15-05-2007, 11:20
|
|
|
חבר מתאריך: 03.09.06
הודעות: 3,486
|
|
אתה רוצה להגיד לי שעשיתה את כל זה?
זה לא הגיוני ,
http://www.symantec.com/security_response/writeup.jsp?docid=2006-032316-2221-99&tabid=3Important: If you are unable to start your Symantec antivirus product or the product reports that it cannot delete a detected file, you may need to stop the risk from running in order to remove it. To do this, run the scan in Safe mode. For instructions, read the document, How to start the computer in Safe Mode. Once you have restarted in Safe mode, run the scan again.
After the files are deleted, restart the computer in Normal mode and proceed with the next section.
Warning messages may be displayed when the computer is restarted, since the threat may not be fully removed at this point. You can ignore these messages and click OK. These messages will not appear when the computer is restarted after the removal instructions have been fully completed. The messages displayed may be similar to the following:
Title: [FILE PATH]
Message body: Windows cannot find [FILE NAME]. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.
4. To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions refer to the document: How to make a backup of the Windows registry.
- Click Start > Run.
- Type regedit
- Click OK.
Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tooltool, and then continue with the removal.
to resolve this problem. Download and run this - Navigate to the subkey:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run
- In the right pane, delete the values:
"drvsyskit" = "%Userprofiles%\Application Data\hidires\hidr.exe"
"german.exe" = "%System%\wintems.exe"
- Navigate to the subkey:
HKEY_CURRENT_USER\Software\DateTime4
- In the right pane, restore the original values, if required:
"port" = "0x5B7E"
"uid" = "[RANDOM]"
"wdrn" = "0x00000001"
- Exit the Registry Editor.
נערך לאחרונה ע"י pbc בתאריך 15-05-2007 בשעה 11:22.
|