在论坛混了好几天,得到许多人的帮助才写完。
谢谢各位的指教。
版本1.0
病毒特征:
右键单击盘符,出现黑体auto,browse,自动播放,双击硬盘出现打开方式
目前可以彻底清理的病毒:
SXS,LSASS.EXE,COMMAND.COM,AUTORUN.VBS
遇到未知病毒时根据AUTORUN.INF里面调用的程序,删除病毒主体。
例如
autorun.inf
open=test.exe
程序会自动删除test.exe
在对待未知病毒上还比较欠缺,仅仅是根据autorun.inf来处理,检测不到病毒衍生物。
如果系统不是安装在C盘,处理LSASS.EXE病毒时容易把注册表修改坏,导致不能正常登陆。
白天上班,只能晚上更新,因此更新速度可能比较慢。
http://zhenlove.com.cn/cndos/fileup/files/autorunkillone.rar
链接已失效(管理员注)
I've been in the forum for several days and only finished writing after getting help from many people.
Thank you all for your instructions.
Version 1.0
Virus characteristics:
Right - click on the drive letter, there appear bold auto, browse, autoplay; double - click the hard drive, there appears the open - with way
Currently, the viruses that can be completely cleaned:
SXS, LSASS.EXE, COMMAND.COM, AUTORUN.VBS
When encountering an unknown virus, delete the virus main body according to the program called in AUTORUN.INF.
For example
autorun.inf
open=test.exe
The program will automatically delete test.exe
There is still a lack in dealing with unknown viruses, only dealing with it according to autorun.inf, and unable to detect virus derivatives.
If the system is not installed on drive C, when dealing with the LSASS.EXE virus, it is easy to modify the registry badly, leading to being unable to log in normally.
I go to work during the day and can only update at night, so the update speed may be relatively slow.
http://zhenlove.com.cn/cndos/fileup/files/autorunkillone.rar
The link has expired (note from administrator)