看板 AntiVirus 關於我們 聯絡資訊
1.使用icesword,在Functions的Process中,右鍵terminate下列進程 C:\WINDOWS\msmsgrs.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\svho.exe C:\WINDOWS\system32\mssdh.exe 2.刪除下列 登錄檔值 登錄檔路徑:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 登錄檔名稱:MsnLiveMessenger 登錄檔數值:msmsgrs.exe 登錄檔路徑:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 登錄檔名稱:System Service Manager Device 登錄檔數值:svho.exe 登錄檔路徑:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 登錄檔名稱:Microsoft System Service Device 登錄檔數值:mssdh.exe 登錄檔路徑 :HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices 登錄檔名稱:[Key] [Key]是指所有的值,也就是,我要你刪除 整個RunServices 請注意,先看看 RunServices 下面,有幾條登錄檔,並查看其值,依據需要, 把值裡面顯示的檔案,也一併刪除! 3.刪除下列檔案 C:\WINDOWS\ChristmasImg2007-12.zip C:\WINDOWS\msmsgrs.exe C:\Documents and Settings\(用戶名稱)\Local Settings\Temp\eraseme_78082.exe C:\WINDOWS\system32\svho.exe C:\WINDOWS\system32\mssdh.exe 4.用ccleaner 清掉 暫存檔 5.完工 ----------------------------------------------- 測試用的病毒載點: http://www.badongo.com/file/7055095 完整測試內容: http://www.avpclub.ddns.info/discuz/thread-7250-1-1.html -- ※ 發信站: 批踢踢實業坊(ptt.cc) ◆ From: 61.216.197.192
lcjjaff:S大測試~推一個<( ̄︶ ̄)> 12/27 17:47
SDUM:根據別人的圖,新增 C:\WINDOWS\system32\mssdh.exe 12/27 20:08
※ 編輯: SDUM 來自: 61.216.197.192 (12/27 21:28)
cooger:如何刪除豋入檔??? 12/27 23:30
SDUM:從icesword的左邊,Registry進去,沿著路徑砍 12/28 06:57