Releasing files
Copy Code code as follows:
%program files%\internet Explorer\plugins\autorun.inf
%program files%\internet Explorer\plugins\pagefile.pif
%program files%\internet Explorer\plugins\winnice.dll
X:\Autorun.inf (x is not a system disk other letter)
X:\pagefile.pif
Add registry information such as Startup items
Copy Code code as follows:
Hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] { 06a68ad9-ff66-3e63-936b-b693e62f6236}
Point to%program files%\internet Explorer\plugins\winnice.dll
Characteristics:
1, the left mouse button Double-click WinNice.dll folder, that is, run the virus again
2, the left mouse button Double-click the other letter, that is, run the virus again, so as to enter a dead cycle
3, WinNice.dll Insert system in other processes
Resolution process:
1, the right mouse button Open WinNice.dll folder, delete Autorun.inf, pagefile.pif
2, the right mouse button to open other drive letter, delete Autorun.inf, pagefile.pif
3. Use unlocker to unlock WinNice.dll
4, open Registry Editor, to {06a68ad9-ff66-3e63-936b-b693e62f6236} to find, and delete all relevant information
5, the article refers to the tools in this site dedicated network USB u disk has a download and use instructions
Ps:
1, the above information from the Help mail, not search for other information, may not be very accurate or incomplete
2, if you do not understand the Autorun.inf configuration file, we recommend that the left mouse button double-click for automatic playback for a simple understanding