step by step

來源: 2012-03-11 10:44:49 [博客] [舊帖] [給我悄悄話] 本文已被閱讀:

(1) Stop Security Shield 2012 process, press CTRL+ALT+DELETE to open the Windows Task Manager.  Then click on the “Processes” tab, search for the virus, right-click it and select “End Process” key.

(2) Delete the associated files of Security Shield 2012:

%Documents and Settings%\[UserName]\Local Settings\Application Data\[random].exe

(3) Remove the related registry entries of Security Shield 2012: Guides to open registry editor, click “Start” menu, hit “Run”, then type “regedit” click “OK”, while the Registry Editor is open, search and delete the following registry entries listed below:

HKEY_CURRENT_USER\Software\[random]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = 1
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = " "
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" =127.0.0.1:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = .exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"

(4) Scan your computer by "Malwarebyte"