| ²é¿´: 222 | »Ø¸´: 11 | |||
| µ±Ç°Ö÷ÌâÒѾ´æµµ¡£ | |||
[½»Á÷]
ÈçºÎɾ³ýAutorun.infÎļþ¼Ð
|
|||
|
ÔÚÓ²ÅÌÿ¸ö·ÖÇø¶¼ÓÐÒ»¸öÃûΪ"Autorun.inf"µÄÎļþ¼Ð,´ò¿ª¸ÃÎļþ¼Ð,ÀïÃæÓиöÃûΪ:"ÃâÒßĿ¼..."µÄÎļþ¼ÐºÍÒ»¸öÎı¾. Õâ¸ö×ÓÎļþ´ò²»¿ª,Ò²ÎÞ·¨É¾³ý(°üÀ¨°²È«Ä£Ê½,). Îı¾Ô»°ÊÇ"¸ÃÎļþ¼ÐÓÉUSBKillerÉú³É£¬ÓÃÓÚÃâÒßUÅ̲¡¶¾Èç¹ûÄú²»ÐèÒª£¬¿ÉÒÔʹÓÃÈ¡ÏûÃâÒß¹¦ÄÜɾ³ý¸ÃÎļþ¼Ð¡£" UÅÌÒ²ÓÐÕâôһ¸öÎļþ¼Ð Ҳɾ²»µô ֮ǰÓÃÈðÐÇ ºÍ 360°²È«ÎÀʿҲû²é´¦À´ÕâÊDz»ÊDz¡¶¾. Çë½ÌÔõô½â¾ö. лл! [ Last edited by cyx on 2007-9-14 at 16:36 ] |
» ²ÂÄãϲ»¶
336Çóµ÷¼Á
ÒѾÓÐ3È˻ظ´
306Çóµ÷¼Á
ÒѾÓÐ9È˻ظ´
¹¤¿Æ0856Çóµ÷¼Á
ÒѾÓÐ4È˻ظ´
¹¤¿Æ²ÄÁÏ085601 279Çóµ÷¼Á
ÒѾÓÐ10È˻ظ´
081700 µ÷¼Á 267·Ö
ÒѾÓÐ4È˻ظ´
276Çóµ÷¼Á¡£ÓаëÄêµç³ØºÍ°ëÄê¸ß·Ö×Óʵϰ¾Àú
ÒѾÓÐ9È˻ظ´
263Çóµ÷¼Á
ÒѾÓÐ9È˻ظ´
ÇóÀÏʦÊÕÎÒ
ÒѾÓÐ3È˻ظ´
ÕÐ08¿¼Êýѧ
ÒѾÓÐ12È˻ظ´
½ÓÊÕ2026˶ʿµ÷¼Á(ѧ˶+ר˶)
ÒѾÓÐ4È˻ظ´
2Â¥2007-09-14 16:19:40
²»¾ÐС½Ü
ľ³æ (ÖøÃûдÊÖ)
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ¹ó±ö: 2
- ½ð±Ò: 2342.7
- ºì»¨: 2
- Ìû×Ó: 1689
- ÔÚÏß: 56Сʱ
- ³æºÅ: 282007
- ×¢²á: 2006-09-23
- רҵ: Ò©ÎïѧÆäËû¿ÆÑ§ÎÊÌâ
3Â¥2007-09-14 16:30:31
²»¾ÐС½Ü
ľ³æ (ÖøÃûдÊÖ)
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ¹ó±ö: 2
- ½ð±Ò: 2342.7
- ºì»¨: 2
- Ìû×Ó: 1689
- ÔÚÏß: 56Сʱ
- ³æºÅ: 282007
- ×¢²á: 2006-09-23
- רҵ: Ò©ÎïѧÆäËû¿ÆÑ§ÎÊÌâ
4Â¥2007-09-14 16:31:19
maxuedong
ÖÁ×ðľ³æ (ÖøÃûдÊÖ)
Сľ³æÖÕÉí¹ËÎÊ
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ½ð±Ò: 21195.5
- ºì»¨: 2
- Ìû×Ó: 2248
- ÔÚÏß: 215.2Сʱ
- ³æºÅ: 158820
- ×¢²á: 2006-01-07
- ÐÔ±ð: GG
- רҵ: É«Æ×·ÖÎö

5Â¥2007-09-14 17:09:10
kaikaifeng
ÈÙÓþ°æÖ÷ (ÎÄ̳¾«Ó¢)
ѧÊõ´¿Êô¹·Æ¨~
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ¹ó±ö: 2.592
- ½ð±Ò: 2993.8
- É¢½ð: 3670
- ºì»¨: 18
- ɳ·¢: 13
- Ìû×Ó: 15451
- ÔÚÏß: 544.3Сʱ
- ³æºÅ: 430520
- ×¢²á: 2007-08-11
- ÐÔ±ð: GG
- רҵ: ·ÖÎöÒÇÆ÷ÓëÊÔ¼Á
- ¹ÜϽ: ÐÝÏйàË®

6Â¥2007-09-14 17:21:06
abill
гæ (³õÈëÎÄ̳)
- Ó¦Öú: 1 (Ó×¶ùÔ°)
- ½ð±Ò: 24.3
- Ìû×Ó: 21
- ÔÚÏß: 3.4Сʱ
- ³æºÅ: 236302
- ×¢²á: 2006-04-02
- רҵ: »·¾³Î¢ÉúÎïѧ
7Â¥2007-09-14 20:21:33
luoyanglhr
ÖÁ×ðľ³æ (ÖøÃûдÊÖ)
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ½ð±Ò: 21656.5
- É¢½ð: 160
- ºì»¨: 1
- Ìû×Ó: 1625
- ÔÚÏß: 100.7Сʱ
- ³æºÅ: 238127
- ×¢²á: 2006-04-05
- ÐÔ±ð: MM
- רҵ: ÉúÎﻯѧ

8Â¥2007-10-08 10:39:07
liningqiqi
ľ³æ (ÕýʽдÊÖ)
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ½ð±Ò: 1798.9
- É¢½ð: 140
- ºì»¨: 5
- Ìû×Ó: 340
- ÔÚÏß: 40.8Сʱ
- ³æºÅ: 379295
- ×¢²á: 2007-05-22
- ÐÔ±ð: MM
- רҵ: ÎÞ»ú²ÄÁÏ»¯Ñ§
9Â¥2007-10-08 12:04:19
awoman
½ð³æ (СÓÐÃûÆø)
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ½ð±Ò: 2017
- Ìû×Ó: 155
- ÔÚÏß: 53.2Сʱ
- ³æºÅ: 133598
- ×¢²á: 2005-12-14
- רҵ: µç»¯Ñ§
|
²éɱ·½·¨£º Ò».Çå³ý²¡¶¾Ö÷³ÌÐò£¨Ëæ»ú8λ×ÖĸºÍÊý×Ö×éºÏµÄexeºÍdll£© ±ØÐëÊ×ÏÈÇå³ýauto.exeºÍÆäÉú³ÉµÄËæ»ú8λ×ÖĸºÍÊý×Ö×éºÏµÄexeºÍdll£¬ÒòΪËûÊÇľÂíȺµÄÍò¶ñÖ®Ô´£¡£¡ 1.Ê×ÏÈÏÂÔØsrengÕâ¸öÈí¼þ£¨http://download.kztechs.com/files/sreng2.zip£© ½âѹËõºóÔËÐÐsrengps.exe ÒÀ´Îµã»÷¡°Æô¶¯ÏîÄ¿¡±-¡°·þÎñ¡±-¡°Win32·þÎñÓ¦ÓóÌÐò¡± Ö®ºó¹´Ñ¡¡°Òþ²Ø¾ÈÏÖ¤µÄ΢ÈíÏîÄ¿¡± µÈ´ýÁбí³öÀ´Ö®ºó ²éÕÒÄÇÖÖ²»¹æÔòµÄËæ»ú8λ×Öĸ£¨´óд£©ºÍÊý×Ö×éºÏµÄ·þÎñ È»ºóÑ¡ÖÐÏÂÃæµÄ ¡°É¾³ý·þÎñ¡± ²¢µ¥»÷ÉèÖð´Å¥ ÔÚµ¯³öµÄ¿òÖе㡰·ñ¡± 2.ÖØÆô¼ÆËã»ú½øÈ밲ȫģʽÏ °ÑÏÂÃæµÄ´úÂ뿽Èë¼Çʱ¾ÖÐÈ»ºóÁí´æÎª1.regÎļþ Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "RegPath"="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced" "Text"="@shell32.dll,-30500" "Type"="radio" "CheckedValue"=dword:00000001 "ValueName"="Hidden" "DefaultValue"=dword:00000002 "HKeyRoot"=dword:80000001 "HelpID"="shell.hlp#51105" Ë«»÷1.reg°ÑÕâ¸ö×¢²á±íÏîµ¼Èë Ë«»÷ÎҵĵçÄÔ£¬¹¤¾ß£¬Îļþ¼ÐÑ¡Ï²é¿´£¬µ¥»÷ѡȡ"ÏÔʾÒþ²ØÎļþ»òÎļþ¼Ð" ²¢Çå³ý"Òþ²ØÊܱ£»¤µÄ²Ù×÷ϵͳÎļþ£¨ÍƼö£©"Ç°ÃæµÄ¹³¡£ÔÚÌáʾȷ¶¨¸ü¸Äʱ£¬µ¥»÷¡°ÊÇ¡± È»ºóÈ·¶¨ µã»÷ ²Ëµ¥À¸Ï·½µÄ Îļþ¼Ð°´Å¥£¨ËÑË÷Óұߵİ´Å¥£© ÔÚ×ó±ßµÄ×ÊÔ´¹ÜÀíÆ÷Öдò¿ªCÅÌ£¨ÏµÍ³ÅÌ£© ɾ³ýÈçÏÂÎļþ C:\auto.exe C:\autorun.inf ÒÔ¼°Ã¿¸ö·ÖÇøÏÂÃæµÄauto.exeºÍautorun.inf %system32%Îļþ¼ÐϵÄËæ»ú8¸ö×ÖĸºÍÊý×Ö×éºÏµÄexeºÍdll ¼´±¾ÀýÖеÄC:\WINDOWS\system32\E2050308.DLL C:\WINDOWS\system32\F2F187EC.EXE ÖÁ´Ë²¡¶¾Ö÷³ÌÐòÒѾ±»É¾³ýÁË£¬½ÓÏÂÀ´Çå³ýÆäÏÂÔØµÄľÂí ¶þ.Çå³ý²¡¶¾ÏÂÔØµÄľÂí£¨ÓÉÓÚÿ¸ö±äÖÖÏÂÔØµÄľÂí²»¾¡Ïàͬ£¬Òò´Ë±¾Àý½ö¹©²Î¿¼£© »¹ÊÇÔÚ°²È«Ä£Ê½Ï ´ò¿ªsreng Æô¶¯ÏîÄ¿ ×¢²á±í ɾ³ýÈçÏÂÏîÄ¿ [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] Ë«»÷ÎҵĵçÄÔ£¬¹¤¾ß£¬Îļþ¼ÐÑ¡Ï²é¿´£¬µ¥»÷ѡȡ"ÏÔʾÒþ²ØÎļþ»òÎļþ¼Ð" ²¢Çå³ý"Òþ²ØÊܱ£»¤µÄ²Ù×÷ϵͳÎļþ£¨ÍƼö£©"Ç°ÃæµÄ¹³¡£ÔÚÌáʾȷ¶¨¸ü¸Äʱ£¬µ¥»÷¡°ÊÇ¡± È»ºóÈ·¶¨ µã»÷ ²Ëµ¥À¸Ï·½µÄ Îļþ¼Ð°´Å¥£¨ËÑË÷Óұߵİ´Å¥£© ÔÚ×ó±ßµÄ×ÊÔ´¹ÜÀíÆ÷Öдò¿ªCÅÌ£¨ÏµÍ³ÅÌ£© ɾ³ýÈçÏÂÎļþ C:\WINDOWS\mppds.exe C:\WINDOWS\Kvsc3.exe C:\WINDOWS\kterzx.exe C:\WINDOWS\WinForm.exe C:\WINDOWS\AVPSrv.exe C:\WINDOWS\MsIMMs32.exe C:\WINDOWS\cmdbcs.exe C:\WINDOWS\DbgHlp32.exe C:\WINDOWS\upxdnd.exe C:\WINDOWS\kterzx.exe C:\WINDOWS\system32\mppds.dll C:\WINDOWS\system32\upxdnd.dll C:\WINDOWS\system32\AVPSrv.dll C:\WINDOWS\system32\DiskMan32.dll C:\WINDOWS\system32\NVDispDrv.dll C:\WINDOWS\system32\MsIMMs32.dll C:\WINDOWS\system32\WinForm.dll C:\WINDOWS\system32\cmdbcs.dll C:\WINDOWS\system32\DbgHlp32.dll C:\WINDOWS\system32\Kvsc3.dll ×îºóÐèÒªÐÞ¸´»òÕß֨װÈðÐÇɱ¶¾Èí¼þ£¬²¢Ò»¶¨ÐÞ¸ÄÄãµÄÍøÂçÓÎÏ·ÃÜÂë¡£ À´×ÔÈðÐÇÍøÕ¾. |
10Â¥2007-10-14 09:40:03













»Ø¸´´ËÂ¥
