¦¹ blog ±N¤£¦A·s¼W¤º®e¤Î§@¥ô¦ó¦^ÂСA­ì¥»¤Î·s¼Wªº¤º®e±N·|²¾¦Ü§Úªº·s blog¡A§Æ±æ¤j®aÄ~Äò¤ä«ù¡I ·s blog ºô§}¡Ghttp://halfstat.mysinablog.com

µo§G·s¤é»x

  • ¸Ñ¨MC DriveµL¬G¤£°±¼u¥Xªº°ÝÃD

    2008-06-30 22:12:52

    ªñ´Á¦b°Q½×°Ïµo²{¦³«Ü¦h­Ó¬Û¦P­Ó®×¡A´N¬O¶}¾÷«á C Drive µL¬G¦a¤£¼u¥X¡C­ì¦]¬O¤¤¤F´X­Ó·s¯f¬r¡A¦ý¸Ñ¨M¤èªk¤Q¤À²³æ¡G

    ¨BÆJ¤@¡G¶}©l > °õ¦æ > ¿é¤Jregedit
    ¬d§ä[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]¡A¦b¥kÃä¡A¬d¬Ý¦³¨S¦³¤@¨Ç¾÷½X¡A¨ä¸ô®|¬O«ü¦V¥H¤UÀÉ®×

    C:\stormplayer.exe
    C:\Windows\jojj + (¤@°ïÀH¾÷¦r¥À)
    C:\Windows\ufixitprotector.exe
    C:\Windows\system32\cuteftp.exe
    C:\Windows\system32\Fin3.exe

    ¦p¦³¡A«h§R°£¸Ó¾÷½X¡C

    ¨BÆJ¤G¡G¸õ¥Xregistry¨Ã­«·s±Ò°Ê¹q¸£

    ¨BÆJ¤T¡G
    ¥ý¨ì±±¨î¥x > ¸ê®Æ§¨¿ï¶µ > À˵ø > ¿ï¡uÅã¥Ü©Ò¦³Àɮסv¤Î ¤£¿ï¡uÁôÂèü«OÅ@ªº¨t²ÎÀÉ¡v¡A
    §R°£C:\Documents and Settings\¥Î¤á¦W\Local Settings\Temp\ ¤Î Temporary Internet Files ¤J­±©Ò¦³ªºfiles¡AµM«á§R°£¥H¤W´£¤Î¹LªºÀÉ®× (¦p¦³ªº¸Ü)¡C

    §¹¦¨¡I

  • CID ¼s§i¯f¬rªº°ò¥»²M°£¤èªk

    2008-01-16 21:48:49

    (¥»¤å¦P®É¥Zµn©ó§Úªº·s blog http://halfstat.pixnet.net/blog )

    ªñ¨Ó¦b°Q½×°Ïµo²{«Ü¦h¥Î¤á¦b¤Wºô®É¡AÂsÄý¾¹·|¤£°±¼u¥X¤@­Ó¼ÐÃD¬°CIDªº¼s§i¡A¤Q¤ÀÂZ¤H¡C

    ¨ä­ì¦]¬O¦³¤@­Ó¤ì°¨µ{¦¡³Q´Ó¤J¹q¸£¡A¤£¹L²M°£¤èªk¤Q¤À²³æ¡G

    ¨BÆJ¤@¡G¶}©l > °õ¦æ > ¿é¤Jregedit
    ¬d§ä[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]¡A¦b¥kÃä¡A¬d¬Ý¦³¨S¦³¤@­Ó¾÷½X¡A¨ä¸ô®|¬O«ü¦V
    C:\Documents and Settings\¤@­Ó¦WºÙ\Application Data\¤@­Ó©Çfolder\¤@­Óexe

    ¨Ò¦p¡GC:\Documents and Settings\owner\Application Data\haha\easy2kill.exe

    ¥ý°O¤U³o­Ó¸ô®|¡AµM«á§R°£¸Ó¾÷½X¡C

    ¨BÆJ¤G¡G¸õ¥Xregistry¨Ã­«·s±Ò°Ê¹q¸£

    ¨BÆJ¤T¡G
    ¥ý¨ì±±¨î¥x > ¸ê®Æ§¨¿ï¶µ > À˵ø > ¿ï¡uÅã¥Ü©Ò¦³Àɮסv¤Î ¤£¿ï¡uÁôÂèü«OÅ@ªº¨t²ÎÀÉ¡v¡A
    §R°£C:\Documents and Settings\¥Î¤á¦W\Local Settings\Temp\ ¤Î Temporary Internet Files ¤J­±©Ò¦³ªºfiles¡AµM«á§R°£­è¤~§Û¤Uªº¸ô®|¡G

    C:\Documents and Settings\owner\Application Data\haha\ (¾ã­Ó¸ê®Æ§¨§R°£)

    §¹¦¨¡I¶}ÂsÄý¾¹¬Ý¬ÝÁÙ¦³¨S¦³³o°Q¹½ªº¼s§i§a¡I 

    (µù¡G¦pªG§Aªº¹q¸£¤¤¤F¨ä¥L¼s§i¯f¬r©Î¨ä¥L¤ì°¨¡A¥H¤W¤èªk¥i¯àµL®Äªº¡C)

     

  • ¤£¯à¶}±ÒC:\¡B¤£¯àÅã¥ÜÁôÂÃÀɤΥkÁ䵿³æ¥X²{©Ç¦rªº°ò¥»¸Ñ¨M¤èªk

    2007-09-07 16:31:20

    ¦b°Q½×°ÏùØ¡A¸g±`¦³¥Î¤á¦b¶}±ÒC:\®É¡A¹J¨ì¥H¤U°ÝÃD¡G


    ¦ý¥Î¥kÁä¶}±Ò®É¡A¤S·|µo²{¡u¶}±Ò¡vªº¿ï­¶ÅܤF¨ä¥L©Ç¦r©Î¶Ã½X¡G


    ¦¨¦]¡G«Ü¦h¯f¬r¨Ò¦p auto.exe¡Bniu.exe ³£·|ªþ±a¤@­Ó¦W¬° autorun.inf ªºÀɦbC:\©Î¨ä¥L®Ú½L¤º¡A·í¥Î¤áÂIÀ»C:\®É¡Aautorun.inf ¤ºùتº«ü¥O«K·|¦Û°Ê¶}±Ò¯f¬r¹B§@¡C¤£¹L¡A¨¾¬r³n¥ó­YÀË´ú¨ì¯f¬r¦s¦b¡A©Î³\·|¹jÂ÷©Î§R°£¯f¬r¡A¦ý autorun.inf «o¨S¦³³Q§R°£¡A©Ò¥H¨C·íÂIÀ»C:\®É¡Aautorun.inf «K§ä¤£¨ì¬Û¹ïªº¬rÀÉ¡A©ó¬O«K·|°Ý¥Î¤á¥Î¬Æ»òµ{¦¡¶}±Ò¡C

    ¦P®É¡A¥Ñ©ó¯f¬r¤Î autorun.inf ¥»¨­³£¬OÁôÂ꺨t²ÎÀÉ¡A§Ú­Ì¥²¶·­n¦b¸ê®Æ§¨¿ï¶µ¤J­±¿ï¨ú¡uÅã¥Ü©Ò¦³¸ê®Æ§¨©MÀɮסv¤Î¤£¿ï¡uÁôÂèü«OÅ@ªº§@·~¨t²ÎÀÉ¡v¡A¤~·|¬Ý¨ì¥¦­Ì¡C¤£¹L¡A¯f¬r¥»¨­¤]¥i¯à·|¯}Ãa³o­Ó¸ê®Æ§¨¿ï¶µ³]©w¡A¥O¥Î¤áµLªk¿ï¨ú©Î«ç¼Ë¿ï¤]·|¦^´_­ìª¬¡A±q¦ÓµLªk¬d§ä¤Î§R°£¥¦­Ì¡C§ó¬Æªº¬O¥¦­Ìªº¦WºÙ·|¥X²{¦b¥kÁ䵿³æ¤¤¡C

    ¸Ñ¨M¤èªk¡G¥ý°õ¦æ hidden-repair.reg ¥H¤Î Del-Autorun.bat ¥H­×´_¸ê®Æ¶µ¿ï¶µªº³]©w¤Î§R°£ autorun.inf¡AµM«á­«·s±Ò°Ê§Y¥i¡C
    (¤U¸ü³B¡Ghttp://space.uwants.com/batch.download.php?aid=635991 )

    ¦Ü©ó­×´_¥kÁ䵿³æ¡A«h»Ý¶i¤J registry ¶i¦æ­×´_¡G

    ¶}©l > °õ¦æ > ¿é¤J regedit > ½T©w > ´M§ä¥H¤U¾÷½X¡G
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
    MountPoints2\

    ¦b¦¹¾÷½X¤U·|¦³«Ü¦hCLSID (¤@¦ê¤Q¤»¶i¨î½X)ªº¾÷½X¡A³v¤@ÂIÀ»¨Ã®i¶}¡A¦pªG¨ì³Ì«áµo²{¦¹CLSID¤U¥]§t¤F¯f¬rªº¦WºÙ¡A¨Ò¦pauto.exe¡A¨º»ò¥ý§Û¤U¸ÓCLSID¡AµM«á§â¾ã­Ó¾÷½X§R°£¡C¦A´M§ä¦³¨S¦³

    HKEY_CLASSES_ROOT\CLSID\{§A­è¤~§Û¤UªºCLSID}
    ¦³«h¤@¨Ö§R°£¡AµM«á°h¥X registry §Y¥i¡C

    ³Ì«áÁÙ­n¤@´£¡A³q±`¹J¨ì³o­Ó±¡ªp¡A«Ü¦h®É¬O¥Ñ¨ä¥L¡u¤¸¥û¡v©Ò¤Þ°_ªº¡A¨Ò¦p niu.exe ¬O¥Ñcrsss.exe ©Ò²£¥Í¥X¨Óªº¡A¬G¦¹¥²»Ý­n¶i¦æ¹ý©³¸Ñ¬r¤è¥i«OÃÒ¦w¥þ¡C