1. Clear viruses in safe or pure DOS mode
When the computer infected with the virus, the vast majority of infected virus treatment can be completely eliminated in normal mode, here is the normal mode of accuracy should be true mode (Real Mode), here is a common point. It includes WINdows in normal mode and “MS-DOS Mode” or “Command Prompt” under normal mode in Windows. However, some viruses because of the use of more hidden and cunning means tend to attack anti-virus software or even delete the system of anti-virus software practices, for the vast majority of such viruses are designed to install, use, perform anti-virus treatment in safe mode. When clearing in Safe Mode or pure DOS, most of the viruses that are now popular, such as worms, Trojans and web code viruses, can be completely removed in safe mode, and it is not necessary to start antivirus with a floppy disk as before; Also, when your computer is infected, it’s even more important to remove the virus after installing anti-virus software (upgrading to the latest virus library) and in Safe Mode or pure DOS!
Second, with poison files in some mail files
Most of the anti-virus software can directly check these mail files are poisonous, for the mailbox with poison letters, can be based on the user’s settings anti-virus or delete the poison mail, but because of the composite file structure of such mailboxes, easy to appear anti-virus mailbox can still detect virus conditions, this is due to the absence of compressed mailbox space release reasons, you can try to select “tool” in Express Express? “Options”? “Maintenance”? “Clear now”? “Compression” to delete all offline content, also select and delete.
Three, with poison files in the Restore directory, .cpy file
This is the directory where the system restores the restored files, which will only be available on the Windows Me/XP/VISTA operating system, because the system is protected from this directory. In this case, you need to remove the System Restore feature, then delete the poisonous file, and even delete the entire directory.
Four, with poison files in. Rar, . Zip. cab and other compressed files
For the vast majority of anti-virus software, the function of killing and compressing files has been basically perfected, just for some special types of compressed files or password-protected compressed files may be directly cleared. To remove viruses from compressed files, it is recommended to remove them after decompression, or to detoxify compressed files with poison with the help of the function of the external anti-virus program of the compression tool software.
V. Residual code of the virus in the file
This is more common in this case with residual code with CIH, Funlove, macro viruses (including macro viruses in documents such as Word, Excel, Powerpoint, and Wordpro) and individual web viruses, usually virus name suffixes reported by anti-virus software for files with virus residue code are usually ends in, and are not common, such as W32/FunLove.app, W32. Funlove.int. In general, these residual code will not affect the normal operation of the program, will not be contagious, if the need for complete removal, according to the actual situation of each virus to remove. This can also be done with the relevant cleaning tools and the modification of the registry.
Six, share directory antivirus
Encounter local shared directory with poison files can not be cleared, usually other users in the local area network to read and write these files, anti-virus when the performance of the virus can not be directly removed from these virus files, if there is a virus in these directories in the write virus operation, as the shared directory to remove the virus operation, or continue to have files infected or constantly generate new virus files. In both cases, it is recommended to cancel the share, and then to completely kill the shared directory, when the sharing is restored, be careful not to open too high permissions, and add a password to the shared directory. When you kill a virus on a remote shared directory, including a mapper, you first want to make sure that the local computer’s operating system is clean, and that you also have the highest read and write rights for the shared directory. If the remote computer is infected with a virus, it is recommended to kill the virus directly on the remote computer. In particular, if you remove other viruses, it is recommended to cancel all local sharing and then perform antivirus operations. In the usual use, should also pay attention to the security of the shared directory, plus password, at the same time, not necessary, do not directly read the files in the remote shared directory, it is recommended to copy to the local check virus before operating.