Detailed introduction, analysis, and removal of ipv32.exe USB flash drive viruses
Symptoms of poisoning:
Release files
%Windows%%32.exe
% System % voice. cpl
% System % timedate. cpl
Release the root directory of each partition
X: autorun. inf
Autorun. inf content
[Autorun]
Opentracing evilday.exe
Shellexecuteappsevilday.exe
Shellopen (&o=command=evilday.exe
Shell = open (& O)
Shell2 = browse (& B)
Shell2command1_evilday.exe
Shell3 = Resource Manager (& X)
Shell3command1_evilday.exe
Modify the registry:
Create a startup entry for a virus
[HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun]
"NOTEPAD" = "%windows%32.exe"
Modify auto-Playback disable settings
[HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer]
"NoDriveTypeAutoRun" = dword: 0000005b
Disable "show all files and folders"
[Hkcusoftwaremicrosoftwindowscurrentversionpoliceradvancedfolderhiddenshowall]
"CheckedValue" = dword: 00000000
Disable Registry Editor"
[HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
"DisableRegistryTools" = dword: 00000001
Clear method:
1. End the process
%Windows%%32.exe
2. Delete Virus files
%Windows%%32.exe
% System % voice. cpl
% System % timedate. cpl
X: autorun. inf
3. Modify the return time to the System
4. restart the computer
Download SREng
Open sreng-system repair-windows shell/ie-select all-repair-
5. Delete the Registry created by the virus
[HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun]
"NOTEPAD"
[Hkcusoftwaremicrosoftwindowscurrentversionpoliceradvancedfolderhiddenshowall]
"CheckedValue"
6. Modify the registry and fix the disabled "automatic playback"
[HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer]
"NoDriveTypeAutoRun" = dword: 00000091
7. Delete the Image File Execution Options Image hijacking item
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsIceSword.exe]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsTwister.exe]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsSNATask.exe]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsSysWarn.exe] [HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution Optionssloemnit.exe]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsFilMsg.exe]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution Optionsgss.exe]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVStart. EXE]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsKWatch. EXE]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsRvaMon.exe]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution Optionsrva.exe]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsMPMain.exe]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsMPMon.exe]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsMPSVC.exe]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsMPSVC1.exe]
[HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsMPSVC2.exe]
Cleared!