被病毒所修改的注册表:
项:HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
健值:Shell
指向数据:Explorer.exe,service.exe
释放的autorun.inf文件:
[AutoRun]
open=default.exe
shell\open=打开(&O)
shell\open\Command=default.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=default.exe |
|