Poisoning symptoms:
1. autorun. inf and corresponding virus files under the drive letter of each disk are usually transmitted through mobile storage. Double-click or right-click opening will be poisoned,
2. anti-virus software and system maintenance tools cannot be opened. They are hijacked, including Kabbah, coffee, rising, Sreng, autoruns, and ice blade,
3. If all the anti-virus fields appear on the IE web page, they will be immediately closed.
4. the folder option shows that all files and folders cannot be used. Originally, WinRAR can be used to view hidden local files. The window will be closed immediately as long as virus files are browsed.
Solution
1. Delete autorun. inf and virus files under the root directory of the disk.
@ You can use icesword to change the software name to a mess. You just need to find the corresponding file and delete it as long as it is not turned off and cannot run,
@ I can't change the name even if I use iceword. Later I switched to darkspy instead of rename it. I directly put the autorun. inf in the partition and a batch xxxxx.exe "(the name is messy and consists of digital subtitles)
2. Restore anti-virus software
Anti-virus software cannot be started mainly because
HKLM/software/Microsoft/Windows NT/CurrentVersion/Image File Execution
This registry key is hijacked.
Switch to the Registry Editor in the ice edge window, browse HKEY_LOCAL_MACHINE/software/Microsoft/Windows NT/CurrentVersion/Image File Execution options, and view the corresponding program names in the subregistry keys one by one, delete incorrect data items.
Other solutions:
This method has not been tried. It is possible
First, click "run" in the Start Menu"
Bytes
Enter "gpedit. msc" to open the Group Policy console.
Select "Computer Configuration"
Bytes
Click "manage template"
Bytes
Click "system"
Select "Disable automatic playback" in the border on the right"
Change "Not Configured" in the "Disable automatic playback" attribute to "enabled"
Bytes
Turn off auto play default CD-ROM drive switch to all drives"
Do not forget to click "OK" after the operation"
Other solutions:
Go to command line cmd
Attrib autorun. inf-s-h-R
Del autorun. inf