Page 207 - Tự Khắc Phục Máy Tính Khi Bị Vi Rút Tấn Công
P. 207
HKEY_LOCAL_MACHINEVSOFTWARE\Microsoft\Win
dows NTXCurrentVersionMmage File Execution
Options\adam.exe\"Debugger" = "[PATH TO WORM
EXECUTABLE]"
HKEY_LOCAL_MACHINEsSOFTWARĐ\Microsoft\Win
dows NT\CurrentVersion\Image Eile Execution
Options\360tray.exe\"Debugger" = "[PATH TO WORM
EXECUTABLE]"
HKEY_LOCAL_MACHINE\SOFTWAREMVÍicrosoft\Win
dows NTXCuưentVersionMmage Eile Execution
Options\360Safe.exe\"Debugger" = "[PATHTO WORM
EXECUTABLE]"
HKEY_LOCAL_MACHINE\SOFTWAR^icrosoft\Win
dows NTXCurrentVersionXImage Eile Execution
Options\360rpt.exe\"Debugger" = "[PATH TO WORM
EXECUTABLE]"
5. Khôi phục lại các giá trị mặc định:
HKEY_LOCAL_MACHINE\SOFTWAREWIicrosoft\Win
dows\CuưentVersion\Explorer\Advanced\FoIder\Hidden\S
HOWALL\"CheckedValue" = "0"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Co
ntrol\SafeBoot\Minimal
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Co
ntrol\SafeBoot\Network
HKEY_LOCAL_MACHINESSYSTEM\CuưentControlSet\
Control\SafeBoot\Minimal
HKEY_LOCAL_MACHINE\SYSTEM\CuưentControlSet\
Control\SafeBoot\Network
6. Thoát khỏi Registry.
207