Bad weather,Bad mood.
Sunday, March 18, 2007 by HongJunX
It has beening raining for nearly two days and I am at a bad mood these days.It takes me two days to recover my system.Two days of non-study made me feel so guilty.I totally underestimated this virus.I had reinstalled my OS,but this did not terminate all troubles.All the exe setup programs I backuped for a preserving use has been infected,and I did not realize this before.Out of question,this unfortunate newly installed system was infected again.I turned my help again to the Internet.By searching the Internet in Google,I find some key information.In order to be inmuned to this virus,I had to create some fake virus files with the same name with those the virus would create.This method is simple,and effective.For windows, no two files could have the same name in the same directory.It is rightly based on this mechanism .Consequently ,it prevent the virus process from creating virus files.The detailed step is that, after I terminating the virus processes using IceSword,I first created two files named autorun.inf and pagefile.pif in each root directory of each disk,then another two files name lsass.exe and csrss.exe in %system%system32\com directory.The world is peaceful now.But the final cleanup work is not that easy as I thought.So many exe files were infected,I could not tolerate to delete them one by one,also I am not sure which files were infected and which were not.So I turn to anti-virus soft wares.Actually I hated anti-virus softwares before,because they occupy too much system resources,slow the system down,and more importantly,it is useless to newest virus.It is always following the steps of virus,but couldn't make one's system inmuned.But this time,I have no other choice.I need it to disinfect my infected files.I downloaded a kaspersky from Internet,and scanned my computer.Not out of my surprise,this stupid software did not disinfect none of my files but delete those infected.So,after scanning,I uninstalled the kaspersky as soon as I can.And now,everything back to normal except some application software.
0 Comments:
Post a Comment