Page 174 - Tự Khắc Phục Máy Tính Khi Bị Vi Rút Tấn Công
P. 174
"Messenger"
HKEY_LOCAL_MACHINEVSYSrrEM\CuưentControlSet\
Enum\Root\LEGACY_MESSENGER\OOOƠ\"Legacy" - "1"
HKEY_LOCAL_MACHINE\SYSTEM\CuưentControlSet\
Enum\Root\LEGACY_MESSENGER\0000\"ConfigFlags"
= " 0 "
HKEY_LOCAL_MACHINE\SYSTEM\CuưentControlSet\
Enum\Root\LEGACY_MESSENGER\0000\"Class" =
"LegacyDriver"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Enum\Root\LEGACY_MESSENGER\0000\"ClassGUID"
= "{8ECC055D-047E-11D1 A537-0000E8753ED1}"
HKEY_LOCAL_MACHINE\SYSrEM\CurrentControlSet\
Enum\Root\LEGACY_MESSENGER\0000\"DeviceDesc"
= "Messenger"
HKEY_LOCAL_MACHINĐ6YSTEM\CuưentControlSet\
Enum\Root\LEGACY_MESSENGER\"NextInstance" = 'T '
HKEY_LOCAL_MACHINE\SYSTEM\CuưentControlSet\
Services\Messenger\Enum\"0" =
"Root\LEGACY_MESSENGER\0000"
HKEY_LOCAL_MACHINE\SYSTEM\CuưentControlSet\
Services\Messenger\Enum\"Count" = "1"
HKEY_LOCAL_MACHINEVSYSTEM\CurrentControlSet\
Services\Messenger\Enum\"NextInstance" = " 1”
5. Khôi phục các giá trị mặc định:
HKEY_LOCAL_MACHINE\SYSrrEM\ControlSet001\Ser
vices\Messenger\"Type" = "110"
HKEY_LOCAL_MACHINE\SYSrrEM\ControlSet001\Ser
vices\Messenger\"Start" = "2"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001'^r
vices\Messenger\"ImagePath" =
"C:\WINDOW^system32\[ORIGINALLY EXECUTED
EILE NAME].exe -k netsvcs"
HKEY_LOCAL_MACHINBSYSTEM\CuưentControlSet\
174