cause
Oh, the weather is hot these days. Xue Ying, I have a variety of eating ... The result is sent to the hospital infusion. As a horrified, I have no infusion in 6 years ... 5555 ~~~~~~~ It's so good. ^ _ ^
Open the computer one home, 咦? No, how is the computer weird today? Open Super Rabbit Magic Settings (Software Management Software), find the automatic running program item, found more! gosh! Chinese virus! Scan with Jinshan drug tyrants (not Jinshan's fault, I believe you can't find it with Rising, Jiangming, etc. because anti-virus software is not universal, but it is not possible)! Under my investigation, I found that my sister chatted with a computer ................. I told her many times, don't run the procedures sent by strangers! It's really a guy who is not enough to defeat!
However, the virus is also unlucky, breaking my learning information security. This is called "hiding ghosts to hide into the city" ^ _ ^
Pursue
I said before, using the "rabbit" to check the startup item, I found more "c: /winnt/system32/shell.exe", of course, the launch item will be deleted, so the virus will not be turned on next time. run.
Then open the "Task Manager" comes with the system to see the process (if you are win98, you have to find a software to view the process). Know how to call up the mission manager? Just press CTRL Alt Del, then select "Task Manager" is. Well, I saw it, I have a shell.exe process, what should I do? In its point, right click, select "End Process". This stops the virus.
Now you can delete the virus. Don't panic! There is another thing to do.
Here is something else. The current virus will find ways to make themselves, and some use a technology called "file association". What is the file association? For example, if you want to open a text file (the suffix is txt), the system is opened with Notepad.exe. But if the virus makes a hand feet, convert the open program to itself, then you open a text file, the virus will run.
Now I know what to do, yes, it is to view the file association! What software is used? I didn't find better, I had to use "PC Safety Partner". This can only detect recovery EXE and TXT file associations. However, it is generally related to these two. It has also encountered the associated REG (registry file) file. After deleting the virus, run the REG file will not find *. * (Which is the virus). This way to solve: Open "My Computer" in the toolbar Select "Tool" - "Folder Item" - File Type, and then the file type you can identify. Many is it? For example, if you want to recover the association of REG, press the "R" button to jump to the type of R, then find the REG, click "restore" to get it!
Now the virus has returned to the heavens, how to dispose, listen to the respect (of course, deleting).
ending
The virus I didn't delete it. I took it to it, I found that it was a hippocalypse of a pirate legend and winger game (I didn't play). Hey, do you know how to send it to the master? Of course, it is sent with the Monarch's mailbox. OK! Then it is equal to the mailbox to me. Thank you first! to sum up
Hello, sleep well! That is to say you! Listen, now I will sum up the experience!
Through the above text, you should know that killing viruses is not a difficult thing. As long as the principle is mastered, it is simple. Ok, I wrote the steps:
Delete from the start item - End Process - Check the association - delete innocent
Say something nonsense. If you want to ensure your computer's security, you must check the startup items and processes frequently, and also remember normal startup items and processes. And you have to know that anti-virus software can only find known viruses, which are not found for that new and unknown. The most difficult virus now uses "insertion thread" technology. Once the trick, it will be unlucky! So you pay attention!
Knife
2003-8-27
You have any opinions or questions, please follow the post ^ _ ^