比肩病毒查杀
推荐
原创
©著作权归作者所有:来自51CTO博客作者cy051799的原创作品,请联系作者获取转载授权,否则将追究法律责任
病毒一般都具隐藏了的,如果我们的计算机种了比肩病毒在任务管理器里都会有mslogon.exe出现,我们可以结束它的病毒.们打开c:\windows\system32\mslogon.exe
c:\windows\system32\wincfgs.exe
找到这两个文件不要急忙删出.在C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\systemnt.exe或是windows.exe删出就可以了.在到注册表中查找mslogon.exe删出即可重起就可以了.
3、当用户插入移动设备时,病毒将自身复制为以下文件:
%Root%\toy.exe
半生成自启动文件"%root%\autorun.inf",文件内容如下:
[autorun]
shellexecute=Toy.exe
4、用户机器中毒病毒,病毒在用户桌面显示如下信息:
PS: can you find the program',27h,'s interface ?
History Must Be Remeber !
God said: Let there be light. And there was light.
And darkness was upon the face of the deep.
And the earth was without form, and void
In the beginning God created the heaven and the earth.
仅以此悼念比肩!
......
比肩社区( Compare And Cooperation ):
++++++++++++++++++++++++++++++++++++++++++++++++++
变种的比肩是将winlogon.exe 改成winlogOn.exe