²é¿´: 866  |  »Ø¸´: 11
µ±Ç°Ö÷ÌâÒѾ­´æµµ¡£
µ±Ç°Ö»ÏÔʾÂú×ãÖ¸¶¨Ìõ¼þµÄ»ØÌû£¬µã»÷ÕâÀï²é¿´±¾»°ÌâµÄËùÓлØÌû

immajia

ľ³æ (ÕýʽдÊÖ)

[½»Á÷] ¹ØÓÚÈðÐǵÄÎÊÌâ!(ÒÑÍê±Ï!)

ÎÒ×òÌìÏÂÔØÉý¼¶°üºó,ÓÐÒ»´ó¶Ñ²¡¶¾²»Ëµ,ÀÏÊdzöÀ´¸öIE±£»¤ºÚ°×Ãûµ¥,È¡ÏûÀÏÊdzöÀ´,µ¼³öҲûɶ¿ÉÒÔµ¼³öµÄ,ÀÏÊDZijöÀ´,ÌÖÑáËÀÁË! Äĸö³æÓѸæËß°³ÔõôȥµôÕâ¸öÆÆ¶«Î÷,ÊDz¡¶¾»¹ÊÇÉ¶ÍæÒâ°¡?
ÎÒ°ÑÈðÐÇÐ¶ÔØÁËÒ»´Î£¬ÖØÐ°²×°»¹ÊÇ´æÔÚÕâ¸öÆÆÍæÒâ,ʵÔÚû·¨×ÓÁË.
Ï£ÍûÄĸö´óϺ°ï°ïæ°É.

[ Last edited by immajia on 2007-11-21 at 13:47 ]

» ²ÂÄãϲ»¶

ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû

wood3658

½ð³æ (ÕýʽдÊÖ)

¡ï ¡ï ¡ï
immajia(½ð±Ò+3,VIP+0):Âé·³ÁË,ËäÈ»ÊǰٶȳöÀ´µÄ.
£¬ÎÒ¿´Õâ¸öÐУ¬ÎÒÒÔǰҲÖйýÕâÖÖ²¡¶¾¡£
¾­²é£¬ÕâÊÇľÂíÀûÓÃÁËÈðÐǵÄie±£»¤ºÚ°×Ãûµ¥¹¦ÄܵÄ©¶´Ê¹ÓÃÓû§ÖÐÕС£
½â¾ö·½·¨ÈçÏ£º
´Ë²¡¶¾×î½üÊ®·ÖÁ÷ÐУ¬¾¿ÆäÔ­Òò¾ÍÊÇ´ó¼Ò²»×¢ÒâÀàËÆÍ¨¹ýUÅÌ´«²¥µÄ²¡¶¾µÄ·À»¤£¬ÄÃÀ´UÅÌ£¨Òƶ¯´æ´¢£©É豸¾ÍË«»÷£¬µ¼Ö²¡¶¾Ê®·ÖÈÝÒ×µÄͨ¹ýUÅÌ´«²¥¡£
ÁíÒ»¸ö´«²¥·½Ê½¾ÍÊÇ´ò¿ªÍøÒ³Ê±µ¯³öACTIVE²å¼þ°²×°µÄ¶Ô»°¿ò£¬ÄãµãÊÇ£¬»ù±¾¾ÍÖÐÕÐÁË¡£


´Ë²¡¶¾µÄÔªÐ×Ϊauto.exe ËûÊÇÒ»¸öľÂíÏÂÔØÆ÷¡£Í¨¹ýUÅ̵ÈÒÆ¶¯´æ´¢´«²¥µ½ÄãµÄµçÄÔÖÐÒÔºó£¬ÔÚ%system32%ÏÂÃæÉú³ÉÒ»¸öËæ»ú8¸ö×ÖĸºÍÊý×Ö×éºÏ³ÉµÄexeÎļþ
²¢Í¬Ê±Éú³ÉËæ»ú8¸ö×ÖĸºÍÊý×Ö×éºÏµÄdll,ÓÉwinlogon¿ØÖƲåÈ뼸ºõËùÓнø³Ì

ÒÔÉÏÎļþ×¢²á³ÉÒ»¸ö·þÎñ£¬·þÎñÃûÎªËæ»ú8λ×ÖĸºÍÊý×Ö×éºÏµÄÃû³Æ

²¢ÔÚÿ¸ö´ÅÅ̵ĸùĿ¼ÏÂÉú³ÉÒ»¸öauto.exeºÍautorun.inf

±¾ÀýÖÐÉú³ÉÎïÈçÏ£º
C:\WINDOWS\system32\E2050308.DLL
C:\WINDOWS\system32\F2F187EC.EXE
×¢²áΪÈçÏ·þÎñ£ºB12E7AC4

Á¬½ÓÍøÂçÏÂÔØÄ¾Âí£¬Ä¾ÂíÏÂÔØµÄÖÖÀàǧ±äÍò»¯£¬ËùÒÔûÓÐÒ»¸öרÃŵIJéɱ·½·¨¡£ÕâÀïÎÒ½ö¾ÍÎÒ·¢ÏÖµÄÏÂÔØµÄһЩľÂí¾ÙÀý˵Ã÷¡£


±¾ÀýÖÐľÂíÖ²ÈëÍê±ÏÒÔºóÉú³ÉÈçÏÂÎļþ
C:\WINDOWS\system32\AVPSrv.dll
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\DbgHlp32.dll
C:\WINDOWS\system32\DiskMan32.dll
C:\WINDOWS\system32\Kvsc3.dll
C:\WINDOWS\system32\mppds.dll
C:\WINDOWS\system32\MsIMMs32.dll
C:\WINDOWS\system32\nslookupi.exe
C:\WINDOWS\system32\NVDispDrv.dll
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\system32\WinForm.dll
C:\WINDOWS\AVPSrv.exe
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\DbgHlp32.exe
C:\WINDOWS\DiskMan32.exe
C:\WINDOWS\Kvsc3.exe
C:\WINDOWS\mppds.exe
C:\WINDOWS\MsIMMs32.exe
C:\WINDOWS\NVDispDrv.exe
C:\WINDOWS\upxdnd.exe
C:\WINDOWS\WinForm.exe
...

¶ÔÓ¦µÄsrengÈÕÖ¾ÈçÏ£º
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
[]
[]
[]
[]
[]
[]
[]
[]
[]
[]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
[N/A]
[N/A]
[N/A]
[N/A]
[N/A]
[N/A]
[N/A]
==================================
·þÎñ
[B12E7AC4 / B12E7AC4][Stopped/Auto Start]

==================================
ÕýÔÚÔËÐеĽø³Ì
[PID: 1672][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DiskMan32.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[C:\WINDOWS\system32\WinForm.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\WINDOWS\system32\E2050308.DLL] [Microsoft Corporation, ]
==================================
Autorun.inf
[C:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
[D:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
[E:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe


²éɱ·½·¨£º
Ò».Çå³ý²¡¶¾Ö÷³ÌÐò£¨Ëæ»ú8λ×ÖĸºÍÊý×Ö×éºÏµÄexeºÍdll£©
±ØÐëÊ×ÏÈÇå³ýauto.exeºÍÆäÉú³ÉµÄËæ»ú8λ×ÖĸºÍÊý×Ö×éºÏµÄexeºÍdll£¬ÒòΪËûÊÇľÂíȺµÄÍò¶ñÖ®Ô´£¡£¡
1.Ê×ÏÈÏÂÔØsrengÕâ¸öÈí¼þ£¨http://download.kztechs.com/files/sreng2.zip£©
½âѹËõºóÔËÐÐsrengps.exe
ÒÀ´Îµã»÷¡°Æô¶¯ÏîÄ¿¡±-¡°·þÎñ¡±-¡°Win32·þÎñÓ¦ÓóÌÐò¡± Ö®ºó¹´Ñ¡¡°Òþ²Ø¾­ÈÏÖ¤µÄ΢ÈíÏîÄ¿¡±
µÈ´ýÁбí³öÀ´Ö®ºó ²éÕÒÄÇÖÖ²»¹æÔòµÄËæ»ú8λ×Öĸ£¨´óд£©ºÍÊý×Ö×éºÏµÄ·þÎñ
È»ºóÑ¡ÖÐÏÂÃæµÄ ¡°É¾³ý·þÎñ¡± ²¢µ¥»÷ÉèÖð´Å¥
ÔÚµ¯³öµÄ¿òÖе㡰·ñ¡±
2.ÖØÆô¼ÆËã»ú½øÈ밲ȫģʽÏÂ

°ÑÏÂÃæµÄ´úÂ뿽Èë¼Çʱ¾ÖÐÈ»ºóÁí´æÎª1.regÎļþ
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"RegPath"="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced"
"Text"="@shell32.dll,-30500"
"Type"="radio"
"CheckedValue"=dword:00000001
"ValueName"="Hidden"
"DefaultValue"=dword:00000002
"HKeyRoot"=dword:80000001
"HelpID"="shell.hlp#51105"

Ë«»÷1.reg°ÑÕâ¸ö×¢²á±íÏîµ¼Èë

Ë«»÷ÎҵĵçÄÔ£¬¹¤¾ß£¬Îļþ¼ÐÑ¡Ï²é¿´£¬µ¥»÷ѡȡ"ÏÔʾÒþ²ØÎļþ»òÎļþ¼Ð" ²¢Çå³ý"Òþ²ØÊܱ£»¤µÄ²Ù×÷ϵͳÎļþ£¨ÍƼö£©"Ç°ÃæµÄ¹³¡£ÔÚÌáʾȷ¶¨¸ü¸Äʱ£¬µ¥»÷¡°ÊÇ¡± È»ºóÈ·¶¨
µã»÷ ²Ëµ¥À¸Ï·½µÄ Îļþ¼Ð°´Å¥£¨ËÑË÷Óұߵİ´Å¥£©
ɾ³ýÈçÏÂÎļþ
C:\auto.exe
C:\autorun.inf
ÒÔ¼°Ã¿¸ö·ÖÇøÏÂÃæµÄauto.exeºÍautorun.inf

%system32%Îļþ¼ÐϵÄËæ»ú8¸ö×ÖĸºÍÊý×Ö×éºÏµÄexeºÍdll
¼´±¾ÀýÖеÄC:\WINDOWS\system32\E2050308.DLL
C:\WINDOWS\system32\F2F187EC.EXE

ÖÁ´Ë²¡¶¾Ö÷³ÌÐòÒѾ­±»É¾³ýÁË£¬½ÓÏÂÀ´Çå³ýÆäÏÂÔØµÄľÂí

¶þ.Çå³ý²¡¶¾ÏÂÔØµÄľÂí£¨ÓÉÓÚÿ¸ö±äÖÖÏÂÔØµÄľÂí²»¾¡Ïàͬ£¬Òò´Ë±¾Àý½ö¹©²Î¿¼£©
»¹ÊÇÔÚ°²È«Ä£Ê½ÏÂ
´ò¿ªsreng
Æô¶¯ÏîÄ¿ ×¢²á±í ɾ³ýÈçÏÂÏîÄ¿
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
[]
[]
[]
[]
[]
[]
[]
[]
[]
[]
[]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
[N/A]
[N/A]
[N/A]
[N/A]
[N/A]
[N/A]
[N/A]

Ë«»÷ÎҵĵçÄÔ£¬¹¤¾ß£¬Îļþ¼ÐÑ¡Ï²é¿´£¬µ¥»÷ѡȡ"ÏÔʾÒþ²ØÎļþ»òÎļþ¼Ð" ²¢Çå³ý"Òþ²ØÊܱ£»¤µÄ²Ù×÷ϵͳÎļþ£¨ÍƼö£©"Ç°ÃæµÄ¹³¡£ÔÚÌáʾȷ¶¨¸ü¸Äʱ£¬µ¥»÷¡°ÊÇ¡± È»ºóÈ·¶¨
µã»÷ ²Ëµ¥À¸Ï·½µÄ Îļþ¼Ð°´Å¥£¨ËÑË÷Óұߵİ´Å¥£©
ÔÚ×ó±ßµÄ×ÊÔ´¹ÜÀíÆ÷Öдò¿ªCÅÌ£¨ÏµÍ³ÅÌ£©
ɾ³ýÈçÏÂÎļþ
C:\WINDOWS\mppds.exe
C:\WINDOWS\Kvsc3.exe
C:\WINDOWS\kterzx.exe
C:\WINDOWS\WinForm.exe
C:\WINDOWS\AVPSrv.exe
C:\WINDOWS\MsIMMs32.exe
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\DbgHlp32.exe
C:\WINDOWS\upxdnd.exe
C:\WINDOWS\kterzx.exe
C:\WINDOWS\system32\mppds.dll
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\system32\AVPSrv.dll
C:\WINDOWS\system32\DiskMan32.dll
C:\WINDOWS\system32\NVDispDrv.dll
C:\WINDOWS\system32\MsIMMs32.dll
C:\WINDOWS\system32\WinForm.dll
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\DbgHlp32.dll
C:\WINDOWS\system32\Kvsc3.dll
3Â¥2007-11-21 09:29:43
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû
²é¿´È«²¿ 12 ¸ö»Ø´ð

daixj21

ľ³æ (ÖªÃû×÷¼Ò)

Сľ³æË°Îñ×ܾ־ֳ¤¡ª¡ªË®³æ

¡ï
immajia(½ð±Ò+1,VIP+0):лл²ÎÓë!
Ó¦¸ÃÊDz¡¶¾°É£¬ÏÂÒ»¸ö½­ÃñµÄɱɱ¶¾ÔÙ˵£¬ÎÒ¾õµÃÈðÐDz»ÔõôÑù
×Ô¾õÄÉ˰¹âÈÙ͵˰©˰¿É³Ü.............¡ª¡ªÄ¾³æË°Îñ¾Ö
2Â¥2007-11-21 09:25:54
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû

renchao2001yh

ľ³æ (ÕýʽдÊÖ)

ÊDz»Êǵ¯³ö¸öÌáʾ˵Êܱ£»¤Ê²Ã´µÄ£¿ÄÇÄãÉèÖÃÒ»ÏÂÈðÐÇIEÑ¡Ïî¹À¼Æ¾Í³É¡£
×÷ѧÎÊÀÏʵµãºÃ£¬×÷ʵÑéÈÏÕæµãºÃ£¬×öÈË̤ʵµãºÃ¡£
4Â¥2007-11-21 09:30:23
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû

immajia

ľ³æ (ÕýʽдÊÖ)

ÊÇÖж¾ÁËÂð?2Â¥µÄÎÒÔõôÕÒ²»µ½Äã˵µÄÄÇÐ©Ëæ»ú8λ×ÖĸºÍÊý×Ö×éºÏµÄexeºÍdll·þÎñ°¡?
5Â¥2007-11-21 10:00:01
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû
×î¾ßÈËÆøÈÈÌûÍÆ¼ö [²é¿´È«²¿] ×÷Õß »Ø/¿´ ×îºó·¢±í
[¿¼ÑÐ] 291 Çóµ÷¼Á +4 »¯¹¤2026½ì±ÏÒµÉ 2026-03-21 4/200 2026-03-23 09:59 by bingchuan
[¿¼ÑÐ] 0854µç×ÓÐÅÏ¢Çóµ÷¼Á +3 ¦Á____ 2026-03-22 3/150 2026-03-22 21:28 by zhq0425
[¿¼ÑÐ] 328Çóµ÷¼Á£¬Ó¢ÓïÁù¼¶551£¬ÓпÆÑо­Àú +6 ÉúÎ﹤³Ìµ÷¼Á 2026-03-17 10/500 2026-03-22 20:22 by edmund7
[¿¼ÑÐ] 310Çóµ÷¼Á +4 baibai1314 2026-03-16 4/200 2026-03-22 20:19 by edmund7
[¿¼ÑÐ] 324Çóµ÷¼Á +6 luckyѽѽѽѼ 2026-03-20 6/300 2026-03-22 16:01 by ColorlessPI
[¿¼ÑÐ] Ò»Ö¾Ô¸ Î÷±±´óѧ £¬070300»¯Ñ§Ñ§Ë¶£¬×Ü·Ö287£¬Ë«·ÇÒ»±¾£¬Çóµ÷¼Á¡£ +3 ³¿»èÏßÓëÐǺ£ 2026-03-20 3/150 2026-03-22 16:00 by ColorlessPI
[¿¼ÑÐ] Çóµ÷¼Á +7 Auroracx 2026-03-22 7/350 2026-03-22 12:38 by ËØÑÕÇã³Ç1988
[¿¼ÑÐ] ÉúÎïѧһ־Ը985£¬·ÖÊý349Çóµ÷¼Á +4 zxts12 2026-03-21 7/350 2026-03-22 09:57 by zxts12
[¿¼ÑÐ] »¯Ñ§µ÷¼Á +5 yzysaa 2026-03-21 5/250 2026-03-21 22:12 by peike
[¿¼ÑÐ] 0805 316Çóµ÷¼Á +3 ´óÑ©Éî²Ø 2026-03-18 3/150 2026-03-21 18:55 by ѧԱ8dgXkO
[¿¼ÑÐ] ²ÄÁÏѧ˶333Çóµ÷¼Á +3 ±±µÀÏï 2026-03-18 3/150 2026-03-21 18:17 by ѧԱ8dgXkO
[¿¼ÑÐ] 311Çóµ÷¼Á +3 Ó¸ҵÄСÎâ 2026-03-20 3/150 2026-03-21 17:40 by ColorlessPI
[¿¼ÑÐ] Çóµ÷¼Á +3 .m.. 2026-03-21 4/200 2026-03-21 16:25 by barlinike
[¿¼ÑÐ] Äϲý´óѧ²ÄÁÏר˶311·ÖÇóµ÷¼Á +6 77chaselx 2026-03-20 6/300 2026-03-21 07:24 by JourneyLucky
[¿¼ÑÐ] ÄϾ©´óѧ»¯Ñ§376Çóµ÷¼Á +3 hisfailed 2026-03-19 6/300 2026-03-20 23:43 by hisfailed
[¿¼ÑÐ] ²ÄÁÏÓ뻯¹¤ 322Çóµ÷¼Á +4 È»11 2026-03-19 4/200 2026-03-20 22:12 by luoyongfeng
[¿¼ÑÐ] Ò»Ö¾Ô¸¼ªÁÖ´óѧ²ÄÁÏѧ˶321Çóµ÷¼Á +11 Ymlll 2026-03-18 15/750 2026-03-20 19:40 by ¶¡¶¡*
[¿¼ÑÐ] ²ÄÁÏÓ뻯¹¤×¨Ë¶µ÷¼Á +7 heming3743 2026-03-16 7/350 2026-03-20 19:31 by zhukairuo
[¿¼ÑÐ] 086500 325 Çóµ÷¼Á +3 Áì´øÐ¡ÐÜ 2026-03-19 3/150 2026-03-20 18:38 by ¾¡Ë´Ò¢1
[¿¼ÑÐ] 0703»¯Ñ§µ÷¼Á +3 ÄÝÄÝninicgb 2026-03-17 3/150 2026-03-18 10:29 by macy2011
ÐÅÏ¢Ìáʾ
ÇëÌî´¦ÀíÒâ¼û