China DOS Union

-- Unite DOS · Advance DOS · Grow DOS --

Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum
DOS stands for freedom, openness and progress. Let us work hard, learn from the openness and GNU spirit of FreeDOS and Linux, and together build and grow a free GNU GPL world!

中国DOS联盟论坛
The time now is 2026-08-26 19:41
中国DOS联盟论坛 » 其它操作系统综合讨论区 » Image hijacking virus?? View 37,628 Replies 5
Original Poster Posted 2009-06-10 07:11 ·  中国 广东 东莞 电信
中级用户
★★
Credits 461
Posts 243
Joined 2007-10-14 16:56
18-year member
UID 99730
Gender Male
Status Offline


Is this image hijacking virus?? How to clear it?
Floor 2 Posted 2009-06-10 07:16 ·  中国 安徽 黄山 电信
新手上路
Credits 9
Posts 6
Joined 2009-06-07 06:41
17-year member
UID 146880
Gender Male
Status Offline
First, close the process. Then delete the relevant content in the registry. Before deleting, you can find the virus file and delete it. If not, borrow a PE disk and delete the virus file under the PE system.
Floor 3 Posted 2009-06-10 09:00 ·  中国 江苏 无锡 电信
中级用户
★★
Credits 487
Posts 212
Joined 2007-04-01 08:22
19-year member
UID 83597
Gender Male
Status Offline
Hehe, the owner is overworried. This is a normal system registry item.
If there is a virus problem, you can leave a message on my blog,
or send it to the Anti-Virus Alliance WWW.DU110.COM
or Jianmeng Forum http://bbs.janmeng.com/
You can also send it to Animal Home http://bbs.kingzoo.com/
I am a technician there and can help deal with various virus problems.

[ Last edited by luckboy45 on 2009-6-10 at 09:01 ]
Floor 4 Posted 2009-06-10 09:41 ·  中国 广东 潮州 电信
初级用户
Credits 41
Posts 37
Joined 2009-01-09 20:01
17-year member
UID 136255
Gender Male
From 四川南充
Status Offline
Dude, registering for Jianmeng requires an invitation code. Can you give me one first...
echo @echo off>TEST.bat
Floor 5 Posted 2009-06-10 20:44 ·  中国 吉林 延边朝鲜族自治州 延吉市 电信
银牌会员
★★★
正在学习中的菜鸟...
Credits 1,039
Posts 897
Joined 2009-03-01 15:34
17-year member
UID 140302
Gender Male
From 在地狱中仰望天堂
Status Offline
What you see

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path

is the system default, not a virus. Under

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

there are many such entries. In general, they are normal system hijacks
Floor 6 Posted 2009-06-21 11:32 ·  中国 湖南 常德 电信
银牌会员
★★★
Credits 1,384
Posts 709
Joined 2005-10-29 22:22
20-year member
UID 44271
Status Offline
This is normal...
If there are others, you need to pay attention...
Forum Jump: