²é¿´: 869  |  »Ø¸´: 11
µ±Ç°Ö÷ÌâÒѾ­´æµµ¡£
µ±Ç°Ö»ÏÔʾÂú×ãÖ¸¶¨Ìõ¼þµÄ»ØÌû£¬µã»÷ÕâÀï²é¿´±¾»°ÌâµÄËùÓлØÌû

immajia

ľ³æ (ÕýʽдÊÖ)

[½»Á÷] ¹ØÓÚÈðÐǵÄÎÊÌâ!(ÒÑÍê±Ï!)

ÎÒ×òÌìÏÂÔØÉý¼¶°üºó,ÓÐÒ»´ó¶Ñ²¡¶¾²»Ëµ,ÀÏÊdzöÀ´¸öIE±£»¤ºÚ°×Ãûµ¥,È¡ÏûÀÏÊdzöÀ´,µ¼³öҲûɶ¿ÉÒÔµ¼³öµÄ,ÀÏÊDZijöÀ´,ÌÖÑáËÀÁË! Äĸö³æÓѸæËß°³ÔõôȥµôÕâ¸öÆÆ¶«Î÷,ÊDz¡¶¾»¹ÊÇÉ¶ÍæÒâ°¡?
ÎÒ°ÑÈðÐÇÐ¶ÔØÁËÒ»´Î£¬ÖØÐ°²×°»¹ÊÇ´æÔÚÕâ¸öÆÆÍæÒâ,ʵÔÚû·¨×ÓÁË.
Ï£ÍûÄĸö´óϺ°ï°ïæ°É.

[ Last edited by immajia on 2007-11-21 at 13:47 ]
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû

siriuschongyang

¾èÖú¹ó±ö (СÓÐÃûÆø)

Çå¿ÕIEÁÙʱÎļþ£¬cookies
Éý¼¶ÄãµÄɱ¶¾Èí¼þ£¬ÖØÆð¼ÆËã»úÈ»ºóµ½°²È«Ä£Ê½Ï½øÐÐÒ»´ÎÈ«ÅÌɱ¶¾£¬Ò»°ãµÄľÂí¶¼ÊÇ¿ÉÒÔÇå³ýµôµÄ
9Â¥2007-11-21 11:14:12
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû
²é¿´È«²¿ 12 ¸ö»Ø´ð

daixj21

ľ³æ (ÖªÃû×÷¼Ò)

Сľ³æË°Îñ×ܾ־ֳ¤¡ª¡ªË®³æ

¡ï
immajia(½ð±Ò+1,VIP+0):лл²ÎÓë!
Ó¦¸ÃÊDz¡¶¾°É£¬ÏÂÒ»¸ö½­ÃñµÄɱɱ¶¾ÔÙ˵£¬ÎÒ¾õµÃÈðÐDz»ÔõôÑù
×Ô¾õÄÉ˰¹âÈÙ͵˰©˰¿É³Ü.............¡ª¡ªÄ¾³æË°Îñ¾Ö
2Â¥2007-11-21 09:25:54
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû

wood3658

½ð³æ (ÕýʽдÊÖ)

¡ï ¡ï ¡ï
immajia(½ð±Ò+3,VIP+0):Âé·³ÁË,ËäÈ»ÊǰٶȳöÀ´µÄ.
£¬ÎÒ¿´Õâ¸öÐУ¬ÎÒÒÔǰҲÖйýÕâÖÖ²¡¶¾¡£
¾­²é£¬ÕâÊÇľÂíÀûÓÃÁËÈðÐǵÄie±£»¤ºÚ°×Ãûµ¥¹¦ÄܵÄ©¶´Ê¹ÓÃÓû§ÖÐÕС£
½â¾ö·½·¨ÈçÏ£º
´Ë²¡¶¾×î½üÊ®·ÖÁ÷ÐУ¬¾¿ÆäÔ­Òò¾ÍÊÇ´ó¼Ò²»×¢ÒâÀàËÆÍ¨¹ýUÅÌ´«²¥µÄ²¡¶¾µÄ·À»¤£¬ÄÃÀ´UÅÌ£¨Òƶ¯´æ´¢£©É豸¾ÍË«»÷£¬µ¼Ö²¡¶¾Ê®·ÖÈÝÒ×µÄͨ¹ýUÅÌ´«²¥¡£
ÁíÒ»¸ö´«²¥·½Ê½¾ÍÊÇ´ò¿ªÍøÒ³Ê±µ¯³öACTIVE²å¼þ°²×°µÄ¶Ô»°¿ò£¬ÄãµãÊÇ£¬»ù±¾¾ÍÖÐÕÐÁË¡£


´Ë²¡¶¾µÄÔªÐ×Ϊauto.exe ËûÊÇÒ»¸öľÂíÏÂÔØÆ÷¡£Í¨¹ýUÅ̵ÈÒÆ¶¯´æ´¢´«²¥µ½ÄãµÄµçÄÔÖÐÒÔºó£¬ÔÚ%system32%ÏÂÃæÉú³ÉÒ»¸öËæ»ú8¸ö×ÖĸºÍÊý×Ö×éºÏ³ÉµÄexeÎļþ
²¢Í¬Ê±Éú³ÉËæ»ú8¸ö×ÖĸºÍÊý×Ö×éºÏµÄdll,ÓÉwinlogon¿ØÖƲåÈ뼸ºõËùÓнø³Ì

ÒÔÉÏÎļþ×¢²á³ÉÒ»¸ö·þÎñ£¬·þÎñÃûÎªËæ»ú8λ×ÖĸºÍÊý×Ö×éºÏµÄÃû³Æ

²¢ÔÚÿ¸ö´ÅÅ̵ĸùĿ¼ÏÂÉú³ÉÒ»¸öauto.exeºÍautorun.inf

±¾ÀýÖÐÉú³ÉÎïÈçÏ£º
C:\WINDOWS\system32\E2050308.DLL
C:\WINDOWS\system32\F2F187EC.EXE
×¢²áΪÈçÏ·þÎñ£ºB12E7AC4

Á¬½ÓÍøÂçÏÂÔØÄ¾Âí£¬Ä¾ÂíÏÂÔØµÄÖÖÀàǧ±äÍò»¯£¬ËùÒÔûÓÐÒ»¸öרÃŵIJéɱ·½·¨¡£ÕâÀïÎÒ½ö¾ÍÎÒ·¢ÏÖµÄÏÂÔØµÄһЩľÂí¾ÙÀý˵Ã÷¡£


±¾ÀýÖÐľÂíÖ²ÈëÍê±ÏÒÔºóÉú³ÉÈçÏÂÎļþ
C:\WINDOWS\system32\AVPSrv.dll
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\DbgHlp32.dll
C:\WINDOWS\system32\DiskMan32.dll
C:\WINDOWS\system32\Kvsc3.dll
C:\WINDOWS\system32\mppds.dll
C:\WINDOWS\system32\MsIMMs32.dll
C:\WINDOWS\system32\nslookupi.exe
C:\WINDOWS\system32\NVDispDrv.dll
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\system32\WinForm.dll
C:\WINDOWS\AVPSrv.exe
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\DbgHlp32.exe
C:\WINDOWS\DiskMan32.exe
C:\WINDOWS\Kvsc3.exe
C:\WINDOWS\mppds.exe
C:\WINDOWS\MsIMMs32.exe
C:\WINDOWS\NVDispDrv.exe
C:\WINDOWS\upxdnd.exe
C:\WINDOWS\WinForm.exe
...

¶ÔÓ¦µÄsrengÈÕÖ¾ÈçÏ£º
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
[]
[]
[]
[]
[]
[]
[]
[]
[]
[]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
[N/A]
[N/A]
[N/A]
[N/A]
[N/A]
[N/A]
[N/A]
==================================
·þÎñ
[B12E7AC4 / B12E7AC4][Stopped/Auto Start]

==================================
ÕýÔÚÔËÐеĽø³Ì
[PID: 1672][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\WINDOWS\system32\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\AVPSrv.dll] [N/A, ]
[C:\WINDOWS\system32\DiskMan32.dll] [N/A, ]
[C:\WINDOWS\system32\NVDispDrv.dll] [N/A, ]
[C:\WINDOWS\system32\MsIMMs32.dll] [N/A, ]
[C:\WINDOWS\system32\WinForm.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\DbgHlp32.dll] [N/A, ]
[C:\WINDOWS\system32\Kvsc3.dll] [N/A, ]
[C:\WINDOWS\system32\E2050308.DLL] [Microsoft Corporation, ]
==================================
Autorun.inf
[C:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
[D:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe
[E:\]
[AutoRun]
open=auto.exe
shellexecute=auto.exe
shell\Auto\command=auto.exe


²éɱ·½·¨£º
Ò».Çå³ý²¡¶¾Ö÷³ÌÐò£¨Ëæ»ú8λ×ÖĸºÍÊý×Ö×éºÏµÄexeºÍdll£©
±ØÐëÊ×ÏÈÇå³ýauto.exeºÍÆäÉú³ÉµÄËæ»ú8λ×ÖĸºÍÊý×Ö×éºÏµÄexeºÍdll£¬ÒòΪËûÊÇľÂíȺµÄÍò¶ñÖ®Ô´£¡£¡
1.Ê×ÏÈÏÂÔØsrengÕâ¸öÈí¼þ£¨http://download.kztechs.com/files/sreng2.zip£©
½âѹËõºóÔËÐÐsrengps.exe
ÒÀ´Îµã»÷¡°Æô¶¯ÏîÄ¿¡±-¡°·þÎñ¡±-¡°Win32·þÎñÓ¦ÓóÌÐò¡± Ö®ºó¹´Ñ¡¡°Òþ²Ø¾­ÈÏÖ¤µÄ΢ÈíÏîÄ¿¡±
µÈ´ýÁбí³öÀ´Ö®ºó ²éÕÒÄÇÖÖ²»¹æÔòµÄËæ»ú8λ×Öĸ£¨´óд£©ºÍÊý×Ö×éºÏµÄ·þÎñ
È»ºóÑ¡ÖÐÏÂÃæµÄ ¡°É¾³ý·þÎñ¡± ²¢µ¥»÷ÉèÖð´Å¥
ÔÚµ¯³öµÄ¿òÖе㡰·ñ¡±
2.ÖØÆô¼ÆËã»ú½øÈ밲ȫģʽÏÂ

°ÑÏÂÃæµÄ´úÂ뿽Èë¼Çʱ¾ÖÐÈ»ºóÁí´æÎª1.regÎļþ
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"RegPath"="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced"
"Text"="@shell32.dll,-30500"
"Type"="radio"
"CheckedValue"=dword:00000001
"ValueName"="Hidden"
"DefaultValue"=dword:00000002
"HKeyRoot"=dword:80000001
"HelpID"="shell.hlp#51105"

Ë«»÷1.reg°ÑÕâ¸ö×¢²á±íÏîµ¼Èë

Ë«»÷ÎҵĵçÄÔ£¬¹¤¾ß£¬Îļþ¼ÐÑ¡Ï²é¿´£¬µ¥»÷ѡȡ"ÏÔʾÒþ²ØÎļþ»òÎļþ¼Ð" ²¢Çå³ý"Òþ²ØÊܱ£»¤µÄ²Ù×÷ϵͳÎļþ£¨ÍƼö£©"Ç°ÃæµÄ¹³¡£ÔÚÌáʾȷ¶¨¸ü¸Äʱ£¬µ¥»÷¡°ÊÇ¡± È»ºóÈ·¶¨
µã»÷ ²Ëµ¥À¸Ï·½µÄ Îļþ¼Ð°´Å¥£¨ËÑË÷Óұߵİ´Å¥£©
ɾ³ýÈçÏÂÎļþ
C:\auto.exe
C:\autorun.inf
ÒÔ¼°Ã¿¸ö·ÖÇøÏÂÃæµÄauto.exeºÍautorun.inf

%system32%Îļþ¼ÐϵÄËæ»ú8¸ö×ÖĸºÍÊý×Ö×éºÏµÄexeºÍdll
¼´±¾ÀýÖеÄC:\WINDOWS\system32\E2050308.DLL
C:\WINDOWS\system32\F2F187EC.EXE

ÖÁ´Ë²¡¶¾Ö÷³ÌÐòÒѾ­±»É¾³ýÁË£¬½ÓÏÂÀ´Çå³ýÆäÏÂÔØµÄľÂí

¶þ.Çå³ý²¡¶¾ÏÂÔØµÄľÂí£¨ÓÉÓÚÿ¸ö±äÖÖÏÂÔØµÄľÂí²»¾¡Ïàͬ£¬Òò´Ë±¾Àý½ö¹©²Î¿¼£©
»¹ÊÇÔÚ°²È«Ä£Ê½ÏÂ
´ò¿ªsreng
Æô¶¯ÏîÄ¿ ×¢²á±í ɾ³ýÈçÏÂÏîÄ¿
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
[]
[]
[]
[]
[]
[]
[]
[]
[]
[]
[]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
[N/A]
[N/A]
[N/A]
[N/A]
[N/A]
[N/A]
[N/A]

Ë«»÷ÎҵĵçÄÔ£¬¹¤¾ß£¬Îļþ¼ÐÑ¡Ï²é¿´£¬µ¥»÷ѡȡ"ÏÔʾÒþ²ØÎļþ»òÎļþ¼Ð" ²¢Çå³ý"Òþ²ØÊܱ£»¤µÄ²Ù×÷ϵͳÎļþ£¨ÍƼö£©"Ç°ÃæµÄ¹³¡£ÔÚÌáʾȷ¶¨¸ü¸Äʱ£¬µ¥»÷¡°ÊÇ¡± È»ºóÈ·¶¨
µã»÷ ²Ëµ¥À¸Ï·½µÄ Îļþ¼Ð°´Å¥£¨ËÑË÷Óұߵİ´Å¥£©
ÔÚ×ó±ßµÄ×ÊÔ´¹ÜÀíÆ÷Öдò¿ªCÅÌ£¨ÏµÍ³ÅÌ£©
ɾ³ýÈçÏÂÎļþ
C:\WINDOWS\mppds.exe
C:\WINDOWS\Kvsc3.exe
C:\WINDOWS\kterzx.exe
C:\WINDOWS\WinForm.exe
C:\WINDOWS\AVPSrv.exe
C:\WINDOWS\MsIMMs32.exe
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\DbgHlp32.exe
C:\WINDOWS\upxdnd.exe
C:\WINDOWS\kterzx.exe
C:\WINDOWS\system32\mppds.dll
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\system32\AVPSrv.dll
C:\WINDOWS\system32\DiskMan32.dll
C:\WINDOWS\system32\NVDispDrv.dll
C:\WINDOWS\system32\MsIMMs32.dll
C:\WINDOWS\system32\WinForm.dll
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\DbgHlp32.dll
C:\WINDOWS\system32\Kvsc3.dll
3Â¥2007-11-21 09:29:43
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû

renchao2001yh

ľ³æ (ÕýʽдÊÖ)

ÊDz»Êǵ¯³ö¸öÌáʾ˵Êܱ£»¤Ê²Ã´µÄ£¿ÄÇÄãÉèÖÃÒ»ÏÂÈðÐÇIEÑ¡Ïî¹À¼Æ¾Í³É¡£
×÷ѧÎÊÀÏʵµãºÃ£¬×÷ʵÑéÈÏÕæµãºÃ£¬×öÈË̤ʵµãºÃ¡£
4Â¥2007-11-21 09:30:23
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû
×î¾ßÈËÆøÈÈÌûÍÆ¼ö [²é¿´È«²¿] ×÷Õß »Ø/¿´ ×îºó·¢±í
[¿¼ÑÐ] 291 Çóµ÷¼Á +4 »¯¹¤2026½ì±ÏÒµÉ 2026-03-21 5/250 2026-03-23 16:46 by »¯¹¤2026½ì±ÏÒµÉ
[¿¼ÑÐ] 298-Ò»Ö¾Ô¸Öйúũҵ´óѧ-Çóµ÷¼Á +10 ÊÖ»úÓû§ 2026-03-17 11/550 2026-03-23 16:30 by lingjue
[¿¼ÑÐ] Ò»Ö¾Ô¸±±¾©»¯¹¤´óѧ 070300 ѧ˶ 336·Ö Çóµ÷¼Á +5 vvÃÔ 2026-03-22 5/250 2026-03-23 07:36 by Iveryant
[¿¼ÑÐ] 311Çóµ÷¼Á +6 ¶¬Ê®Èý 2026-03-18 6/300 2026-03-22 20:18 by edmund7
[¿¼ÑÐ] Çóµ÷¼ÁԺУÐÅÏ¢ +6 CX 330 2026-03-21 6/300 2026-03-22 15:25 by ÎÞи¿É»÷111
[»ù½ðÉêÇë] ɽ¶«Ê¡ÃæÉÏÏîÄ¿ÏÞ¶îÆÀÉó +4 ʯÈð0426 2026-03-19 4/200 2026-03-22 08:50 by Wei_ren
[¿¼ÑÐ] 085600²ÄÁÏÓ뻯¹¤306 +4 z1z2z3879 2026-03-21 4/200 2026-03-21 23:44 by ms629
[¿¼ÑÐ] ×ÊÔ´Óë»·¾³ µ÷¼ÁÉêÇë(333·Ö) +5 holy J 2026-03-21 5/250 2026-03-21 22:42 by Catalysis25
[¿¼ÑÐ] 332Çóµ÷¼Á +3 ·ï»ËÔº¶¡Õæ 2026-03-20 3/150 2026-03-21 10:27 by luoyongfeng
[¿¼ÑÐ] 346Çóµ÷¼Á[0856] +4 WayneLim327 2026-03-16 7/350 2026-03-21 04:02 by JourneyLucky
[¿¼ÑÐ] »úеר˶299Çóµ÷¼ÁÖÁ²ÄÁÏ +3 kkcoco25 2026-03-16 4/200 2026-03-21 03:52 by JourneyLucky
[¿¼ÑÐ] 303Çóµ÷¼Á +5 î£08 2026-03-17 7/350 2026-03-21 03:11 by JourneyLucky
[¿¼ÑÐ] Ò»Ö¾Ô¸ÖØÇì´óѧ085700×ÊÔ´Óë»·¾³×¨Ë¶£¬×Ü·Ö308Çóµ÷¼Á +3 īīĮ 2026-03-18 3/150 2026-03-21 00:39 by JourneyLucky
[¿¼ÑÐ] Ò»Ö¾Ô¸ Î÷±±´óѧ £¬070300»¯Ñ§Ñ§Ë¶£¬×Ü·Ö287£¬Ë«·ÇÒ»±¾£¬Çóµ÷¼Á¡£ +4 ³¿»èÏßÓëÐǺ£ 2026-03-19 4/200 2026-03-20 22:15 by JourneyLucky
[¿¼ÑÐ] ²ÄÁÏÓ뻯¹¤ 322Çóµ÷¼Á +4 È»11 2026-03-19 4/200 2026-03-20 22:12 by luoyongfeng
[¿¼ÑÐ] Ò»Ö¾Ô¸Î÷ÄϽ»Í¨ ר˶ ²ÄÁÏ355 ±¾¿ÆË«·Ç Çóµ÷¼Á +5 Î÷ÄϽ»Í¨×¨²Ä355 2026-03-19 5/250 2026-03-20 21:10 by JourneyLucky
[¿¼ÑÐ] ¹ãÎ÷´óѧ¼ÒÇÝÒÅ´«ÓýÖÖ¿ÎÌâ×é2026Äê˶ʿÕÐÉú£¨½ÓÊÕ¼ÆËã»úרҵµ÷¼Á£© +3 123°¢±ê 2026-03-17 3/150 2026-03-20 15:58 by ·ÉÐÐçù
[¿¼ÑÐ] ÕÐÊÕµ÷¼Á˶ʿ +4 lidianxing 2026-03-19 12/600 2026-03-20 12:25 by lidianxing
[¿¼ÑÐ] ¡¾Í¬¼ÃÈí¼þ¡¿Èí¼þ£¨085405£©¿¼ÑÐÇóµ÷¼Á +3 2026eternal 2026-03-18 3/150 2026-03-18 19:09 by ²«»÷518
[¿¼ÑÐ] ÓÐûÓеÀÌú/ÍÁľµÄÏëµ÷¼ÁÄÏÁÖ£¬¸ø×Ô¼ºÕÐʦµÜÖС« +3 TqlXswl 2026-03-16 7/350 2026-03-17 15:23 by TqlXswl
ÐÅÏ¢Ìáʾ
ÇëÌî´¦ÀíÒâ¼û