| ²é¿´: 296 | »Ø¸´: 10 | |||
| µ±Ç°Ö÷ÌâÒѾ´æµµ¡£ | |||
| ¡¾ÐüÉͽð±Ò¡¿»Ø´ð±¾ÌûÎÊÌ⣬×÷Õßmagua-no2½«ÔùËÍÄú 2 ¸ö½ð±Ò | |||
| µ±Ç°Ö»ÏÔʾÂú×ãÖ¸¶¨Ìõ¼þµÄ»ØÌû£¬µã»÷ÕâÀï²é¿´±¾»°ÌâµÄËùÓлØÌû | |||
magua-no2ľ³æ (СÓÐÃûÆø)
|
[ÇóÖú]
µçÄÔÖж¾£¬Çë¸ßÊÖ°ïæ
|
||
|
ÎҵĵçÄÔ£¬×òÌìÓÉÓÚ½èÓÃͬѧµÄÒÆ¶¯Ó²Å̶øÖж¾¡£ ÌØÕ÷£º¿¨°Í˹»ù¼ì²âµ½DLLHOST.EXEºÍSVCHOST.EXE²¡¶¾£¬Ëƺõɾ³ý²»ÁË£¬ÎÒÑ¡ÔñÁ˸ôÀ룬ºóÀ´ÎÊÌâÒ»´ó¶Ñ ËùÓÐÓ²ÅÌ´ò²»¿ªÁË£¬Ö»ÄÜÓÒ»÷£¬È»ºóÑ¡´ò¿ª²ÅÄܽøÈ룻 ÔËÐÐmsconfig£¬Ìáʾwindows ÕÒ²»µ½´ËÎļþ£» ¸÷Ó²Å̸ùĿ¼Ï³öÏÖrunauto.. Îļþ¼Ð£¬ÎÞ·¨É¾³ý¡£ ÎÒÕÒµ½DLLHOST.EXEºÍSVCHOST.EXE£¬·¢ÏÖÊÇ¡°ReLinsonϵÁÐÈí¼þ£¬¶à¹¦ÄÜÏÂÔØÕß¡±£¬ÍøÉÏÒ»²é£¬ËµÊǺڿÍÈí¼þ¡£ ¸ßÊÖÃÇ£¬ÎÒ¸ÃÔõô°ì£¿ ¶àлָµã£¡¸Ð¼¤²»¾¡¡£ |
» ²ÂÄãϲ»¶
¿¼Ñе÷¼Á
ÒѾÓÐ4È˻ظ´
281Çóµ÷¼Á
ÒѾÓÐ4È˻ظ´
0805 316Çóµ÷¼Á
ÒѾÓÐ6È˻ظ´
085601Çóµ÷¼Á×Ü·Ö293Ó¢Ò»Êý¶þ
ÒѾÓÐ3È˻ظ´
08¹¤Ñ§µ÷¼Á
ÒѾÓÐ17È˻ظ´
340Çóµ÷¼Á
ÒѾÓÐ4È˻ظ´
311Çóµ÷¼Á
ÒѾÓÐ3È˻ظ´
ʳƷר˶ һ־Ը˫һÁ÷ 328
ÒѾÓÐ4È˻ظ´
²ÄÁϵ÷¼Á
ÒѾÓÐ6È˻ظ´
300·Ö£¬²ÄÁÏ£¬Çóµ÷¼Á£¬Ó¢Ò»Êý¶þ
ÒѾÓÐ5È˻ظ´
lwy960803
ľ³æ (СÓÐÃûÆø)
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ½ð±Ò: 1508.9
- ºì»¨: 2
- Ìû×Ó: 219
- ÔÚÏß: 33.1Сʱ
- ³æºÅ: 151104
- ×¢²á: 2005-12-30
- רҵ: ²ÄÁϼӹ¤
¡ï
magua-no2(½ð±Ò+1,VIP+0):killautorunÓêÁÖľ·ç°æ±¾,ÏÂÔØÊ±¾ÍÌáʾÓв¡¶¾£¿
magua-no2(½ð±Ò+1,VIP+0):killautorunÓêÁÖľ·ç°æ±¾,ÏÂÔØÊ±¾ÍÌáʾÓв¡¶¾£¿
|
ÊÇ·ñ°²×°ÆäËüÈí¼þµÄʱºò¸½´ø×Ű²×°Á˺ڿÍÈí¼þ£¡£¡£¡ ÁíÍâÒÔºóÔÙÓÃÒÆ¶¯Ó²Å̵ϰ£¬×îºÃÊÇÏȲé²éÊÇ·ñÓÐAuto²¡¶¾£¡£¡ ½¨ÒéʹÓÃkillautorunÓêÁÖľ·ç°æ±¾µÄ£¡£¡ |
5Â¥2007-09-15 12:36:37
nucleus01
ÖÁ×ðľ³æ (ÖøÃûдÊÖ)
Сľ³æ±±Í¥½Ú¶Èʹ
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ¹ó±ö: 0.11
- ½ð±Ò: 15488.1
- ºì»¨: 1
- Ìû×Ó: 2930
- ÔÚÏß: 108.4Сʱ
- ³æºÅ: 165700
- ×¢²á: 2006-01-13
- ÐÔ±ð: GG
- רҵ: ÎïÀí
¡ï
magua-no2(½ð±Ò+1,VIP+0):ÐÁ¿àÁË£¬iceswordûÓùý°¡
magua-no2(½ð±Ò+1,VIP+0):ÐÁ¿àÁË£¬iceswordûÓùý°¡
|
dllhost.exe²¡¶¾Çå³ý°ì·¨2007-06-09 12:31ÏÖÏóÃèÊö£º¸÷¸öÓ²ÅÌ·ÖÇøÓÐÒ»¸öÎļþ¼Ðrunauto.. £¬%windows%Ŀ¼ÏÂÓÐÌØÕ÷µÄ²¡¶¾Îļþdllhost.exe Çå³ý²½Ö裺£¨ÒÔÏÂËùÓвÙ×÷ÔÚ IceSword ÖнøÐУ©Iceword v1.20ÏÂÔØ¼°¼òµ¥½éÉÜ 1¡¢½ûÖ¹½ø³Ì´´½¨¡£ 2¡¢½áÊø²¡¶¾½ø³Ì%windows%\dllhost.exe¡£ 3¡¢É¾³ý²¡¶¾Îļþ£º %windows%\dllhost.exe %windows%\cmd.exe.exe %windows%\regedit.exe.exe %windows%\setuprs1.exe x:\autorun.inf (X´ú±íÓ²Å̸÷¸ö·ÖÇø¼°UÅÌÅÌ·û) x:\autorun.inf.tmp 4¡¢É¾³ý²¡¶¾·þÎñÏ¼´É¾³ý×¢²á±íÒÔÏ·ÖÖ§£º HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\COMSystemApp ´ËÍ⣬HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List·Ö֧ϵÄ"C:\\windows\\dllhost.exe"="C:\\windows\\dllhost.exe:*:Enabled:dllhost.exe"ҲҪɾ³ý¡£ 5¡¢É¾³ý²¡¶¾Ìí¼ÓµÄIFEOÏ¼´É¾³ý×¢²á±íÒÔÏ·ÖÖ§£º HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe 6¡¢È¡ÏûIceSwordµÄ¡°½ûÖ¹½ø³Ì´´½¨¡±£¬¹Ø±ÕIceSword¡£ 7¡¢É¾³ý¸÷¸ö·ÖÇø¼°UÅÌÀïÃæµÄrunauto..Îļþ¼Ð£¬É¾³ý·½·¨£º£¨ÒÔ D ÅÌΪÀý£© ¿ªÊ¼¡ª¡ªÔËÐСª¡ªÊäÈë¡°cmd¡±¡ª¡ªÊäÈë¡°D: ¡±¡ª¡ªÊäÈë¡°rd /s/q runauto...\ ¡± 8¡¢Íê |

2Â¥2007-09-15 11:49:44
magua-no2
ľ³æ (СÓÐÃûÆø)
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ½ð±Ò: 4133.4
- Ìû×Ó: 179
- ÔÚÏß: 12.1Сʱ
- ³æºÅ: 118167
- ×¢²á: 2005-11-26
- ÐÔ±ð: GG
- רҵ: Á÷ÌåÁ¦Ñ§
4Â¥2007-09-15 12:28:53
liuwei0551
ÖÁ×ðľ³æ (ÖªÃû×÷¼Ò)
- Ó¦Öú: 29 (СѧÉú)
- ¹ó±ö: 0.355
- ½ð±Ò: 23554.4
- ºì»¨: 2
- Ìû×Ó: 7047
- ÔÚÏß: 203.7Сʱ
- ³æºÅ: 295334
- ×¢²á: 2006-11-11
- ÐÔ±ð: GG
- רҵ: ´ß»¯»¯Ñ§
6Â¥2007-09-15 15:05:37













»Ø¸´´ËÂ¥