End Infected Processes
Press Ctrl + Alt + Delete.
Click on "Task Manager."
Click on the "Processes" tab.
End the following processes. To end a process, simply right-click on it and select "End Process."
"svchost.exe"
"explorer.exe"
"services.exe"
Remove Infected Registry Keys
Click on the "Start" menu.
Click on "Run."
Type "regedit" (without the quotation marks) into the open box and click "OK." The Registry Editor window will open.
Find and delete the following registry keys from the left pane of the Registry Editor. To delete a registry key, simply right-click on it and select "Delete."
"HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices{random}Parameters"ServiceDll" = Path to worm"
"HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices{random}"ImagePath" = %SystemRoot%system32svchost.exe -k netsvcs"
"HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpipParameters
"TcpNumConnections" = dword:0---00FFFFFE"
Remove Infected DLL Files
Click on the "Start" menu.
Click on "Run."
Type "cmd" (without the quotation marks) into the open box and click "OK." This will open the Command Prompt window.
Type the following into the Command Prompt window. Be sure to press ENTER after every line.
"regsvr32 /u [Random].dll"
"regsvr32 /u Internet Explorer[Random].dll"
"regsvr32 /u Movie Maker[Random].dll"
Remove Infected Files
Click on the "Start" menu.
Click on "Search Files and Folders."
Search for and delete the following files. To delete a file, simply right-click on it and select "Delete."
7 jam yang lalu
0 Coments:
Posting Komentar
Trimakasih,
Telah berkunjung di riodarmala.blogspot.com
Jangan lupa tinggalkan comments.