ããUçæç»è®¿é®ï¼å¯æç
§å¦ä¸æ¥éª¤è¿è¡ä¿®å¤ï¼
1ï¼è¿å
¥âå¼å§---è¿è¡âï¼è¾å
¥regeditæå¼æ³¨å表ç¼è¾å¨ï¼å°âHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHOWALLâåæ¯ï¼ç¶åå¨å³çªå£ä¸æ¾å°äºè¿å¶åé®âChecked valueâï¼å°âChecked valueâçé®å¼æ¹ä¸ºâ1âã
2ï¼å¨âå·¥å
·çæ件夹é项ä¸ï¼éæ©âæ¾ç¤ºæææ件åæ件夹âï¼è¿æ ·å°±å¯ä»¥æ¾ç¤ºäºã
3å¨Uçä¸ä¼çå°å个æ件ï¼åå«æ¯floderãdestopãdestop2åautorun.infï¼å°è¿å个å
¨é¨å é¤ã
4ï¼ä¹åä¼å¨Uçéåç°ä¸ä¸ªéèæ件RECYCLERï¼æè¿ä¸ªæ件夹å é¤ããã
5ï¼æ¾å°[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon]åæ¯ï¼æ"Userinit"è¿ä¸ªé®çé®å¼æ¹ä¸º"userinit.exe"ã
6ï¼å¨è¿ç¨éæå½åç¨æ·åä¸çwuauserv.exeåsvchost.exeç»æã
7ï¼è¿å
¥c:\windows\system32\svchostç®å½ï¼æ³¨æsvchostæ¯ä¸ªæ件夹ï¼ä¸æ¯ç¨åºï¼ï¼å°è¿ä¸ªç®å½å
¨é¨å é¤ãè¿æ ·å°±å¤§ååæäºï¼æUçæä¸æ¥åæä¸å°±å¯ä»¥æ£å¸¸ä½¿ç¨äºã
追é®è¿ä¸ªæè¯è¿äº ä¸è¡ç