first, how to find the virus
This virus has very obvious external characteristics, but it is often easy to ignore. It's easy to ignore because it doesn't slow down the computer, so many people don't notice it. However, if we double-click on the U disk, not open in the current window, but in a new window open, then it may be poisoned. At this point, you can right-click the letter in My computer, look at the top of the command is what, if it is "Auto", rather than the normal "open", then the possibility of poisoning further increase; But to confirm the poisoning, we need to enter E:autorun.inf in the address bar (e disk should be replaced with the actual letter , if the file you are opening in the open file is a file like Sxs.xls.exe, then you must be poisoned.
Second, how to remove the virus
After discovering the virus, don't worry, there are many ways to remove it. Here are some more simple ways to introduce.
1, manual removal
Because the virus works by using automatic playback of autorun.inf files, we can delete them manually.
Open the Folder Options window, switch to the View tab, cancel the Hide protected operating system files item, and then set Show All files and folders. This allows us to view the Autorun.inf file at the root of the disk, open it, and view the file following the open line, which normally should be sxs.xls.exe, but some variants are other file names, such as Tel.xls.exe, Fun.xls.exe and so on.
First delete the file that is followed by the open line, and then delete the Autorun.inf file. In general, as long as there is a single disk infection, the other partitions will also be infected, so you want to do the same for all partitions.
It should be noted that manual removal is only applicable to some objects. If you have a backup file for the system, then you can restore the backup file, the recovery of the successful C disk is safe, and then in the Explorer other disk of the above files deleted, so that is more thorough.
2, anti-virus software removal
In fact, if you install anti-virus software, as long as the virus to upgrade to the latest version, the general can be killed. In addition, rising also provided the orange August kill tools, we do not try.
But many users have reported that the disk could not be opened after using antivirus software cleanup. This is because the antivirus software only clears the file followed by the open line, and cannot clear the Autorun.inf file. When we double-click the partition, the file that is listed in the open row of the Autorun.inf file is automatically run, and the file is deleted and there is a natural error.
So at this point everyone needs to use the manual removal method described above to remove the Autorun.inf file.
Tips: Use the above method to remove the need to restart the computer before it can take effect.
Third, how to prevent
Since the U disk is very popular now, when our U disk on the poisoned machine used outdated, it will be infected. The infected USB disk can be used on other machines, and it will repeat the infection. It seems that the U disk is the biggest victim, so for users how to avoid the U disk and infected with the virus?
In fact, it is very simple, through the previous introduction we have seen that the operation of the virus is mainly by double-clicking the trigger Autorun.inf file to complete. If we do not double-click, but use the right keystroke, select the "Open" or "Explorer" command to view the contents of the U disk, so that the Autorun.inf file can not run, naturally will not infect the virus.