Some days ago the computer in the "Sxs.exe virus", and then sorted out a "Sxs.exe Virus manual removal Method", did not expect a few days, through the search for friends to break through the 8000 mark, this virus attack is widely imagined.
Antivirus software side has finally launched a special kill tool for this virus, and then encounter this problem friends do not have to do their own.
Description
Reference
At the beginning of August, there was a large number of malignant viruses written for mainstream anti-virus software. In addition to common hazards, they will also cause mainstream anti-virus software and personal firewall can not open, and even lead to anti-virus when the system appears "blue screen", automatic restart, panic and other conditions.
Rising "Orange August special Extraction Removal Tool" specifically for such viruses to write, you can clear the "QQ Pass (Trojan.PSW.QQPass)", "Legendary Terminator (Trojan.PSW.Lmir)", "Missimma (Trojan.psw.misc)" and other viruses and variants. Rising anti-virus software does not install the user can download the use of free.
Note: It is recommended that you restart your computer, hold down the F8 key, select "Safe Mode" and use this tool to disinfect the virus after entering.
Attached: Virus list virus is mainly for the following security software
Kaspersky
Symantec AntiVirus
Rising
Jiangmin Anti-Virus Software
Skynet Firewall Personal Edition
Phage
Mumak Star
Jinshan Poison PA
Orange August Special Extract removal Tool download Address:
Http://it.rising.com.cn/Channels/Service/2006-08/1154786729d36873.shtml
***************************************
Sxs.exe Virus Manual Removal method
The first time ever encountered such a stubborn virus, online looking for, there is no uniform name, rising called TROJAN.PSW.QQPASS.PQB virus, I call it sxs.exe virus it
After reloading the system, double-click the partition disk again in the, depressed, rising automatic shutdown can not open, decided to manually delete it
Phenomenon: System files hidden cannot be displayed, double-click the letter does not reflect, Task Manager found Sxs.exe or Svohost.exe (with the system process svchost.exe a word of the difference), anti-virus software real-time monitoring automatic shutdown and can not open
Find a lot of methods on the Internet, can not be effectively deleted, and no Kill tools
To manually delete the Sxs.exe virus method:
You must not double-click the partition disk in the following procedure, and you need to open it with the right mouse button-open
First, shut down the virus process
Ctrl + Alt + Del Task Manager, find SxS or svohost in the process (not svchost, one letter), and then end it.
Second, show the hidden system files
Run--regedit
HKEY_LOCAL_MACHINE "Software" Microsoft Windows "CurrentVersion"
Explorer "Advanced" folder "Hidden" ShowAll,
Modify the CheckedValue key value to 1
Notice here, the virus will be valid DWORD value CheckedValue deleted, a new invalid string value CheckedValue, and the key value to 0! It's no use changing this to 1. (Some of the virus variants will directly delete this checkedvalue, just like the following, you can build a new one on it)
Method: Delete the CheckedValue key value, right-click the new--dword value-named CheckedValue, and modify its key value of 1 so that you can select Show all hidden files and show system files.
Set system files and hidden files to display in folder--Tools--Folder Options
Third, remove the virus
Right-click on the partition disk-open and see that there are Autorun.inf and sxs.exe two files in each disk and directory and delete them.
To find the Soundmam key value, there may be two, delete the key value of C:\WINDOWS\system32\SVOHOST.exe
Finally, delete the SVOHOST.exe or Sxs.exe in the C:\WINDOWS\system32 directory
Restart the computer, found that anti-virus software can be opened, partition disk double-click can be opened.
V. Follow-up
Anti-Virus software real-time monitoring can be opened, but the boot can not automatically run
The easiest way to do this is to perform the add-on removal component of the antivirus software-fix it.
More people have recently found poisoning. Related Software downloads Http://upload.programfan.com/upfile/200611280727787.rar
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.