A new version of 2003 SP1 was installed a few days ago, and "VIKING" was unfortunately caught on the Internet. After the virus was cleared manually, 360 security guards were used again, and two pieces of green e software scanned once... I think it is safe. I restarted the machine and found that the major event was not good. The icons of most executable files on the hard disk were gone... in both eyes, I had to scream, and it would be hard to get all the executable files .. I quickly found several normal files from the backup file and compared them with the infected files. It's not too bad. The executable files are all larger in size, and it's all about getting smaller .. Haha .. Immediately download the latest Rising Star update package, install and disinfect the virus. After a burst of madness, rising found that the file had not been detected by virus infection and was speechless, and then pulled out Kabbah, upgrade, and Antivirus installed N years ago, even if Kabbah detects that it cannot be killed, it only deletes files .. Khan... tell the old master (zzzzzzz, http://www.heybrain.com), he said the virus is generally better to clear, so sent him two infected and not infected with the same file. After a while, he finds out that the content before the e4df of the executable file can be deleted and restored. Yeah... the master is the Master. I admire and admire him. Unfortunately, he is not familiar with the structure of PE files, and he cannot get it. He agreed to write a killing tool in the dark... An hour later, because it was too difficult to write and traverse the hard disk, he changed a antivirus DLL and even wrote interface calls ......
After writing the script, the anti-virus service is fine, and the speed is not very fast ..ProgramIt only serves to clear viruses and does not apply too much filtering, so it is inevitable that there will be errors during use.
: Http://lanyus.googlepages.com/killviking.rar
Virus address: http://lanyus.googlepages.com/virus.dat