星期五, 5月 07, 2004

VPC got virused !! the mutation of SASSER - AVSERVE2.EXE

Symdrom :
1. the CPU loading is high.
2.routing table have manay entrys... because I didn't add the 244 router.

Open Task Manger, found that AVSVER2.exe occupy 52% usage.

Clean:

1.delete it on task manager.
2.find XXXX_up.exe in /WINNT/System32/, delete it.
3.find avsver2.exe in /WINNT, delete it.
4.use Regedit, find avserve2.exe (in HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/CurrentVersion/Run), delete it.
5.

沒有留言:

網誌存檔