å¯è½æ¯æ¯.
æç¨æ¨é©¬æ客æ¶ä¹éå°è¿è¿ç§æ
åµ,åå æ¯æ¨é©¬æ客æexplorerçæ©å±åæ¹ä¸º[explorer.exe_被å±è½æ¨é©¬],äºæ¯å°±åºç°åæ ·é®é¢.
ä½ å¨C:/windows/system32/ä¸æ¥æ¾è¢«ç¯¡æ¹çæ件,æ¹åæ¥å³å¯.åè
ç´æ¥æå
¥winXPç,æç
§æ示ä¹å¯è§£å³é®é¢.
è³äºå½»åºæ¸
ç,ä¸è½½ ä¼å大å¸æµæ°è½¯ä»¶æ¸
çå·¥å
· è¿è¡æ¸
ç.ä¸è½½å°å:
www.wopti.net/download.htm å¦å¤,å³é®ç¬¬ä¸ä¸ªæ¯Auto,ä½ åºè¯¥å¨æ¯ä¸ªçä¸æ¥æ¾autorun.infçæ件,å é¤å³å¯
-----------第äºæ¬¡åç----------------
é对éèæ件æ æ³æ¾ç¤ºçé®é¢:ä¾æ¬¡æå¼æ§å¶é¢æ¿->æ件夹é项->æ¥ç(é项å¡)->é«çº§è®¾ç½®->éèæ件åæ件夹->éæ¾ç¤ºæææ件åæ件夹
é£å°±æ¯æ¯,çèµ·æ¥æç¹åè½éª,ä½ å°ç½ä¸æä¸æ,ä¸ä¸ªEwidoæ¥ææ¯,ææ¨å¤©æåç°,åå®çº§ææ¯å¾å¥½ä½¿.æè
ä¸ä¸ä¸ªæ±æ°è½éªç
æ¯è½¬æå·¥å
·
çä½ å¯¹autorun.infæå
´è¶£,ççè¿ä¸ª:
------------------解æautorun.inf------------------------
æ们å¨ä½¿ç¨åç§å
çæ¶ï¼é½ä¼åç°åä¸ç§ç°è±¡ï¼å½æ们æå
çæ¾å
¥å
驱åï¼Windows便è½èªå¨å°å¯å¨å
çä¸çæ个ç¨åºï¼ä»èå®æä¸ä¸ªåºäºWindowså¹³å°è®¾è®¡ç产åçé
ç½®ãå®è£
çæä½ï¼æè
æå¼èµæºç®¡çå¨ï¼ä¼åç°å
ççå¾æ 已被æ¹åææ å¿å
¶äº§åä¹ç±»çå¾æ äºã è¿ç确让æ们æè§å°æä½ä¸çæ¹ä¾¿åå¿«æ·ãå
¶å®ï¼è¿æ¯å©ç¨äºWindowsæä½ç³»ç»çâèªå¨ææ¾ï¼AutoPlayï¼âåè½ã
èªå¨ææ¾çå·¥ä½åç
èªå¨ææ¾çåçå¾ç®åï¼å½å
ç被æ¾å
¥éç¨Windowsæä½ç³»ç»ç计ç®æºå
驱ä¸æ¶ï¼ç³»ç»ä¼ç«å³æ£æµWindowsçä¸ä¸ª32ä½å
驱驱å¨ç¨åºï¼ç¶åæ寻å
çä¸æ ¹ç®å½ä¸ä¸ä¸ªå«Autorun.infçé
ç½®æ件ï¼å¹¶èªå¨è¿è¡è¿ä¸ªAutorun.infä¸è®¾ç½®çå½ä»¤ãæ¾ç¶ï¼å¨æ´ä¸ªè¿ç¨ä¸èµ·çå
³é®ä½ç¨ç便æ¯è¿ä¸ªAutorun.infæ件ï¼æ们æä½éªå°çâèªå¨âï¼äºå®ä¸é½æ¯å¨è¿ä¸ªæ件éé¢å
æå®çã
ä¸ã解读Autorun.inf
Autorun.infæ¯ä¸ä¸ªææ¬å½¢å¼çé
ç½®æ件ï¼æ们å¯ä»¥ç¨ææ¬ç¼è¾è½¯ä»¶è¿è¡ç¼è¾ï¼å®åªè½ä½äºé©±å¨å¨çæ ¹ç®å½ä¸ãè¿ä¸ªæ件å
å«äºéè¦èªå¨è¿è¡çå½ä»¤ï¼å¦æ¹åç驱å¨å¨å¾æ ãè¿è¡çç¨åºæ件ãå¯éå¿«æ·èåçå
容ã
Autorun.infæ件ç»æè¾ç®åï¼ä¸»è¦å
å«ä¸ä¸ªåºå®ç段æ è¯[Autorun]åèªå®çèªå¨ææ¾å½ä»¤(Autoplay command)ãå®ä¹å¥½Autoplay commandå°±å¯ä»¥å®ç°èªå·±çèªå¨ææ¾äºã
æ¹å驱å¨å¨å¾æ å½ä»¤ï¼Defaulticonå½ä»¤åIconå½ä»¤
è¿ä¸¤æ¡å½ä»¤é½è½æ¹åå
çå¾æ ï¼åè½ç¸åãæ们平æ¶è§å°çå
çå¾æ çæ¹åå°±æ¯ç¨æ¤å½ä»¤æ¥å®ç°çã
å½ä»¤ä¸é½å
å«å¾æ ä¿¡æ¯æ件(iconname)ï¼å¯ä»¥æåºè¯¥æ件å¨å
çä¸çç¸å¯¹è·¯å¾(path)ï¼å¨æ²¡ææåºè·¯å¾çæ
åµä¸ï¼Windowsèªå¨å°å
ççæ ¹ç®å½ä¸æ寻å¾æ ä¿¡æ¯æ件ãå
¶å½ä»¤æ ¼å¼ä¸ºï¼
Defaulticon=Path\Iconname
æIcon=Path\Iconname
Iconnameå¯ä»¥æ¯.icoã.bmpã.exeæ .dllæ件ãä¾å¦ï¼è¦å¼ç¨å
çæ ¹ç®å½ä¸Setup.icoä½ä¸ºå
ççå¾æ ï¼å¯è¿æ ·è¡¨ç¤ºï¼
Defaulticon=Setup.ico
æIcon=Setup.ico
å¦æè¿ä¸ªæ件å
å«å¤ä¸ªå¾æ ï¼å¯æå®æ件ä¸çä¸ä¸ªèµæºå·ï¼ç´¢å¼ï¼æ¥å¼ç¨å
¶ä¸çä¸åå¾æ ãèµæºå·ç±0ã1ã2â¦â¦æ°åæ¥æ è¯ï¼åå«ä»£è¡¨å¾æ ä¿¡æ¯æ件ä¸ç第ä¸ä¸ªå¾æ ã第äºä¸ªå¾æ â¦â¦ï¼å®ä¸å¾æ ä¿¡æ¯æ件é´ç¨éå·åéãä¾å¦ï¼å¨å
çautorunç®å½ä¸æä¸ä¸ªå
å«ä¸¤ä¸ªå¾æ çautorun.exeæ件ï¼è¦å¼ç¨å
¶ä¸ç第äºä¸ªå¾æ ä½ä¸ºå
çå¾æ ï¼å¯ä»¥è¿æ ·è¡¨ç¤ºï¼
Defaulticon =Autorun\Autorun.exe, 1
æIcon=Autorun\Autorun.exe, 1
å½ä½ 对è¿ä¸ªå¾æ æå°ä¸æ»¡ææ¶ï¼åªè¦æ¢ä¸ä¸ªèµæºå·å³å¯ã
éè¦è¯´æçæ¯ï¼å¦æDefaulticon åIconå½ä»¤ååºç°å¨ä¸ä¸ªAutorun.infæ件ä¸ï¼Autoplay使ç¨Defaulticonå½ä»¤è忽ç¥Iconå½ä»¤ã
äºãåä¸ä¸ªèªå¨æå¼ç½é¡µçå
ç
1ãæä½ çç½é¡µæ¾å¨ä¸ä¸ªæ件夹ä¸é¢ï¼å¦html
2ãå¨ç®å½æ°å»ºä¸ä¸ªautorun.infçæ件ï¼æå¼åç¼è¾ä¸ºä»¥ä¸å
容ï¼
[aotorun]
icon=***.ico(å å¾æ ï¼
shellexecute=index.html(å
çæ¾å
¥åèªå¨æå¼index.html,å¦ææ¯win9x/meçè¯åæ¹æopen=start.exe index.html)
ä¸ãåä¸ä¸ªèªå¨æ¾æçå
ç
1ãé¦å
å¾æ°å»ºä¸ä¸ªæ件夹æ¥æ¾è¦ææ¾çMP3ï½ï¼å¶æ¾å¨Dçä¸ï¼å°±æ¯d:\mp3
2ãä¸è½½ä¸ä¸ªææ¾å¨è½¯ä»¶ï¼æ³¨æè¦æ¯ç»¿è²çï¼å¦ååãFoobarï¼
3ã对ææ¾å¨è¿è¡è®¾ç½®ï¼å»æä¸è¦çåè½ï¼æ主è¦çæ¯æD:\MP3çé³ä¹å å°ææ¾å表ä¸é¢å¹¶ä¿å为fplææ¾å表æ件
4ãå¨MP3ç®å½ä¸æ°å»ºä¸ä¸ªå为autorun.infçæ件ï¼ç¨è®°äºæ¬æå¼ï¼è¾å
¥ä»¥ä¸å
容ï¼
[aotorun]
open=foobar\foobar.exe **.fpl(å°±æ¯éè¿foobaræ¥æå¼**.fplææ¾å表ï¼
icon=foobar\foobar.exe,1(设置å¾æ 为foobarç¨åºç第ä¸ä¸ªå¾æ ï¼
5ãæD:\MP3ä¸ææçæ件å»å½å°å
çã
åãæ¹å驱å¨å¨çå¾æ
1ãå¨è¦æ¹åå¾æ ç驱å¨å¨æ ¹ç®å½ä¸æ°å»ºautorun.inf(è¿é以dç为ä¾ï¼
2ãè¾å
¥ä»¥ä¸å
容:
[autorun]
ICON=c:\windows\system\shell32.dll,21(Dççå¾æ ä¼åæ shell32.dllç第21个å¾æ ï¼
äºã为å
çå å³é®èåï½
1ãå¨å
çæ ¹ç®å½ä¸æ°å»ºä¸ä¸ªautorun.infï¼ç¼è¾ä¸º
[autorun]
icon=c:\windows\system\shell32.dll,21
shell\01=说ææ件
shell\01\command=notepad readme.txt(ç¨notepadæå¼readme.txtæ件ï¼
shell\02=èªå¨è¿è¡å
ç
shell\02\command=autorunï¼èªå¨è¿è¡å
çäºï¼
shell\03=å®è£
WINRAR
shell\03\command=winrar.exeï¼å®è£
WINRARï¼
open=***.exe(èªå¨è¿è¡å
çæ¶è¿è¡è¿ä¸ªç¨åºï¼
ä¹è®¸è¦å»å½åæè½ææã
å
ãç¨autorun.infå®ç°ä¿®æ¹æ³¨å表ï¼å±é©ï¼
示ä¾1ãæå
¥å
çåå°±èªå¨éæä½ ç注å表ããã
é¦å
ç¼åä¸ä¸ªREGæ件ï¼æå¼è®°äºæ¬ï¼é®å
¥ä»¥ä¸å
容ï¼
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=dword: 00000001
å°ä»¥ä¸é¨åå¦å为lock.regæ件ãè¦ç¹å«æ³¨æ第ä¸è¡REGEDIT4è¦ç¨å¤§åä¸é¡¶æ ¼åï¼å¨å®åé¢è¦ç©ºä¸ä¸è¡ï¼å¨æåä¸è¡åå®åè®°å¾è¦æ两次å车é®ï¼å³æåä¹è¦ç©ºä¸ä¸è¡ã
ç¶åæ°å»ºä¸ä¸ªAutoRun.infæ件ï¼è¾å
¥ä»¥ä¸å
容ï¼
[AutoRun]
Open=Regedit/s ShareC.reg
å /såæ°æ¯ä¸ºäºå¯¼å
¥æ¶ä¸ä¼æ¾ç¤ºä»»ä½æ示信æ¯ï¼ä¿åAutoRun.infæ件ãå°lock.regåAutoRun.infè¿ä¸¤ä¸ªæ件é½å¤å¶å°å¦ä¸å°çµèçç£ççæ ¹ç®å½ä¸æå»å½å°å
çä¸ï¼è¿æ ·å¯¹æ¹åªè¦åå»é£ä¸ªç£çæè
æå
çæå
¥å
驱就ä¼å°lock.reg导å
¥æ³¨å表ï¼èä¸æ²¡ææ示å¦ãã对æ¹ç注å表就被éäº
说æ1ï¼æ¯å¦æ§è¡AutoRunåè½å
¶å®ç±æ³¨å表æ¥å³å®ãå¨âå¼å§âèåçâè¿è¡âä¸è¾å
¥Regeditï¼æå¼æ³¨å表ç¼è¾å¨ï¼å±å¼å°HKEY_CURRENT_USER\ software\Microsoft\Windows\Currentï¼ Version\Policies\Exploer主é®ä¸ï¼å³è¾¹çªå£ä¸çäºè¿å¶å¼âNoDriveTypeï¼ AutoRunâå³å®äºæ¯å¦æ§è¡AutoRunåè½ï¼å
æ¬ç¡¬çåRamdiskï¼ãâNoDriveTypeAutoRunâé»è®¤é®å¼ä¸º95 00 00 00
说æ2ï¼Shell32.DLLæ¯ä¸ä¸ªWindowsç³»ç»æ件ï¼éé¢å
å«æå¾å¤Windowsçç³»ç»å¾æ ï¼21表示æ¾ç¤ºä¸ºç¼å·ä¸º21çå¾æ ï¼å½ç¶ä½ ä¹å¯ä»¥èªå·±å¶ä½ä¸ä¸ªå¾æ ï¼åªéè¦å¨âICONâä¸è¡æè·¯å¾åç¸åºä¿®æ¹å³å¯ãé¤äºå¯ä»¥ä½¿ç¨DLLæ件ä¸çå¾æ å¤ï¼è¿è½ç¨EXEæ件ä¸çå¾æ ï¼æç´æ¥ä½¿ç¨ICOæ件ã
说æ3ï¼ä¸åçææ¾å¨çåæ°å è½½æ¹å¼å¯è½ä¼ä¸åçã
æ们å¨ä½¿ç¨åç§å
çæ¶ï¼é½ä¼åç°åä¸ç§ç°è±¡ï¼å½æ们æå
çæ¾å
¥å
驱åï¼Windows便è½èªå¨å°å¯å¨å
çä¸çæ个ç¨åºï¼ä»èå®æä¸ä¸ªåºäºWindowså¹³å°è®¾è®¡ç产åçé
ç½®ãå®è£
çæä½ï¼æè
æå¼èµæºç®¡çå¨ï¼ä¼åç°å
ççå¾æ 已被æ¹åææ å¿å
¶äº§åä¹ç±»çå¾æ äºã è¿ç确让æ们æè§å°æä½ä¸çæ¹ä¾¿åå¿«æ·ãå
¶å®ï¼è¿æ¯å©ç¨äºWindowsæä½ç³»ç»çâèªå¨ææ¾ï¼AutoPlayï¼âåè½ã
èªå¨ææ¾çå·¥ä½åç
èªå¨ææ¾çåçå¾ç®åï¼å½å
ç被æ¾å
¥éç¨Windowsæä½ç³»ç»ç计ç®æºå
驱ä¸æ¶ï¼ç³»ç»ä¼ç«å³æ£æµWindowsçä¸ä¸ª32ä½å
驱驱å¨ç¨åºï¼ç¶åæ寻å
çä¸æ ¹ç®å½ä¸ä¸ä¸ªå«Autorun.infçé
ç½®æ件ï¼å¹¶èªå¨è¿è¡è¿ä¸ªAutorun.infä¸è®¾ç½®çå½ä»¤ãæ¾ç¶ï¼å¨æ´ä¸ªè¿ç¨ä¸èµ·çå
³é®ä½ç¨ç便æ¯è¿ä¸ªAutorun.infæ件ï¼æ们æä½éªå°çâèªå¨âï¼äºå®ä¸é½æ¯å¨è¿ä¸ªæ件éé¢å
æå®çã
ä¸ã解读Autorun.inf
Autorun.infæ¯ä¸ä¸ªææ¬å½¢å¼çé
ç½®æ件ï¼æ们å¯ä»¥ç¨ææ¬ç¼è¾è½¯ä»¶è¿è¡ç¼è¾ï¼å®åªè½ä½äºé©±å¨å¨çæ ¹ç®å½ä¸ãè¿ä¸ªæ件å
å«äºéè¦èªå¨è¿è¡çå½ä»¤ï¼å¦æ¹åç驱å¨å¨å¾æ ãè¿è¡çç¨åºæ件ãå¯éå¿«æ·èåçå
容ã
Autorun.infæ件ç»æè¾ç®åï¼ä¸»è¦å
å«ä¸ä¸ªåºå®ç段æ è¯[Autorun]åèªå®çèªå¨ææ¾å½ä»¤(Autoplay command)ãå®ä¹å¥½Autoplay commandå°±å¯ä»¥å®ç°èªå·±çèªå¨ææ¾äºã
æ¹å驱å¨å¨å¾æ å½ä»¤ï¼Defaulticonå½ä»¤åIconå½ä»¤
è¿ä¸¤æ¡å½ä»¤é½è½æ¹åå
çå¾æ ï¼åè½ç¸åãæ们平æ¶è§å°çå
çå¾æ çæ¹åå°±æ¯ç¨æ¤å½ä»¤æ¥å®ç°çã
å½ä»¤ä¸é½å
å«å¾æ ä¿¡æ¯æ件(iconname)ï¼å¯ä»¥æåºè¯¥æ件å¨å
çä¸çç¸å¯¹è·¯å¾(path)ï¼å¨æ²¡ææåºè·¯å¾çæ
åµä¸ï¼Windowsèªå¨å°å
ççæ ¹ç®å½ä¸æ寻å¾æ ä¿¡æ¯æ件ãå
¶å½ä»¤æ ¼å¼ä¸ºï¼
Defaulticon=Path\Iconname
æIcon=Path\Iconname
Iconnameå¯ä»¥æ¯.icoã.bmpã.exeæ .dllæ件ãä¾å¦ï¼è¦å¼ç¨å
çæ ¹ç®å½ä¸Setup.icoä½ä¸ºå
ççå¾æ ï¼å¯è¿æ ·è¡¨ç¤ºï¼
Defaulticon=Setup.ico
æIcon=Setup.ico
å¦æè¿ä¸ªæ件å
å«å¤ä¸ªå¾æ ï¼å¯æå®æ件ä¸çä¸ä¸ªèµæºå·ï¼ç´¢å¼ï¼æ¥å¼ç¨å
¶ä¸çä¸åå¾æ ãèµæºå·ç±0ã1ã2â¦â¦æ°åæ¥æ è¯ï¼åå«ä»£è¡¨å¾æ ä¿¡æ¯æ件ä¸ç第ä¸ä¸ªå¾æ ã第äºä¸ªå¾æ â¦â¦ï¼å®ä¸å¾æ ä¿¡æ¯æ件é´ç¨éå·åéãä¾å¦ï¼å¨å
çautorunç®å½ä¸æä¸ä¸ªå
å«ä¸¤ä¸ªå¾æ çautorun.exeæ件ï¼è¦å¼ç¨å
¶ä¸ç第äºä¸ªå¾æ ä½ä¸ºå
çå¾æ ï¼å¯ä»¥è¿æ ·è¡¨ç¤ºï¼
Defaulticon =Autorun\Autorun.exe, 1
æIcon=Autorun\Autorun.exe, 1
å½ä½ 对è¿ä¸ªå¾æ æå°ä¸æ»¡ææ¶ï¼åªè¦æ¢ä¸ä¸ªèµæºå·å³å¯ã
éè¦è¯´æçæ¯ï¼å¦æDefaulticon åIconå½ä»¤ååºç°å¨ä¸ä¸ªAutorun.infæ件ä¸ï¼Autoplay使ç¨Defaulticonå½ä»¤è忽ç¥Iconå½ä»¤ã
äºãåä¸ä¸ªèªå¨æå¼ç½é¡µçå
ç
1ãæä½ çç½é¡µæ¾å¨ä¸ä¸ªæ件夹ä¸é¢ï¼å¦html
2ãå¨ç®å½æ°å»ºä¸ä¸ªautorun.infçæ件ï¼æå¼åç¼è¾ä¸ºä»¥ä¸å
容ï¼
[aotorun]
icon=***.ico(å å¾æ ï¼
shellexecute=index.html(å
çæ¾å
¥åèªå¨æå¼index.html,å¦ææ¯win9x/meçè¯åæ¹æopen=start.exe index.html)
ä¸ãåä¸ä¸ªèªå¨æ¾æçå
ç
1ãé¦å
å¾æ°å»ºä¸ä¸ªæ件夹æ¥æ¾è¦ææ¾çMP3ï½ï¼å¶æ¾å¨Dçä¸ï¼å°±æ¯d:\mp3
2ãä¸è½½ä¸ä¸ªææ¾å¨è½¯ä»¶ï¼æ³¨æè¦æ¯ç»¿è²çï¼å¦ååãFoobarï¼
3ã对ææ¾å¨è¿è¡è®¾ç½®ï¼å»æä¸è¦çåè½ï¼æ主è¦çæ¯æD:\MP3çé³ä¹å å°ææ¾å表ä¸é¢å¹¶ä¿å为fplææ¾å表æ件
4ãå¨MP3ç®å½ä¸æ°å»ºä¸ä¸ªå为autorun.infçæ件ï¼ç¨è®°äºæ¬æå¼ï¼è¾å
¥ä»¥ä¸å
容ï¼
[aotorun]
open=foobar\foobar.exe **.fpl(å°±æ¯éè¿foobaræ¥æå¼**.fplææ¾å表ï¼
icon=foobar\foobar.exe,1(设置å¾æ 为foobarç¨åºç第ä¸ä¸ªå¾æ ï¼
5ãæD:\MP3ä¸ææçæ件å»å½å°å
çã
åãæ¹å驱å¨å¨çå¾æ
1ãå¨è¦æ¹åå¾æ ç驱å¨å¨æ ¹ç®å½ä¸æ°å»ºautorun.inf(è¿é以dç为ä¾ï¼
2ãè¾å
¥ä»¥ä¸å
容:
[autorun]
ICON=c:\windows\system\shell32.dll,21(Dççå¾æ ä¼åæ shell32.dllç第21个å¾æ ï¼
äºã为å
çå å³é®èåï½
1ãå¨å
çæ ¹ç®å½ä¸æ°å»ºä¸ä¸ªautorun.infï¼ç¼è¾ä¸º
[autorun]
icon=c:\windows\system\shell32.dll,21
shell\01=说ææ件
shell\01\command=notepad readme.txt(ç¨notepadæå¼readme.txtæ件ï¼
shell\02=èªå¨è¿è¡å
ç
shell\02\command=autorunï¼èªå¨è¿è¡å
çäºï¼
shell\03=å®è£
WINRAR
shell\03\command=winrar.exeï¼å®è£
WINRARï¼
open=***.exe(èªå¨è¿è¡å
çæ¶è¿è¡è¿ä¸ªç¨åºï¼
ä¹è®¸è¦å»å½åæè½ææã
å
ãç¨autorun.infå®ç°ä¿®æ¹æ³¨å表ï¼å±é©ï¼
示ä¾1ãæå
¥å
çåå°±èªå¨éæä½ ç注å表ããã
é¦å
ç¼åä¸ä¸ªREGæ件ï¼æå¼è®°äºæ¬ï¼é®å
¥ä»¥ä¸å
容ï¼
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=dword: 00000001
å°ä»¥ä¸é¨åå¦å为lock.regæ件ãè¦ç¹å«æ³¨æ第ä¸è¡REGEDIT4è¦ç¨å¤§åä¸é¡¶æ ¼åï¼å¨å®åé¢è¦ç©ºä¸ä¸è¡ï¼å¨æåä¸è¡åå®åè®°å¾è¦æ两次å车é®ï¼å³æåä¹è¦ç©ºä¸ä¸è¡ã
ç¶åæ°å»ºä¸ä¸ªAutoRun.infæ件ï¼è¾å
¥ä»¥ä¸å
容ï¼
[AutoRun]
Open=Regedit/s ShareC.reg
å /såæ°æ¯ä¸ºäºå¯¼å
¥æ¶ä¸ä¼æ¾ç¤ºä»»ä½æ示信æ¯ï¼ä¿åAutoRun.infæ件ãå°lock.regåAutoRun.infè¿ä¸¤ä¸ªæ件é½å¤å¶å°å¦ä¸å°çµèçç£ççæ ¹ç®å½ä¸æå»å½å°å
çä¸ï¼è¿æ ·å¯¹æ¹åªè¦åå»é£ä¸ªç£çæè
æå
çæå
¥å
驱就ä¼å°lock.reg导å
¥æ³¨å表ï¼èä¸æ²¡ææ示å¦ãã对æ¹ç注å表就被éäº
说æ1ï¼æ¯å¦æ§è¡AutoRunåè½å
¶å®ç±æ³¨å表æ¥å³å®ãå¨âå¼å§âèåçâè¿è¡âä¸è¾å
¥Regeditï¼æå¼æ³¨å表ç¼è¾å¨ï¼å±å¼å°HKEY_CURRENT_USER\ software\Microsoft\Windows\Currentï¼ Version\Policies\Exploer主é®ä¸ï¼å³è¾¹çªå£ä¸çäºè¿å¶å¼âNoDriveTypeï¼ AutoRunâå³å®äºæ¯å¦æ§è¡AutoRunåè½ï¼å
æ¬ç¡¬çåRamdiskï¼ãâNoDriveTypeAutoRunâé»è®¤é®å¼ä¸º95 00 00 00
说æ2ï¼Shell32.DLLæ¯ä¸ä¸ªWindowsç³»ç»æ件ï¼éé¢å
å«æå¾å¤Windowsçç³»ç»å¾æ ï¼21表示æ¾ç¤ºä¸ºç¼å·ä¸º21çå¾æ ï¼å½ç¶ä½ ä¹å¯ä»¥èªå·±å¶ä½ä¸ä¸ªå¾æ ï¼åªéè¦å¨âICONâä¸è¡æè·¯å¾åç¸åºä¿®æ¹å³å¯ãé¤äºå¯ä»¥ä½¿ç¨DLLæ件ä¸çå¾æ å¤ï¼è¿è½ç¨EXEæ件ä¸çå¾æ ï¼æç´æ¥ä½¿ç¨ICOæ件ã
说æ3ï¼ä¸åçææ¾å¨çåæ°å è½½æ¹å¼å¯è½ä¼ä¸åçã