The first is autorun. inf.The content of the common virus Autorun. inf file is[Autorun]Open).recyclerrecyclerautorun.exeShell1 = OpenShell1commandcmd.recyclerrecyclerautorun.exeShell2 = BrowserShell2commandcmd.recyclerrecyclerautorun.exe
Shellexecuteapps.recyclerrecyclerautorun.exeThe effect is that when the disk is op
I. Preface
I have studied anti-virus in article 006th: Using WinRAR and autorun. autorun. as the final answer to this question, I plan to discuss how to use MFC to develop a simple immune program. Although we should be no longer suffering from autorun. inf, many of the ideas are still worth exploring. It should be emph
The virus is improving, and the anti-virus method is also improving.
The original virus spread through a USB flash drive usually writes an autorun. inf file under the root directory of the USB flash drive, so that users can accidentally double-click the USB flash drive to directly run the
As for the previous autorun. inf immunization, it is completely useless,For example:
@ Echo offCD/d h:MD autorun. infMD autorun. inf/test ../Attrib autorun. inf + S + H + REcho y | CALCs autorun. inf/d everyone
If the virus is d
From: Network
Autorun. inf-type viruses and Trojans are believed to have been marked in the standard form. The Downloader-type Trojans are more obvious. The following ZZ Methods hope to be useful to you. You can test them by yourself.
Reference
Iamcj original
In the previous make a anti-Autorun batch, we discussed how to disable the Shell Hardware Detection Service to prevent the automatic operation of the
Trojan. DL. win32.autorun. yuz, Trojan. win32.inject. gh, Trojan. win32.agent. zsq, etc.
EndurerOriginal2007-10-231Version
Pe_xscan 07-08-30 by Purple endurer2007-10-22 13:13:44Windows XP Service Pack 2 (5.1.2600)Administrator user group
C:/Windows/system32/winlogon.exe * 604 | MICROSOFT (r) Windows (r) Operating System | 5.1.2600.2180 | Windows NT logon application | (c) Microsoft Corporation. all rights reserved. | 5.1.2600.2180 (xpsp_sp2_rtm.040803
How autorun. inf is immune
We will not discuss how the autorun. inf virus is infected. Let's just talk about immune
The main points for immune to autorun. inf are:
1. prevent viruses from generating the autorun. inf file in the root directory of the drive.
2. prevent vir
Worm program worm. win32.autorun. DG Solution
Virus name
Worm. win32.autorun. DG
Capture Time
2007-10-14
Virus symptoms
The virus is a worm program written in Delphi. It is 25,600 bytes in length, the icon is a regular executable file icon, and the
When ravmone.exe "...... The mysterious ghost in the root directory, the killer of system security, is called the "USB flash drive virus ". Countless Windows users are focusing on them. This article is a summary of your research on the USB flash drive virus and lessons learned from the fight against the USB flash drive virus.
All systems after Windows 95 have an
Iamcj blog
In the previous Make a anti-autorun batch, we discussed how to disable the Shell Hardware Detection Service to prevent the automatic operation of the disc/USB flash drive during insertion, there are also a considerable number of discussions, removing the question of no nutrition in the middle, which puts forward three points worth noting:
Through rd/s/q, you can directly Delete the autorun. inf d
The root directory of the mobile hard disk may not be deleted at any time. vinf file, opened with hexeditor, binary, but from the end of the ASCII code, you can see jwgkvsq. vmx. Search online to find out that this is a relatively new virus.
In fact, if the virus is not infected with the system, you can enter the security mode and perform the following operations:
1. Shut down the system. Welcome;
2. Disab
Kill. bat
CopyCode The Code is as follows: @ echo off
Taskkill/f/IM virus .exe
CD \
For/d % I in (C, D, E, F, G, H, I, K, L, M, N, O, P, Q, R, s, T, U, V, W, X, Y, Z) Do attrib-s-a-r-H % I: \ autorun. INF attrib-s-a-r-H % I: \ virus .exe del % I: \ autorun. INF
Kill. vbsCopy codeThe Code is as follows: on error res
address list and the attack configuration, and according to the configuration file, carries on the corresponding attack.
The configuration file is as follows:
www.victim.net:3389
Www.victim.net:80
Www.victim.com:80
Www.victim.net:80
1
1
120
50000
"Panda Incense" FuckJacks.exe variant of the same as the previous variant of the use of white Panda incense icon, virus after running the copy itself to the system directory:
%system%\drivers\spoclsv.exe
T
the registry, sets itself as the boot entry, traverses each drive, and writes itself to the root directory of the disk, add an Autorun. inf file that enables the user to activate the virus body when opening the disk. Then, the virus opened a thread to infect local files, and opened another thread to connect to a website to download ddos programs for malicious at
From: http://blog.3gcomet.com/
Idea: the same name folder and file cannot exist under the same folder at the same time. Today, some people say that the previous ideas are
Create a folder to prevent the execution of autorun. inf virus. The operation is as follows (use the command to create a folder, and the E disk is the drive letter of the U disk ):
E:
MD autoru
Autorun. inf and its command details
We already know that you can use intellirun. inf to specify the icons and running files automatically loaded on the CD,In fact, autorun. inf is very useful,The following describes the application of autorun. inf in detail.
Learn about autorun. infWhat is
[% Repeat_0 match = "/data/option" %] [% = @ title %] [% = @ count %] ticket [[% = @ percent %]
[% _ Repeat_0 %]
Sxs. EXE is a trojan virus that steals the passwords of QQ accounts. It is characteristic of being able to spread through a removable disk. The main harm of the virus is to steal QQ accounts and passwords. The virus also ends a large number of anti
First, create a text document under the root directory of the USB flash drive.Then rename it autorun. inf (Be sure to change the suffix)Enter [Autorun] // indicates that the autorun part starts and must be entered.Icon = C. ICO // give the USB flash drive a personalized drive letter icon C. ICO (the icon name can be changed for C. ico)Then place an icon file name
Solve the autorun And mags. pif viruses in linux-general Linux technology-Linux technology and application information. The following is a detailed description. Yesterday, my computer experienced symptoms of poisoning. After I started the computer, I found that the system time was changed. Then, after double-clicking each system disk, the address book page will appear. I can only right-click it and find two hidden
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.