系统文件关联
.exe ==> exefile = "%1" %*
.com ==> comfile = "%1" %*
.cmd ==> cmdfile = "%1" %*
.bat ==> batfile = "%1" %*
.txt ==> txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1
.scr ==> scrfile = "%1" /S
.reg ==> regfile = regedit.exe "%1"
.doc ==> WordPad.Document.1 = "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
其它启动项
C:\Autorun.inf
AUTORUN = xiaoshen.exe
D:\Autorun.inf
AUTORUN = xiaoshen.exe
F:\Autorun.inf
AUTORUN = xiaoshen.exe
G:\Autorun.inf
AUTORUN = xiaoshen.exe
H:\Autorun.inf
AUTORUN = xiaoshen.exe
WIN.INI
无信息
SYSTEM.INI
SHELL = Explorer.exe
SCRNSAVE.EXE = C:\WINDOWS\System32\logon.scr
还会出现heng。com。我觉得不是落雪
附件:
6388432006119111928.bmp