Step 1: when a computer with viruses enters the XP system, it will not be able to see the interface, and then use Alt + Ctrl + Del to enter the task manager. You will find that the CPU usage remains above 100%, and there are two EXPLORER. EXE process (one of which is a normal process and called by the system. If there is no difference, you can end both processes, and then "switch to-Application-new task-browse-select" C: quit. after the two are disabled, you can enter the operation interface, but the virus has not been cleaned up.
Step 2: Use anti-virus software to kill viruses. The two viruses are located in "C: WINDOWSsystem32" and the virus name is "Trojan. PSW. SBoy. a/B". Many anti-virus software cannot be eliminated.
Step 3: because the virus is still running after the restart and cannot enter the system, we can infer that the virus is probably in the startup Item. Repeat the first step. after entering the system, "Start-run-msconfig", remove the check boxes of these two names, and then select "exit without restarting".
Step 4: Choose "my computer"> "Tools"> "folder"> "View"> "unhide protected operating system files". In the displayed dialog box, press "yes". then, select "show all files and folders" to go to "C: windowssystem32316-delete wsctf.exe and EXPLORER in the folder. EXE files (if they cannot be deleted, you can change the suffix. Txt and then delete it)
Step 5: Start-run-regedit and press OK to open the registry. Go to the HKEY_CURRENT_USER SoftwareMicrosoft windowscurrentversionrundirectory, and delete the wsctf.exe and EXPLORER. EXE records on the right. Go to HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon. You can see the key value userinit, value: userinit.exe, EXPLORER. EXE, and double-click Userinit to delete the comma and EXPLORER. EXE in the middle.