[http://]macr.microfsot.com/Adm[REMOVED]. This will download a copy of Trojan.Anicmoo, which exploits the Microsoft Windows Cursor And Icon ANI Format Handling Remote Buffer Overflow Vulnerability (BID 23194) and downloads the worm body from [http://]a.2007ip.com/5949645[REMOVED].
如果想要獲得額外的資訊,和另一種關閉Windows Me的系統還原,你可以查閱微軟知識庫的文章:Antivirus Tools Cannot Clean Infected Files in the _Restore Folder (Article ID: Q263455).
2. 移除病毒加入host檔的entries。
a. 指到下列位置:
· Windows 95/98/Me:
%Windir%
· Windows NT/2000/XP:
%Windir%\System32\drivers\etc
Notes:
· The location of the hosts file may vary and some computers may not have this file. There may also be multiple copies of this file in different locations. If the file is not located in these folders, search your disk drives for the hosts file, and then complete the following steps for each instance found.
· %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).
b. 雙擊host檔。
c. 如果有必要,取消選取"Always use this program to open this program"這個選項
Title: [FILE PATH]
Message body: Windows cannot find [FILE NAME]. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.
5. 刪除新增到機碼的數值。
重要:Symantec強烈建議您更改機碼前先備份它。更改錯誤可能會造成資料遺失或檔案毀損。這裡只更改特定的機碼。可以參考以下文件:How to make a backup of the Windows registry.