 \ jvmlts. dll 39,424 bytes
C: \ WINDOWS \ system32 \ QQhx. dat 38,464 bytes
U: \ sxs.exe
U: \ autorun. inf
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ Hidden \ NOHIDDEN \ showall \ checkedvalue
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ shell
Assumer.exe C: \ windows \ system32 \ jvmlts.exe

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.