Release files
Copy codeThe Code is as follows: % Program Files % \ Internet Explorer \ PLUGINS \ Autorun. inf
% Program Files % \ Internet Explorer \ PLUGINS \ pagefile. pif
% Program Files % \ Internet Explorer \ PLUGINS \ WinNice. dll
X: \ Autorun. inf (X is a non-system disk with other drive letters)
X: \ pagefile. pif
Add registry information, such as a startup ItemCopy codeThe Code is as follows: HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ ShellExecuteHooks] {06A68AD9-FF66-3E63-936B-B693E62F6236}
Point to % Program Files % \ Internet Explorer \ PLUGINS \ WinNice. dll
Features:
1. Double-click the WinNice. dll folder to run the virus again.
2. Double-click another drive letter with the left mouse to run the virus again to enter an endless loop.
3. Insert WinNice. dll into other processes of the system.
Solution Process:
1. Right-click the WinNice. dll folder and delete Autorun. inf and pagefile. pif.
2. Right-click another drive letter and delete Autorun. inf and pagefile. pif.
3. Use Unlocker to unlock and delete WinNice. dll
4. Open Registry Editor, search for {06A68AD9-FF66-3E63-936B-B693E62F6236}, and delete all relevant information.
5. The tools involved in this article are downloaded and used in the dedicated network USB flash drive on this site.
PS:
1. The above information is obtained from the help email. Other information is not found, which may be inaccurate or incomplete.
2. If you do not know about the Autorun. inf configuration file, we recommend that you double-click the left mouse button to perform automatic playback.