ORF反垃圾邮件系统

邮件服务器-邮件系统-邮件技术论坛(BBS)

 找回密码
 会员注册
查看: 3572|回复: 0
打印 上一主题 下一主题

delete WORM_RANDEX.FB

[复制链接]
跳转到指定楼层
顶楼
发表于 2004-2-19 12:33:02 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
Terminating the Malware Program <br>
<br>
This procedure terminates the running malware process from memory. You will need the name(s) of the file(s) detected earlier. <br>
<br>
Open Windows Task Manager.<br>
On Windows 95/98/ME systems, press<br>
CTRL+ALT+DELETE<br>
On Windows NT/2000/XP systems, press<br>
CTRL+SHIFT+ESC, then click the Processes tab. <br>
In the list of running programs*, locate the malware file or files detected earlier. <br>
Select one of the detected files, then press either the End Task or the End Process button, depending on the version of Windows on your system. <br>
Do the same for all detected malware files in the list of running processes. <br>
To check if the malware process has been terminated, close Task Manager, and then open it again. <br>
Close Task Manager. <br>
*NOTE: On systems running Windows 95/98/ME, Task Manager may not show certain processes. You may use a third party process viewer to terminate the malware process. Otherwise, continue with the next procedure, noting additional instructions. <br>
<br>
Removing Autostart Entries from the Registry <br>
<br>
Removing autostart entries from the registry prevents the malware from executing during startup. <br>
<br>
To remove the malware autostart entries: <br>
<br>
Open Registry Editor. To do this, click Start>Run, type Regedit, then press Enter. <br>
In the left panel, double-click the following:<br>
HKEY_LOCAL_MACHINE>Software>Microsoft><br>
Windows>CurrentVersion>Run <br>
In the right panel, locate and delete the entry or entries:<br>
REMOVE ME = "asclt.exe" <br>
In the left panel, double-click the following:<br>
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows><br>
CurrentVersion>RunOnce <br>
In the right panel, locate and delete the entry or entries:<br>
REMOVE ME = "asclt.exe" <br>
In the left panel, double-click the following:<br>
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows><br>
CurrentVersion>RunServices <br>
In the right panel, locate and delete the entry or entries:<br>
REMOVE ME = "asclt.exe" <br>
In the left panel, double-click the following:<br>
HKEY_CURRENT_USER>Software>Microsoft>Windows><br>
CurrentVersion>Run <br>
In the right panel, locate and delete the entry or entries:<br>
REMOVE ME = "asclt.exe" <br>
In the left panel, double-click the following:<br>
HKEY_CURRENT_USER>Software>Microsoft>Windows><br>
CurrentVersion>Runonce <br>
In the right panel, locate and delete the entry or entries:<br>
REMOVE ME = "asclt.exe" <br>
Close Registry Editor.<br>
(by trend micro)<br>
<br>
in the end,<br>
delete the "asclt.exe" from the dic "winnt\system32\"<br>
<br>
it's ok<br>
(by xzlea)<br>
<br>
<br>
您需要登录后才可以回帖 登录 | 会员注册

本版积分规则

小黑屋|手机版|Archiver|邮件技术资讯网

GMT+8, 2024-11-20 07:15

Powered by Discuz! X3.2

© 2001-2016 Comsenz Inc.

本论坛为非盈利中立机构,所有言论属发表者个人意见,不代表本论坛立场。内容所涉及版权和法律相关事宜请参考各自所有者的条款。
如认定侵犯了您权利,请联系我们。本论坛原创内容请联系后再行转载并务必保留我站信息。此声明修改不另行通知,保留最终解释权。
*本论坛会员专属QQ群:邮件技术资讯网会员QQ群
*本论坛会员备用QQ群:邮件技术资讯网备用群

快速回复 返回顶部 返回列表