U disk virus VistaAA.exe Manual killing method _ virus killing
Source: Internet
Author: User
Modified:2008 year May 8, 18:52:32
md5:7009ac302c6d2c6aadede0d490d5d843
sha1:0e10da72367b8f03a4f16d875fea251d47908e1e
crc32:dce5ae5a
After virus runs:
1. Release a sbl.sys to the%system32%\drivers below, and copy a cover Beep.sys, then load the drive, restore SSDT hook, resulting in some anti-virus software active defense function failure.
2. End the process of many anti-virus software and security tools
Such as:
6. Create a Registry Startup Project
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<LoveHebeAA><C:\WINDOWS\system32\vistaAA.exe>
The purpose of booting itself up
7. Create a timer every 1800 seconds to start the virus itself
Purge method:
1. Restart Computer access
In Safe Mode (after Power-on press F8 key and then come out an advanced menu to select the first safe mode to enter the system)
Open Sreng:
Start the Project registry delete the following items
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.