to change the "NoDriveTypeAutoRun" key value to: BD, 00.
If you want to restore the autorun function of the hard drive or optical drive, perform a reverse operation.
In fact, Autorun is not required in the root directory of most hard disks. INF file to run the program, so we can completely disable the autorun function of the hard disk, even if there is
Recently, AutoRun. the inf file enables all the hard disks of the other party to be fully shared or the Trojan. the Application of inf files in hacking technology is still rare, and there are not many related materials. Many people think this is mysterious. This article attempts to solve this problem for you, so that you can fully understand this not complex but extremely interesting technology.
1. Theoretical Basis:
Friends who often use CDs know tha
root directory, you must specify its path, for example, open = soft. bat, which indicates 1. BAT file.TIPS: if the file to be run is not com, EXE, or bat, it doesn't matter. We can compile a BAT file manually, add the path and file name of the file to be opened to bat.(2) custom disc iconsIn the autorun section, there is another interesting command line, which is the icon. Generally, the specified icon file can be in ICO and BMP formats, of course, i
DLL files containing ICON resources. If the EXE and DLL files contain multiple Icon files, you must specify the icon index number you want to use, note that the icon index number starts from 0, for example, "icon = icon. DLL, 1 ", it indicates the icon will be used. the second icon in the DLL file.Tip: the icon can be
One: Software download and installation
Users can download the software from the black and white network. After downloading the compressed package decompression, double-click the name "AutoFireWall.exe" executable file, pop-up main interface as shown:
Figure I
Second: Software use
Software includes monitoring information, firewall settings, and other modules.
Click "View Monitor Record", will pop up a notepad record.
Autorun virus Firewall
AUTORUN. The INF is one of the more common files used in our computer to allow you to run a specified file automatically when you double-click the disk. The computer Autorun.inf virus, what should do? WinXP system Autorun.inf How to delete it? The following small series for everyone to bring WinXP system delete the Autorun.inf folder method. Come and have a look!
Method/Step:
1, the folder is a stubborn folder, the use of the deletion function can
According to the author: in view of the full introduction of autorun on the Internet. there are not many articles about the inf function. I found an autorun article on the official Microsoft website's official website, called "inf. description of inf in English. This article is written by the translator and the author himself. (Thanks to the excellent articles provided by the author)
======= I am a separato
EndurerOriginal
2006-12-232Supplementary Revision2006-12-221Version
Yesterday afternoon, an error message box pops up after a friend's computer connected to the USB flash drive, prompting that disk A or something could not be found. After the USB flash drive is closed, it is called again. Let me help you.
Use WinRAR to open the USB flash drive and find the fileAutorun. infAndSss.exe, Which is generated immediately after deletion.
Download hijackthis and procview from http://endurer.ys168.com.
Ru
Trojan. DL. win32.autorun. yuz, Trojan. win32.inject. gh, Trojan. win32.agent. zsq, etc.
EndurerOriginal2007-10-231Version
Pe_xscan 07-08-30 by Purple endurer2007-10-22 13:13:44Windows XP Service Pack 2 (5.1.2600)Administrator user group
C:/Windows/system32/winlogon.exe * 604 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | Windows NT logon application | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803
, prohibited, disabled by default)32: Optical Drive Device (CDROM, disabled by default)64: virtual storage device (RAM, which is not recommended by default)128: other drives not specified (Reserved bits are recommended. disabled by default)3. The autorun. inf file is divided into three parts: [Autorun] [Autorun. Alpha] [deviceinstall].[
then decide what operations to perform. If you look at it carefully, you will find more content. After we shield the operation permission of this key value from everyone, the system will not be able to access the corresponding table, so only the open operation will be available.
The combination of the content mentioned in the two articles should completely solve the problems caused by automatic running and double-click drive letters!
Test, available.
Comments:Advantage:
Hbinject.exe, hbmhly. dll, sys07003.dll, zsqf. dll, ytfa. dll, ytfb. dll, ytfc. dll, etc.
Original endurerVersion 1st
Yesterday, a friend said that he opened a flash file on the Internet. The Flash Player encountered an error and
Most common USB flash drives are immune to the registry, and directories with special file names are generated on the USB flash drives. Provides an alternative dynamic immune method.
The specific memory string in the Shell32.dll module of the Process Explorer can achieve the dynamic immunity automatically executed by the USB flash drive.
Shell32.dll version: 6.0.2800.1873
Imagebase: 7CD00000
. Text: 7CD8A16
Release files
Copy codeThe Code is as follows: % Program Files % \ Internet Explorer \ PLUGINS \ Autorun. inf
% Program Files % \ Internet Explorer \ PLUGINS \ pagefile. pif
% Program Files % \ Internet Explorer \ PLUGINS \ WinNice. dll
X: \ Autorun. inf (X is a non-system disk with other drive letters)
X: \ pagefile. pif
Add registry information, such as a
Situation
All the keys on the right run, and the 8-bit xxxxxx.exe and autorun. inf files appear under each disk.
Virus attacks such as viruses and Trojans are disabled on the Internet, and nod32 and other antivirus methods cannot be enabled.
Software
You cannot view hidden files. solution:
Method 1: Modify the Registry File (Save the following file in OK. reg) and run it.
Copy codeThe Code is as follows: Windows Registry Editor Version 5.00
[HKEY_LOC
The Autorun virus is hard to deal.
Let's take a look.
The USB flash drive uses autorun to spread viruses. for the help of the inf file, the virus first copies itself to the USB flash drive, and then creates an autorun. inf. When you double-click the USB flash drive. inf settings to run the virus in the USB flash drive, as long as we can block
The first is autorun. inf.The content of the common virus Autorun. inf file is[Autorun]Open).recyclerrecyclerautorun.exeShell1 = OpenShell1commandcmd.recyclerrecyclerautorun.exeShell2 = BrowserShell2commandcmd.recyclerrecyclerautorun.exe
Shellexecuteapps.recyclerrecyclerautorun.exeThe effect is that when the disk is opened, the file "recyclerrecyclerautorun.exe"
Worker script calls the process,Hazard: it makes people look uncomfortable! There are no other dangers. It is estimated that the prank guy wrote it.Then the Internet found a solution, the URL is as follows http://hi.baidu.com/robertcome/blog/item/0d0ab112a9c7e3cec3fd7831.htmPost firstVirus Autorun. vbs detection and removal methodQ: Recently, there was a strange phenomenon on the machine. After "my computer" is opened, no matter which disk icon is dou
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.