Down.exe/virus. win32.autorun. Z/Trojan. PWS. maran.262
EndurerOriginal2Added replies from Kaspersky.1Version
When you open a page that is occasionally used in the Forum, rising prompts you to download and run suspicious files.
Search by Google, and Google has already marked it:Http://www.google.cn/search? Complete = 1 HL = ZH-CN newwindow = 1 Q = % E8 % BF % 98% E7 % 8f % A0 % E5 % 8C % Ba + % E6 % 97% A7 % e9 % 9B % A8 % E6 % a5 % BC % E6 % B8 %
" Time (HH:MM:SS) Alarm "Item to set your boot times, such as: 6:30:00, then your computer will be automatically turned on at 6:30 A.M.. After setting, return to the main interface, press F10 key to save your settings. Not all motherboards support this feature, there are some old models of motherboards and some of the kitchen boards do not have this function, you should first look at the motherboard instructions to see if the support of this feature.
Auto Start Program
Automatically started pr
Solve the autorun And mags. pif viruses in linux-general Linux technology-Linux technology and application information. The following is a detailed description. Yesterday, my computer experienced symptoms of poisoning. After I started the computer, I found that the system time was changed. Then, after double-clicking each system disk, the address book page will appear. I can only right-click it and find two hidden virus files:
Today, a classmate has a virus in his computer, but there are many important things in the computer, such as virus-style Autorun. INF is a stubborn old virus. As long as the deletion is not clean, it will immediately copy and implant everything in the computer into such a file, which is usually in the root directory, when each drive disk is opened, the virus runs automatically, and is added to each drive disk. Then, the virus gradually spreads to each
Prevention Methods: USB flash drives with viruses to your computer and solutions to viruses:
1. When inserting a USB flash drive, press and hold the "shift" key on the keyboard until the message "devices can be used" is displayed. You can release the "shift" key. Do not double-click it when enabling the USB flash drive, do not use context menu.To open a single "open" option, use the Resource Manager(START-allProgram-Attachment-Windows resource manager. After you open the resource manager, you m
The other day, my sister used a USB flash drive to bring back a virus named "autorun Storm" from school. After being poisoned, double-clicking any drive letter will pop up a form, and some Trojans may be downloaded.
Clear method:
Shut down the wscript.exe process in the Resource ManagerShow all hidden files and system filesSearch Autorun .*Delete all searched filesOpen the registry and search "userinit".
The root directory of the mobile hard disk may not be deleted at any time. vinf file, opened with hexeditor, binary, but from the end of the ASCII code, you can see jwgkvsq. vmx. Search online to find out that this is a relatively new virus.
In fact, if the virus is not infected with the system, you can enter the security mode and perform the following operations:
1. Shut down the system. Welcome;
2. Disable the recycle bin function;
3. Add the Administrators group to folders such as recycler a
Install Tomcat7.0 and boot Autorun in Ubuntu1. Mounting Tomcat7.0Generally green version, download a tomcat7.0 to the specified directory can beThen go to the Bin folder of the Tomcat directory and execute sudo./startup.sh to complete the boot2. Boot Autorun tomcat7.0Enter, enter, and modify/etc/rc.local with root accessAs follows:#!/bin/sh-e## rc.local## This script was executed at the end of each multiuse
Autorun virus Defender is a special for the popular U disk virus development of the killing program. Its unique precision killing and expansion of the killing double killing mechanism can thoroughly remove viruses and trojans related files and registry entries, do not leave remnants. With a unique heuristic killing engine, the unknown U disk virus has more than 90% of the recognition rate. The software is built with Intel (R) multi-core processor opti
Autorun. inf and registry NoDriveTypeAutoRun key values
Binary digits
8
7
6
5
4
3
2
1
Type
1
RAMDISK
CDROM
REMOTE
FIXED
REMOVABLE
NO_ROOT_DIR
UNKNOWN
Name
Memory
Optical Drive
Network ing
Hard Disk
Mobile storage
No drive letter
Unrecognized
Decimal Value
128
64
32
16
8
4
2
1
is also silent Ah, today installed under the latest version of the Webstorm, found special card, the old motionless on the card to die, see the next process, Bull X Ah, git for Windows has been rubbing against the crazy growth, a little to the beginning of the behemoth.Just a minute.This computer can not die ...Manual off the next process, obviously not card, but a will come out again, very depressed .....-----------------------------------------------------Online search, how to disable this pro
Today, I found that the computer was abnormal. I only needed to open the folder on the left side of the Windows resource manager, and the cmd.exe crashed. I checked that w32.downadup. Autorun virus was detected. Although the latest version of Rising antivirus software is installed on the machine, the virus cannot be detected at all. Symantec can detect it, but the Organization's confidential computers do not allow the installation of foreign anti-viru
EndurerOriginal1Version
A netizen said that no matter what website he opened on his computer, the displayed pages were hxxp: // 218.*1 *. 1*4.170 vip1.htm and vip2.htm.
Hxxp: // 218.*1 *. 1*4.170/vip1.htm content is US-ASCII encoded. Download http://purpleendurer.ys168.com encoding decoding to US-ASCIIProgramThe obtained content contains the Javascript script.CodeThe function is to download the file 611.exe, save it as C:/Microsoft.com, and run it.
File Description: D:/test/611.exeAttribute:
Configuration cronCron service every minute not only to read all the files within/var/spool/cron, but also to read a/etc/crontab, so we configure this file can also use the Cron service to do something. The crontab configuration is for a user, while the edit/etc/crontab is a task for the system. The file format for this file is:Shell=/bin/bashPath=/sbin:/bin:/usr/sbin:/usr/binMailto=root//If an error occurs, or if there is data output, the data is sent to this account as an emailhome=///user-ru
U disk again in the Autorun virus, really annoying! Is there a simple anti-virus method?
First insert the U disk, then create a new text document, add the following in it:
@echo on
Taskkill/im explorer.exe/f
Taskkill/im W.exe
Start reg add hkcusoftwaremicrosoftwindowscurrentversionexploreradvanced/v showsuperhidden/t reg_dword/d 1/f
Start reg Import Kill.reg
Del c:autorun.*/f/q/as
Del%systemroot%system32autorun.*/f/q/as
Del d:autorun.*/f/q/as
You can create 4 auto-run macros in standard modules in Excel, which are Auto_Open (run automatically when you open the workbook), Auto_Close, Auto_Activate, Auto_Deactivate. These autorun macros are reserved for compatibility with EXCEL5 and 95. You can now replace them with the Open,close,activate,deactivate event of the workbook.So, what is a "standard module"? In fact, the module we inserted in the VBE, Microsoft called it a "standard module." Whi
Virus. win32.autorun. Xu is infected with a traffic violation query webpage.EndurerOriginal2007-10-26 th1Version
The problem lies in the counter code used by the webpage:/------/
Check out the code of hxxp: // www. H * C ** JJ ** d.com/wfcx/count/online.asp:/---Document. write ("---/There are so many things to be hung up ~
I found hxxp: // W ***. 7 *** 373 * 4.cn/reg.htm? A. Code:/------/
Hxxp: // W **. 7 ** 373 * 4.cn/dog.htm content:/------/
Hxxp: /
A forum is infected with worm. win32.autorun. eyh
The forum page contains code:/------/
Hxxp: // www.5 ** 4 * z ** c.cn/1*%7aq/q.jsOutput code:/---
Hxxp: // M **. SF * S3 ** wws.cn/03/x4.htmCode included:/------/
Hxxp: // M **. SF * S3 ** wws.cn/03/google.htmA previously unknown encryption method is used. The first part of the code is:/------/
Its function is to check the browser software. If it is an Internet browser, ie.swf is displayed, and ff.swf
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.