| ²é¿´: 858 | »Ø¸´: 11 | |||
| µ±Ç°Ö÷ÌâÒѾ´æµµ¡£ | |||
| µ±Ç°Ö»ÏÔʾÂú×ãÖ¸¶¨Ìõ¼þµÄ»ØÌû£¬µã»÷ÕâÀï²é¿´±¾»°ÌâµÄËùÓлØÌû | |||
immajiaľ³æ (ÕýʽдÊÖ)
|
[½»Á÷]
¹ØÓÚÈðÐǵÄÎÊÌâ!(ÒÑÍê±Ï!)
|
||
|
ÎÒ×òÌìÏÂÔØÉý¼¶°üºó,ÓÐÒ»´ó¶Ñ²¡¶¾²»Ëµ,ÀÏÊdzöÀ´¸öIE±£»¤ºÚ°×Ãûµ¥,È¡ÏûÀÏÊdzöÀ´,µ¼³öҲûɶ¿ÉÒÔµ¼³öµÄ,ÀÏÊDZijöÀ´,ÌÖÑáËÀÁË! Äĸö³æÓѸæËß°³ÔõôȥµôÕâ¸öÆÆ¶«Î÷,ÊDz¡¶¾»¹ÊÇÉ¶ÍæÒâ°¡? ÎÒ°ÑÈðÐÇÐ¶ÔØÁËÒ»´Î£¬ÖØÐ°²×°»¹ÊÇ´æÔÚÕâ¸öÆÆÍæÒâ,ʵÔÚû·¨×ÓÁË. Ï£ÍûÄĸö´óϺ°ï°ïæ°É. [ Last edited by immajia on 2007-11-21 at 13:47 ] |
» ²ÂÄãϲ»¶
Ò»Ö¾Ô¸070300Õã´ó»¯Ñ§358·Ö£¬Çóµ÷¼Á£¡
ÒѾÓÐ4È˻ظ´
Ò»Ö¾Ô¸ÖÐÄÏ´óѧ»¯Ñ§Ñ§Ë¶0703×Ü·Ö337Çóµ÷¼Á
ÒѾÓÐ4È˻ظ´
Ò»Ö¾Ô¸±±¾©»¯¹¤´óѧ 070300 ѧ˶ 336·Ö Çóµ÷¼Á
ÒѾÓÐ5È˻ظ´
323Çóµ÷¼Á
ÒѾÓÐ6È˻ظ´
352Çóµ÷¼Á
ÒѾÓÐ3È˻ظ´
Ò»Ö¾Ô¸¶«»ª´óѧ»¯Ñ§070300£¬Çóµ÷¼Á
ÒѾÓÐ8È˻ظ´
277²ÄÁÏ¿ÆÑ§Ó빤³Ì080500Çóµ÷¼Á
ÒѾÓÐ7È˻ظ´
317Çóµ÷¼Á
ÒѾÓÐ18È˻ظ´
293Çóµ÷¼Á
ÒѾÓÐ5È˻ظ´
280·ÖÇóµ÷¼Á Ò»Ö¾Ô¸085802
ÒѾÓÐ7È˻ظ´
renchao2001yh
ľ³æ (ÕýʽдÊÖ)
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ½ð±Ò: 3468.2
- É¢½ð: 2530
- ºì»¨: 5
- ɳ·¢: 1
- Ìû×Ó: 909
- ÔÚÏß: 161.3Сʱ
- ³æºÅ: 441037
- ×¢²á: 2007-10-27
- ÐÔ±ð: GG
- רҵ: µç»¯Ñ§

4Â¥2007-11-21 09:30:23
daixj21
ľ³æ (ÖªÃû×÷¼Ò)
Сľ³æË°Îñ×ܾ־ֳ¤¡ª¡ªË®³æ
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ¹ó±ö: 0.01
- ½ð±Ò: 3143.4
- É¢½ð: 742
- ºì»¨: 9
- ɳ·¢: 9
- Ìû×Ó: 8361
- ÔÚÏß: 304Сʱ
- ³æºÅ: 447796
- ×¢²á: 2007-11-01
- ÐÔ±ð: GG
- רҵ: ¾ÛºÏÎï¹²»ìÓ븴ºÏ²ÄÁÏ

2Â¥2007-11-21 09:25:54
wood3658
½ð³æ (ÕýʽдÊÖ)
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ½ð±Ò: 995.6
- É¢½ð: 10
- ºì»¨: 1
- Ìû×Ó: 337
- ÔÚÏß: 88.6Сʱ
- ³æºÅ: 349663
- ×¢²á: 2007-04-20
- ÐÔ±ð: GG
- רҵ: ÎÞ»ú²ÄÁÏ»¯Ñ§
¡ï ¡ï ¡ï
immajia(½ð±Ò+3,VIP+0):Âé·³ÁË,ËäÈ»ÊǰٶȳöÀ´µÄ.
immajia(½ð±Ò+3,VIP+0):Âé·³ÁË,ËäÈ»ÊǰٶȳöÀ´µÄ.
£¬ÎÒ¿´Õâ¸öÐУ¬ÎÒÒÔǰҲÖйýÕâÖÖ²¡¶¾¡£¾²é£¬ÕâÊÇľÂíÀûÓÃÁËÈðÐǵÄie±£»¤ºÚ°×Ãûµ¥¹¦ÄܵÄ©¶´Ê¹ÓÃÓû§ÖÐÕС£ ½â¾ö·½·¨ÈçÏ£º ´Ë²¡¶¾×î½üÊ®·ÖÁ÷ÐУ¬¾¿ÆäÔÒò¾ÍÊÇ´ó¼Ò²»×¢ÒâÀàËÆÍ¨¹ýUÅÌ´«²¥µÄ²¡¶¾µÄ·À»¤£¬ÄÃÀ´UÅÌ£¨Òƶ¯´æ´¢£©É豸¾ÍË«»÷£¬µ¼Ö²¡¶¾Ê®·ÖÈÝÒ×µÄͨ¹ýUÅÌ´«²¥¡£ ÁíÒ»¸ö´«²¥·½Ê½¾ÍÊÇ´ò¿ªÍøÒ³Ê±µ¯³öACTIVE²å¼þ°²×°µÄ¶Ô»°¿ò£¬ÄãµãÊÇ£¬»ù±¾¾ÍÖÐÕÐÁË¡£ ´Ë²¡¶¾µÄÔªÐ×Ϊauto.exe ËûÊÇÒ»¸öľÂíÏÂÔØÆ÷¡£Í¨¹ýUÅ̵ÈÒÆ¶¯´æ´¢´«²¥µ½ÄãµÄµçÄÔÖÐÒÔºó£¬ÔÚ%system32%ÏÂÃæÉú³ÉÒ»¸öËæ»ú8¸ö×ÖĸºÍÊý×Ö×éºÏ³ÉµÄexeÎļþ ²¢Í¬Ê±Éú³ÉËæ»ú8¸ö×ÖĸºÍÊý×Ö×éºÏµÄdll,ÓÉwinlogon¿ØÖƲåÈ뼸ºõËùÓнø³Ì ÒÔÉÏÎļþ×¢²á³ÉÒ»¸ö·þÎñ£¬·þÎñÃûÎªËæ»ú8λ×ÖĸºÍÊý×Ö×éºÏµÄÃû³Æ ²¢ÔÚÿ¸ö´ÅÅ̵ĸùĿ¼ÏÂÉú³ÉÒ»¸öauto.exeºÍautorun.inf ±¾ÀýÖÐÉú³ÉÎïÈçÏ£º C:\WINDOWS\system32\E2050308.DLL C:\WINDOWS\system32\F2F187EC.EXE ×¢²áΪÈçÏ·þÎñ£ºB12E7AC4 Á¬½ÓÍøÂçÏÂÔØÄ¾Âí£¬Ä¾ÂíÏÂÔØµÄÖÖÀàǧ±äÍò»¯£¬ËùÒÔûÓÐÒ»¸öרÃŵIJéɱ·½·¨¡£ÕâÀïÎÒ½ö¾ÍÎÒ·¢ÏÖµÄÏÂÔØµÄһЩľÂí¾ÙÀý˵Ã÷¡£ ±¾ÀýÖÐľÂíÖ²ÈëÍê±ÏÒÔºóÉú³ÉÈçÏÂÎļþ C:\WINDOWS\system32\AVPSrv.dll C:\WINDOWS\system32\cmdbcs.dll C:\WINDOWS\system32\DbgHlp32.dll C:\WINDOWS\system32\DiskMan32.dll C:\WINDOWS\system32\Kvsc3.dll C:\WINDOWS\system32\mppds.dll C:\WINDOWS\system32\MsIMMs32.dll C:\WINDOWS\system32\nslookupi.exe C:\WINDOWS\system32\NVDispDrv.dll C:\WINDOWS\system32\upxdnd.dll C:\WINDOWS\system32\WinForm.dll C:\WINDOWS\AVPSrv.exe C:\WINDOWS\cmdbcs.exe C:\WINDOWS\DbgHlp32.exe C:\WINDOWS\DiskMan32.exe C:\WINDOWS\Kvsc3.exe C:\WINDOWS\mppds.exe C:\WINDOWS\MsIMMs32.exe C:\WINDOWS\NVDispDrv.exe C:\WINDOWS\upxdnd.exe C:\WINDOWS\WinForm.exe ... ¶ÔÓ¦µÄsrengÈÕÖ¾ÈçÏ£º [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] ================================== ·þÎñ [B12E7AC4 / B12E7AC4][Stopped/Auto Start] ================================== ÕýÔÚÔËÐеĽø³Ì [PID: 1672][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\mppds.dll] [N/A, ] [C:\WINDOWS\system32\upxdnd.dll] [N/A, ] [C:\WINDOWS\system32\AVPSrv.dll] [N/A, ] [C:\WINDOWS\system32\DiskMan32.dll] [N/A, ] [C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ] [C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ] [C:\WINDOWS\system32\WinForm.dll] [N/A, ] [C:\WINDOWS\system32\cmdbcs.dll] [N/A, ] [C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ] [C:\WINDOWS\system32\Kvsc3.dll] [N/A, ] [C:\WINDOWS\system32\E2050308.DLL] [Microsoft Corporation, ] ================================== Autorun.inf [C:\] [AutoRun] open=auto.exe shellexecute=auto.exe shell\Auto\command=auto.exe [D:\] [AutoRun] open=auto.exe shellexecute=auto.exe shell\Auto\command=auto.exe [E:\] [AutoRun] open=auto.exe shellexecute=auto.exe shell\Auto\command=auto.exe ²éɱ·½·¨£º Ò».Çå³ý²¡¶¾Ö÷³ÌÐò£¨Ëæ»ú8λ×ÖĸºÍÊý×Ö×éºÏµÄexeºÍdll£© ±ØÐëÊ×ÏÈÇå³ýauto.exeºÍÆäÉú³ÉµÄËæ»ú8λ×ÖĸºÍÊý×Ö×éºÏµÄexeºÍdll£¬ÒòΪËûÊÇľÂíȺµÄÍò¶ñÖ®Ô´£¡£¡ 1.Ê×ÏÈÏÂÔØsrengÕâ¸öÈí¼þ£¨http://download.kztechs.com/files/sreng2.zip£© ½âѹËõºóÔËÐÐsrengps.exe ÒÀ´Îµã»÷¡°Æô¶¯ÏîÄ¿¡±-¡°·þÎñ¡±-¡°Win32·þÎñÓ¦ÓóÌÐò¡± Ö®ºó¹´Ñ¡¡°Òþ²Ø¾ÈÏÖ¤µÄ΢ÈíÏîÄ¿¡± µÈ´ýÁбí³öÀ´Ö®ºó ²éÕÒÄÇÖÖ²»¹æÔòµÄËæ»ú8λ×Öĸ£¨´óд£©ºÍÊý×Ö×éºÏµÄ·þÎñ È»ºóÑ¡ÖÐÏÂÃæµÄ ¡°É¾³ý·þÎñ¡± ²¢µ¥»÷ÉèÖð´Å¥ ÔÚµ¯³öµÄ¿òÖе㡰·ñ¡± 2.ÖØÆô¼ÆËã»ú½øÈ밲ȫģʽÏ °ÑÏÂÃæµÄ´úÂ뿽Èë¼Çʱ¾ÖÐÈ»ºóÁí´æÎª1.regÎļþ Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "RegPath"="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced" "Text"="@shell32.dll,-30500" "Type"="radio" "CheckedValue"=dword:00000001 "ValueName"="Hidden" "DefaultValue"=dword:00000002 "HKeyRoot"=dword:80000001 "HelpID"="shell.hlp#51105" Ë«»÷1.reg°ÑÕâ¸ö×¢²á±íÏîµ¼Èë Ë«»÷ÎҵĵçÄÔ£¬¹¤¾ß£¬Îļþ¼ÐÑ¡Ï²é¿´£¬µ¥»÷ѡȡ"ÏÔʾÒþ²ØÎļþ»òÎļþ¼Ð" ²¢Çå³ý"Òþ²ØÊܱ£»¤µÄ²Ù×÷ϵͳÎļþ£¨ÍƼö£©"Ç°ÃæµÄ¹³¡£ÔÚÌáʾȷ¶¨¸ü¸Äʱ£¬µ¥»÷¡°ÊÇ¡± È»ºóÈ·¶¨ µã»÷ ²Ëµ¥À¸Ï·½µÄ Îļþ¼Ð°´Å¥£¨ËÑË÷Óұߵİ´Å¥£© ɾ³ýÈçÏÂÎļþ C:\auto.exe C:\autorun.inf ÒÔ¼°Ã¿¸ö·ÖÇøÏÂÃæµÄauto.exeºÍautorun.inf %system32%Îļþ¼ÐϵÄËæ»ú8¸ö×ÖĸºÍÊý×Ö×éºÏµÄexeºÍdll ¼´±¾ÀýÖеÄC:\WINDOWS\system32\E2050308.DLL C:\WINDOWS\system32\F2F187EC.EXE ÖÁ´Ë²¡¶¾Ö÷³ÌÐòÒѾ±»É¾³ýÁË£¬½ÓÏÂÀ´Çå³ýÆäÏÂÔØµÄľÂí ¶þ.Çå³ý²¡¶¾ÏÂÔØµÄľÂí£¨ÓÉÓÚÿ¸ö±äÖÖÏÂÔØµÄľÂí²»¾¡Ïàͬ£¬Òò´Ë±¾Àý½ö¹©²Î¿¼£© »¹ÊÇÔÚ°²È«Ä£Ê½Ï ´ò¿ªsreng Æô¶¯ÏîÄ¿ ×¢²á±í ɾ³ýÈçÏÂÏîÄ¿ [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] Ë«»÷ÎҵĵçÄÔ£¬¹¤¾ß£¬Îļþ¼ÐÑ¡Ï²é¿´£¬µ¥»÷ѡȡ"ÏÔʾÒþ²ØÎļþ»òÎļþ¼Ð" ²¢Çå³ý"Òþ²ØÊܱ£»¤µÄ²Ù×÷ϵͳÎļþ£¨ÍƼö£©"Ç°ÃæµÄ¹³¡£ÔÚÌáʾȷ¶¨¸ü¸Äʱ£¬µ¥»÷¡°ÊÇ¡± È»ºóÈ·¶¨ µã»÷ ²Ëµ¥À¸Ï·½µÄ Îļþ¼Ð°´Å¥£¨ËÑË÷Óұߵİ´Å¥£© ÔÚ×ó±ßµÄ×ÊÔ´¹ÜÀíÆ÷Öдò¿ªCÅÌ£¨ÏµÍ³ÅÌ£© ɾ³ýÈçÏÂÎļþ C:\WINDOWS\mppds.exe C:\WINDOWS\Kvsc3.exe C:\WINDOWS\kterzx.exe C:\WINDOWS\WinForm.exe C:\WINDOWS\AVPSrv.exe C:\WINDOWS\MsIMMs32.exe C:\WINDOWS\cmdbcs.exe C:\WINDOWS\DbgHlp32.exe C:\WINDOWS\upxdnd.exe C:\WINDOWS\kterzx.exe C:\WINDOWS\system32\mppds.dll C:\WINDOWS\system32\upxdnd.dll C:\WINDOWS\system32\AVPSrv.dll C:\WINDOWS\system32\DiskMan32.dll C:\WINDOWS\system32\NVDispDrv.dll C:\WINDOWS\system32\MsIMMs32.dll C:\WINDOWS\system32\WinForm.dll C:\WINDOWS\system32\cmdbcs.dll C:\WINDOWS\system32\DbgHlp32.dll C:\WINDOWS\system32\Kvsc3.dll |
3Â¥2007-11-21 09:29:43
immajia
ľ³æ (ÕýʽдÊÖ)
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ½ð±Ò: 1492.5
- Ìû×Ó: 793
- ÔÚÏß: 43.2Сʱ
- ³æºÅ: 322247
- ×¢²á: 2007-03-11
- ÐÔ±ð: GG
- רҵ: ÓлúºÏ³É
5Â¥2007-11-21 10:00:01













»Ø¸´´ËÂ¥
£¬ÎÒ¿´Õâ¸öÐУ¬ÎÒÒÔǰҲÖйýÕâÖÖ²¡¶¾¡£