Killing the annoying QQ "edge" virus!

zhaozj2021-02-16  48

Hello, ××× Today I got online books online, the book is called "edge", the name is good, and the name of the author of the book is very clever, just like your QQ screen name, also called "×] × ". Will it be what you wrote? Quite talented, huh, huh! Write a lot, download it! Click on this address to download this book: http://www.book.cn.gg/

If you have seen the above, and have downloaded the so-called "book", but also opened it. In the absence of any protection measures, I believe that you have already never had a wickry QQ virus. Open the Task Manager from the right-click hit in the taskbar (once only once), you can see two (or more) Taskmgr.exe (not case sensitive). And, when you open a friend's Send Message Dialog, the above has already sent it to your friend, you have no time to remind him (her), maybe he (she) It has been trickled. Ok, let's kill this hateful virus.

First, close all QQ. Open Task Manager, find Taskmgr.exe that CPU usage often changes, is currently a normal manager. End all other processes that have the same name as it. At this point, don't open any text file (because the virus is associated with the text file).

Then, click a folder, select "Folder Item" on the tool on the menu, click to view, in the Advanced Settings, "File and Folders" hide protected operating system files (recommended "This option is removed, and" display all files and folders ", click OK. Next, under the system disc, remove the following files: (Note: The following file is NOTEP "E" D.exe, not NOTEP "a" D.exe, don't delete the wrong!)% Systemroot% / system32 / noteped.exe (18K)% systemroot% / system / noteped.exe (18k)% systemroot% / system / taskmgr.exe (18k)% systemroot% / system / windll.dll (1K, this file content is "alljapanesarepigs", do not delete It doesn't matter, hehe!)% Systemroot% / noteped.exe (18k) There is also the book you downloaded book.exe, you must also delete it, to prevent it again!

Finally, the default key value of the registry primary key HKEY_LOCAL_MACHINE / SOFTWARE / COMMAND / TXTFILE / SHELL / OPEN / COMMAND will be changed to "% systemroot% / system32 / notepad.exe% 1". (Windows2000 / XP automatically modifies this key value when deleting files last step)

OK, this three steps are finished, the dead virus disappeared, the rest is let us despise http://www.book.cn.gg/ The author of the site!

转载请注明原文地址:https://www.9cbs.com/read-25965.html

New Post(0)