¦¹ blog ±N¤£¦A·s¼W¤º®e¤Î§@¥ô¦ó¦^ÂСA쥻¤Î·s¼Wªº¤º®e±N·|²¾¦Ü§Úªº·s blog¡A§Æ±æ¤j®aÄ~Äò¤ä«ù¡I ·s blog ºô§}¡Ghttp://halfstat.mysinablog.com
µo§G·s¤é»x
-
2008-06-30 22:12:52
ªñ´Á¦b°Q½×°Ïµo²{¦³«Ü¦hÓ¬Û¦PӮסA´N¬O¶}¾÷«á C Drive µL¬G¦a¤£¼u¥X¡Cì¦]¬O¤¤¤F´XÓ·s¯f¬r¡A¦ý¸Ñ¨M¤èªk¤Q¤À²³æ¡G
¨BÆJ¤@¡G¶}©l > °õ¦æ > ¿é¤Jregedit
¬d§ä[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]¡A¦b¥kÃä¡A¬d¬Ý¦³¨S¦³¤@¨Ç¾÷½X¡A¨ä¸ô®|¬O«ü¦V¥H¤UÀÉ®×
C:\stormplayer.exe
C:\Windows\jojj + (¤@°ïÀH¾÷¦r¥À)
C:\Windows\ufixitprotector.exe
C:\Windows\system32\cuteftp.exe
C:\Windows\system32\Fin3.exe
¦p¦³¡A«h§R°£¸Ó¾÷½X¡C
¨BÆJ¤G¡G¸õ¥Xregistry¨Ã«·s±Ò°Ê¹q¸£
¨BÆJ¤T¡G
¥ý¨ì±±¨î¥x > ¸ê®Æ§¨¿ï¶µ > À˵ø > ¿ï¡uÅã¥Ü©Ò¦³Àɮסv¤Î ¤£¿ï¡uÁôÂèü«OÅ@ªº¨t²ÎÀÉ¡v¡A
§R°£C:\Documents and Settings\¥Î¤á¦W\Local Settings\Temp\ ¤Î Temporary Internet Files ¤J±©Ò¦³ªºfiles¡AµM«á§R°£¥H¤W´£¤Î¹LªºÀÉ®× (¦p¦³ªº¸Ü)¡C
§¹¦¨¡I
¬d¬Ý(436)
µû½×(1)
¦¬ÂÃ
¤À¨É
ºÞ²z
-
2008-01-16 21:48:49
(¥»¤å¦P®É¥Zµn©ó§Úªº·s blog http://halfstat.pixnet.net/blog )
ªñ¨Ó¦b°Q½×°Ïµo²{«Ü¦h¥Î¤á¦b¤Wºô®É¡AÂsÄý¾¹·|¤£°±¼u¥X¤@Ó¼ÐÃD¬°CIDªº¼s§i¡A¤Q¤ÀÂZ¤H¡C
¨äì¦]¬O¦³¤@Ӥ차µ{¦¡³Q´Ó¤J¹q¸£¡A¤£¹L²M°£¤èªk¤Q¤À²³æ¡G
¨BÆJ¤@¡G¶}©l > °õ¦æ > ¿é¤Jregedit
¬d§ä[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]¡A¦b¥kÃä¡A¬d¬Ý¦³¨S¦³¤@Ó¾÷½X¡A¨ä¸ô®|¬O«ü¦V
C:\Documents and Settings\¤@Ó¦WºÙ\Application Data\¤@Ó©Çfolder\¤@Óexe
¨Ò¦p¡GC:\Documents and Settings\owner\Application Data\haha\easy2kill.exe
¥ý°O¤U³oÓ¸ô®|¡AµM«á§R°£¸Ó¾÷½X¡C
¨BÆJ¤G¡G¸õ¥Xregistry¨Ã«·s±Ò°Ê¹q¸£
¨BÆJ¤T¡G
¥ý¨ì±±¨î¥x > ¸ê®Æ§¨¿ï¶µ > À˵ø > ¿ï¡uÅã¥Ü©Ò¦³Àɮסv¤Î ¤£¿ï¡uÁôÂèü«OÅ@ªº¨t²ÎÀÉ¡v¡A
§R°£C:\Documents and Settings\¥Î¤á¦W\Local Settings\Temp\ ¤Î Temporary Internet Files ¤J±©Ò¦³ªºfiles¡AµM«á§R°£è¤~§Û¤Uªº¸ô®|¡G
C:\Documents and Settings\owner\Application Data\haha\ (¾ãÓ¸ê®Æ§¨§R°£)
§¹¦¨¡I¶}ÂsÄý¾¹¬Ý¬ÝÁÙ¦³¨S¦³³o°Q¹½ªº¼s§i§a¡I
(µù¡G¦pªG§Aªº¹q¸£¤¤¤F¨ä¥L¼s§i¯f¬r©Î¨ä¥L¤ì°¨¡A¥H¤W¤èªk¥i¯àµL®Äªº¡C)
¬d¬Ý(4511)
µû½×(11)
¦¬ÂÃ
¤À¨É
ºÞ²z
-
2007-09-07 16:31:20
¦b°Q½×°ÏùØ¡A¸g±`¦³¥Î¤á¦b¶}±ÒC:\®É¡A¹J¨ì¥H¤U°ÝÃD¡G

¦ý¥Î¥kÁä¶}±Ò®É¡A¤S·|µo²{¡u¶}±Ò¡vªº¿ï¶ÅܤF¨ä¥L©Ç¦r©Î¶Ã½X¡G

¦¨¦]¡G«Ü¦h¯f¬r¨Ò¦p auto.exe¡Bniu.exe ³£·|ªþ±a¤@Ó¦W¬° autorun.inf ªºÀɦbC:\©Î¨ä¥L®Ú½L¤º¡A·í¥Î¤áÂIÀ»C:\®É¡Aautorun.inf ¤ºùتº«ü¥O«K·|¦Û°Ê¶}±Ò¯f¬r¹B§@¡C¤£¹L¡A¨¾¬r³n¥óYÀË´ú¨ì¯f¬r¦s¦b¡A©Î³\·|¹jÂ÷©Î§R°£¯f¬r¡A¦ý autorun.inf «o¨S¦³³Q§R°£¡A©Ò¥H¨C·íÂIÀ»C:\®É¡Aautorun.inf «K§ä¤£¨ì¬Û¹ïªº¬rÀÉ¡A©ó¬O«K·|°Ý¥Î¤á¥Î¬Æ»òµ{¦¡¶}±Ò¡C
¦P®É¡A¥Ñ©ó¯f¬r¤Î autorun.inf ¥»¨³£¬OÁôÂ꺨t²ÎÀÉ¡A§ÚÌ¥²¶·n¦b¸ê®Æ§¨¿ï¶µ¤J±¿ï¨ú¡uÅã¥Ü©Ò¦³¸ê®Æ§¨©MÀɮסv¤Î¤£¿ï¡uÁôÂèü«OÅ@ªº§@·~¨t²ÎÀÉ¡v¡A¤~·|¬Ý¨ì¥¦Ì¡C¤£¹L¡A¯f¬r¥»¨¤]¥i¯à·|¯}Ãa³oÓ¸ê®Æ§¨¿ï¶µ³]©w¡A¥O¥Î¤áµLªk¿ï¨ú©Î«ç¼Ë¿ï¤]·|¦^´_쪬¡A±q¦ÓµLªk¬d§ä¤Î§R°£¥¦Ì¡C§ó¬Æªº¬O¥¦Ìªº¦WºÙ·|¥X²{¦b¥kÁ䵿³æ¤¤¡C
¸Ñ¨M¤èªk¡G¥ý°õ¦æ hidden-repair.reg ¥H¤Î Del-Autorun.bat ¥H×´_¸ê®Æ¶µ¿ï¶µªº³]©w¤Î§R°£ autorun.inf¡AµM«á«·s±Ò°Ê§Y¥i¡C
(¤U¸ü³B¡Ghttp://space.uwants.com/batch.download.php?aid=635991 )
¦Ü©ó×´_¥kÁ䵿³æ¡A«h»Ý¶i¤J registry ¶i¦æ×´_¡G
¶}©l > °õ¦æ > ¿é¤J regedit > ½T©w > ´M§ä¥H¤U¾÷½X¡G
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\
¦b¦¹¾÷½X¤U·|¦³«Ü¦hCLSID (¤@¦ê¤Q¤»¶i¨î½X)ªº¾÷½X¡A³v¤@ÂIÀ»¨Ã®i¶}¡A¦pªG¨ì³Ì«áµo²{¦¹CLSID¤U¥]§t¤F¯f¬rªº¦WºÙ¡A¨Ò¦pauto.exe¡A¨º»ò¥ý§Û¤U¸ÓCLSID¡AµM«á§â¾ãÓ¾÷½X§R°£¡C¦A´M§ä¦³¨S¦³
HKEY_CLASSES_ROOT\CLSID\{§Aè¤~§Û¤UªºCLSID}
¦³«h¤@¨Ö§R°£¡AµM«á°h¥X registry §Y¥i¡C
³Ì«áÁÙn¤@´£¡A³q±`¹J¨ì³oÓ±¡ªp¡A«Ü¦h®É¬O¥Ñ¨ä¥L¡u¤¸¥û¡v©Ò¤Þ°_ªº¡A¨Ò¦p niu.exe ¬O¥Ñcrsss.exe ©Ò²£¥Í¥X¨Óªº¡A¬G¦¹¥²»Ýn¶i¦æ¹ý©³¸Ñ¬r¤è¥i«OÃÒ¦w¥þ¡C
¬d¬Ý(4365)
µû½×(17)
¦¬ÂÃ
¤À¨É
ºÞ²z