Page 257 - Tự Khắc Phục Máy Tính Khi Bị Vi Rút Tấn Công
P. 257

HKEY_CURRENT_USER\Software\Microsoft\Windows\
       CurrentVersion\Policies\System\"DisableCMD" = "1"
       HKEY_CURRENT_USER\Software\Microsoft\Windows\
       CuưentVersion\Run\"Microsoft Word" =
       "%System%\hostdll.exe"
    5. Tim kiếm và xóa giá trị sau:
       HKEY_LOCAL_MACHINEVSOFTWARE\Classes\exefile
       \"(default)" = "Eile Eolder"
       HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefiIe
       \"TileInfo" = "propiDocComments"
       HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile
       VlníoTip" = "prop;DocComments"
       HKEY_LOCAL_MACHINEvSOFrWARE\ClassesVegfile
       \shelI\open\command\"(default)" = "cmd.exe /c del "%1""
       HKEY_LOCAL_MACHINE\SOFTWAR^icrosoft\Win
       dows NT\CurrentVersion\"RegisteredOrganization" =
       "your System is mine"
       HKEY_LOCAL_MACHINE^OFTWARE\Microsoft\Win
       dows NT\CurrentVersion\"RegisteredOwner" = "your
       System is mine"
       HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Win
       dows NT\CurrentVersion\Winlogon\"SheH" =
       "Explorer.exe, C:\WINDOWS\system32\taskfile.exe"
       HKEY_CURRENT_USER\Software\Microsoft\Windows\
       CurrentVersion\Explorer\Advanced\"Hidden" = "2"
       HKEY_CURRENT_ƯSER\Software\Microsoft\Windows\
       CurrentVersion\Explorer\Advanced\"HideFileExt" =  1"
       HKEY_CURRENT_USER\Software\Microsoft\Windows\
       CurrentVersion\ExploreiNAdvancec^"ShowSuperHidden" = "0"
       HKEY_CURRENT_USER\Software\Microsoft\Windows\
       CurrentVersion\ExploreĩNAdvancecfv"ClassicViewState" = "0"
       HKEY_CURRENT_USER\Software\Microsoft\Windows\CurT
       entVersion\Policies\ExplOTei\"NoDriveTypeAutoRun" = "5B"
    6. Thoát khỏi Registry.


                                257
   252   253   254   255   256   257   258   259   260   261   262