Shualai.exe Virus and Manual killing method _ virus killing
Source: Internet
Author: User
This is a use of ANI to spread the Trojan Horse group, its "dynamic insertion process" function is caused by the difficulty of antivirus after the one of the reasons.
Another: After the recruit, the system partition of the. exe is all infected. This is also the problem after the poison.
"Symptoms" After the Recruit: Shualai.exe process is visible in the list of processes.
Suggestion: Use Sreng to keep the log, in order to understand the basic situation, easy to the back of the manual antivirus operation.
Manual killing process is as follows (with IceSword operation):
1, prohibit the process creation.
2, according to the Sreng log, the first end of the virus process shualai.exe and all the processes inserted by the virus module (virus inserted which process, depending on the program you were running.) Here's an example of how I ran the sample. )
3, delete the virus file, empty IE temporary folder.
4. Remove virus Startup Items
Consider a special case:
If someone put autoruns and other tools outside the system partition, at this time run Autoruns ———— trouble big!! After this poison is in the ————, all of the. exe outside the system partition is infected.
5, Cancel IceSword "Prohibit process creation".
6, repair the Hosts file.
Note: Those outside the system partition are infected with the virus. exe--is not expected to be hopeless.
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service