"Panda burning incense" after another powerful virus removal method

  
                


These days, due to work needs, the anti-virus software was uninstalled. I didn't expect the tragedy to happen. In less than two days, my computer had a virus named Trojan-Dropper.Win32.Agent.bct. The role of the virus is to be able to automatically infect all the disks, similar to the rose virus youdian.

I didn't realize that I had a virus, until the work was done, I installed the 360, and then I cheated a Kabbah serial number, installed the KAV6 upgrade, restarted … …

Next, my machine, no, it's Kabbah, it's like screaming …… It's not a bark, it's a thousand horses calling! It's quite spectacular! I am dumbfounded. ……

So much? It’s only two days. Then look at it again, is it a Trojan?! Nothing …… just set it up and find that the virus does not ask for direct cleaning. Waiting for me to come back later and see the harvest ……

It’s really overcharged! —— I’m topping your lungs! Kabbah is finding out the virus, virus-infected File, Kabbah is deleted together!! E disk and F disk two disk nearly 25G information, software ah … …

As long as the exe end … … all give cards! I panicked, hurry to go online for help, found that there is no special kill! Currently are manually deleted … …

So find a way to find them, put it on everyone to prevent, take me as a ring!! Don't think that your machine can be streaking on the internet!! Always wear clothes … … recommend Kabbah or NOD32.


The first method: Generate and run _.de in the system root directory, generate _.de.bat, suicide to generate x:\\windows\\system\\internat.exe (if previously If there is a directory with the same name, rename the folder to internat.exe.tmp. Generate autorun.inf and setup.exe on each disk. Run the command cmd.exe /c dir disk other than the system disk:\\*.exe /s /b >>C:\\WINDOWS\\win.log Infects EXE file according to the file in win.log and increases 26890 bytes after infection


Killing method:

1, use the command manager to end the process of intern.exe;

2, delete X:\\windows\\system\\internat.exe;

3, use the right button to enter each disk, delete The following autorun.inf and setup.exe;

4, create a folder named _.de in the root directory of the system;

5, thoroughly scan all hard drives with anti-virus software, It can be deleted without being infected. In this way, although the infected EXE has not been repaired, the poison will not recur. You can run it and wait until killing can kill it.


The second method: either save the following as jy.reg, and then double-click to import Windows Registry Editor Version 5.00[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options \\internat.exe]"Debugger"="internat.exe" This way, internat.exe will not run.

In addition, if you have been unfortunately infected, and Kabbah is not good or bad to the friend who deleted the file, please mourn … … If you feel that it is not safe after manual cleaning, then kill it. The only way to do this is to manually clean up the file ending in the exe and still be infected ……



Copyright © Windows knowledge All Rights Reserved