"Panda burning incense" after another powerful virus removal method

  
These days, because of the need of work, the anti-virus software was uninstalled. I didn't expect the tragedy to happen. In less than two days, my computer had a virus named Trojan-Dropper.Win32.Agent.bct. The role of the virus is to be able to automatically infect all the disks, similar to the rose virus youdian.
I didn't realize that I had a virus, until the work was done, I installed the 360, and then I cheated a Kabbah serial number, installed the KAV6 upgrade, restarted … …
Next, my machine, no, it's Kabbah, it's like screaming …… It's not a bark, it's a million horses calling! It's quite spectacular! I'm dumbfounded ……
So much? Just two days and then look again, is a Trojan?! Nothing … … just set it up, found that the virus does not ask to directly clean up. Waiting for me to come back later and see the harvest ……
Sure enough, it’s over three buckets! —— I’m topping your lungs! Kabbah is finding out the virus, the virus infected file, Kabbah Delete it together!! E disk and F disk two disk nearly 25G information, software ah … …
as long as the exe end … … all give cards! I panic, hurry on the line Help, found that there is no special kill! Currently are manually deleted … …
So find a way to find them, put it on everyone to prevent, take me as a ring!!! Do not think, your machine You can streak on the internet!! Always wear clothes for the machine … … recommend Kabbah or NOD32.
The first method: generate and run _.de in the system root directory, generate _.de.bat, suicide to generate x:\\windows\\system\\internat.exe (if there is a directory with the same name, then that folder) Renamed internat.exe.tmp) Generate autorun.inf and setup.exe under each disk. Run the command cmd.exe /c dir disk other than the system disk: \\*.exe /s /b >>C:\\WINDOWS\\ Win.log according to the file in win.log infected EXE file infection increased by 26890 bytes
killing method:
1, use the command manager to end the process of intern.exe;
2, delete X:\\windows\\system\\internat.exe;
3, right click to enter each disk, delete the following autorun.inf and setup.exe;
4, create a file named _.de in the root directory of the system disk Folder;
5, use anti-virus software to thoroughly scan all hard drives, infected can not be repaired can not be deleted. In this way, although the infected EXE has not been repaired, the poison will not recur. You can run it and wait until killing can kill it.
Second method: Or save the following as jy.reg, then double-click to import Windows Registry Editor Version 5.00[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\internat.exe]"Debugger" ="internat.exe" This way, internat.exe will not run.
In addition, if you have been unfortunately infected, and Kabbah is not good or bad to the friend who deleted the file, please mourn … … If you feel that it is not safe after manual cleaning, then kill it. The only way to do this is to manually clean up the file ending in the exe and still be infected ……

Copyright © Windows knowledge All Rights Reserved