Teach you how to clean up the rose virus in the USB flash drive
The rose virus, one of the three major viruses of a USB flash drive, is believed to be a frequent visitor to many of its friends ". Rosevirus (rose.exe) is a benign virus consisting of two file carriers, namely ROSE. EXE and AUTOEXEC. BAT, double-click the storage device to read autorun. inf information text vulnerability, which occupies a large amount of cpu resources in the system, may cause some operating system crashes. As for how to clean up the rose virus, many online experts have come up with a wonderful manual cleaning method. Let's take a look at it.
A. rose.exe virus is mainly manifested in
1. occupying a large amount of cpu resources in the system.
2. Create the rose.exe and autorun. inf2 files in each partition and open "my computer". The default setting of each hard drive letter is changed to "automatic playback" instead of "open ". When you double-click the drive letter, the system automatically runs, but the partition cannot be opened.
3. Most of them are spread through storage devices such as USB flash drives and mobile hard drives. Network hazards are still being discovered.
4. Some computer operating systems may crash, which may occur after self-check and restart the system repeatedly. If you carefully check the file, you will find that the system lacks an NTDETECT. COM file.
Ii. Solution
1. If the system crashes, the system will be restarted after self-check and cannot enter the system. You can copy the same version of NTDETECT from another computer through a USB flash disk or a floppy disk. COM to the local system disk.
2. After entering the system, the task manager is called and all processes named "rose.exe" are removed from the page (we recommend that you repeat this operation in subsequent operations to ensure that virus files do not recur ).
3rd, enter the “regedit.exe (xpxpxp ----at start-up and run the reg (.
4. In my computer-tools-Folder Options-View-show all files and folders and remove the "Hide protected system files" check box.
5. Click the right-click button on each disc to open it. You cannot double-click it to delete all the rose.exe and autorun. inf files.
6. Check whether the rose.exe file exists in c: windowssystem32. if it exists, delete it directly.
Appendix: Teach you to manually disinfect viruses without any tools (remember to right-click the drive letter in anti-virus and do not double-click the drive letter. Otherwise, you will be able to discard all your efforts !)
1. In my computer-tools-Folder Options-View-show all files and folders, remove the "hidden protected system files" check box and try again.
Click Start, right-click my computer, and then click Properties ".
Click the System Restore tab. Select "Disable System Restore" or "Disable System Restore on All Drives "..
(Normally, rose.exe is hidden in the System Restoration folder of each drive letter, which is also the most basic reason why anti-virus software cannot be killed)
2. Enter the security mode (remember to finish the above operations first! In security mode, the system cannot be restored !)
3. Generate a. bat batch file. The content of the batch file is as follows:
Taskkill/f/IM rose.exe
Del/F/A: s c: \ AUTORUN. INF
Del/F/A: s c: \ Rose.exe
Del/F/A: s d: \ AUTORUN. INF
Del/F/A: s d: \ Rose.exe
Del/F/A: s e: \ AUTORUN. INF
Del/F/A: s e: \ Rose.exe
Del/F/A: s f: \ AUTORUN. INF
Del/F/A: s f: \ Rose.exe
Del/F/A: s g: \ AUTORUN. INF
Del/F/A: s g: \ Rose.exe
Del/F/A: s h: \ AUTORUN. INF
Del/F/A: s h: \ Rose.exe
Del/F/A: s I: \ AUTORUN. INF
Del/F/A: s I: \ Rose.exe
Del/F/A: s j: \ AUTORUN. INF
Del/F/A: s j: \ Rose.exe
Del/F/A: s k: \ AUTORUN. INF
Del/F/A: s k: \ Rose.exe
Del/F/A: s l: \ AUTORUN. INF
Del/F/A: s l: \ Rose.exe
Del/F/A: s m: \ AUTORUN. INF
Del/F/A: s m: \ Rose.exe
Del/F/A: s n: \ AUTORUN. INF
Del/F/A: s n: \ Rose.exe
Del/F/A: s o: \ AUTORUN. INF
Del/F/A: s o: \ Rose.exe
Del/F/A: s c: \ system32 \ rose.exe
Del/F/A: s c: \ system. sys
Del/F/A: s c: \ windows \ system32 \ run. reg
Del/F/A: s c: \ windows \ system32 \ systemdate. ini
Del/F/A: s d: \ systemdate. ini
Del/F/A: s d: \ systemfile.com
Generate a. reg registry file with the following content:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]
"Dll" =-
Run the above two files
In step 4, open the registration table by entering regedit.exe at start-up and run it to check for all the corresponding keys. Then, delete the entire shell Sub-key. (Remember to delete it only by shell, and then press F3 after deleting one. Until the registry search is complete)
5. Right-click each drive letter and choose "open". (remember not to double-click it. Otherwise, you will get rid of it.) check again!
Delete the rose.exeand autorun.inffiles in all the inventory directories and any suspicious files related to the rose.exe and autorun. inf files! Including the hidden System Recovery folder! All done after restarting!
Since then, no matter whether you are a cainiao or a master, you no longer have to worry about the rose virus in the USB flash drive. It seems like a long tutorial. In fact, the operation is very simple. Learn this professional manual cleaning technique, you will no longer need anti-virus tools. Learn from your favorite friends.