A few days ago, I returned to school to submit my papers. Many students got this number of virus on their computers. Kaba and Rising were always unable to kill them. Later, everyone searched for information and asked some experts through the Internet, and finally solved it. Now I will share my experience with you:
1. Delete the "Virus Component Release" program:
"%windows%\System32\" (window xp system directory is: "C:\WINDOWS\System32\" )
2. Delete the "driver that sends ARP spoofing package" (and "virus daemon"):
"%windows%\System32\drivers\" (window xp system directory is: "C:\WINDOWS\System32\drivers\" )
a. In Device Manager, click "View" -->"Show hidden devices"
b. In the device tree structure, open "Non-plug-play..."
c. Find “NetGroup Packet Filter Driver” or “NetGroup Packet Filter”. If not found, please refresh the device list first.
d. Right-click the "NetGroup Packet Filter Driver” or "NetGroup Packet Filter” menu and select "Uninstall"
e. Restart the windows system
f. Delete "%windows%\System32\drivers\" (window xp system directory is: "C:WINDOWS\System32\drivers\" )
3. Delete the controller of the "command driver to send ARP spoof package"
"%windows%\System32\" (window xp system directory is: "C:WINDOWS\System32\" )
4. Delete the following "Virus Fake Driver" registry service key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Npf
Finally, just restart the computer~
1. Delete the "Virus Component Release" program:
"%windows%\System32\" (window xp system directory is: "C:\WINDOWS\System32\" )
2. Delete the "driver that sends ARP spoofing package" (and "virus daemon"):
"%windows%\System32\drivers\" (window xp system directory is: "C:\WINDOWS\System32\drivers\" )
a. In Device Manager, click "View" -->"Show hidden devices"
b. In the device tree structure, open "Non-plug-play..."
c. Find “NetGroup Packet Filter Driver” or “NetGroup Packet Filter”. If not found, please refresh the device list first.
d. Right-click the "NetGroup Packet Filter Driver” or "NetGroup Packet Filter” menu and select "Uninstall"
e. Restart the windows system
f. Delete "%windows%\System32\drivers\" (window xp system directory is: "C:WINDOWS\System32\drivers\" )
3. Delete the controller of the "command driver to send ARP spoof package"
"%windows%\System32\" (window xp system directory is: "C:WINDOWS\System32\" )
4. Delete the following "Virus Fake Driver" registry service key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Npf
Finally, just restart the computer~