Page 257 - Tự Khắc Phục Máy Tính Khi Bị Vi Rút Tấn Công
P. 257
HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Policies\System\"DisableCMD" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\
CuưentVersion\Run\"Microsoft Word" =
"%System%\hostdll.exe"
5. Tim kiếm và xóa giá trị sau:
HKEY_LOCAL_MACHINEVSOFTWARE\Classes\exefile
\"(default)" = "Eile Eolder"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefiIe
\"TileInfo" = "propiDocComments"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile
VlníoTip" = "prop;DocComments"
HKEY_LOCAL_MACHINEvSOFrWARE\ClassesVegfile
\shelI\open\command\"(default)" = "cmd.exe /c del "%1""
HKEY_LOCAL_MACHINE\SOFTWAR^icrosoft\Win
dows NT\CurrentVersion\"RegisteredOrganization" =
"your System is mine"
HKEY_LOCAL_MACHINE^OFTWARE\Microsoft\Win
dows NT\CurrentVersion\"RegisteredOwner" = "your
System is mine"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Win
dows NT\CurrentVersion\Winlogon\"SheH" =
"Explorer.exe, C:\WINDOWS\system32\taskfile.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Explorer\Advanced\"Hidden" = "2"
HKEY_CURRENT_ƯSER\Software\Microsoft\Windows\
CurrentVersion\Explorer\Advanced\"HideFileExt" = 1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\ExploreiNAdvancec^"ShowSuperHidden" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\ExploreĩNAdvancecfv"ClassicViewState" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurT
entVersion\Policies\ExplOTei\"NoDriveTypeAutoRun" = "5B"
6. Thoát khỏi Registry.
257