Ò»¼üתÌù²å¼þ7.2£¬¡¾×ªÌù¡¿½üÆÚ³£¼ûÁ÷Ã¥¹ã¸æÈí¼þ¡¢²¡¶¾²å¼þÇå³ý´óÈ«£¡

¡¾×ªÌù¡¿½üÆÚ³£¼ûÁ÷Ã¥¹ã¸æÈí¼þ¡¢²¡¶¾²å¼þÇå³ý´óÈ«£¡ - ¹ÊÕϽâ´ð - µçÄԽ̳ÌÍø

¡¾×ªÌù¡¿½üÆÚ³£¼ûÁ÷Ã¥¹ã¸æÈí¼þ¡¢²¡¶¾²å¼þÇå³ý´óÈ«£¡

ÈÕÆÚ£º2007-08-08   ¼ö£º
×ï·¸Ò»:U88Á¬Ëø¼ÓÃËÍø¡¡
·¸×ï±íÏÖ ¡¡
Óû§ÖÐÕÐ×ÀÃæ¶àÁËÒ»¸öU88¿ì½Ý·½Ê½£¬µã»÷¾Í»áµ¯³öww*w.u88.cnµÄÒ³Ãæ¡£»¹²»ÄÜɾ³ý£¬Ã»ÓÐжÔØÑ¡Ï°Ñ×ÀÃæ¿ì½Ý·½Ê½É¾ÁË£¬Ï´ÎÆô¶¯È˼Ò×Ô¶¯ÔÙ¸øÄã¼ÓÉÏ£¬Ï൱Íç¹Ì£¡¡¡
Çå³ý°ì·¨¡¡
¿ª»ú°´F8,µ½°²È«Ä£Ê½ÏÂ,ɾ³ýc:\program Files\Internet ExplorerϵÄ2052Ŀ¼¡¡
»òc:\program Files\Internet explorerϵÄlibĿ¼,È»ºóÓÃÁ÷Ã¥Èí¼þÇåÀíÖúÊÖ»ò³¬¼¶ÍÃ×ÓÀ´Ð¶ÔزÐÓà.¡¡
¡¡
×ï·¸¶þ:dtservice dtap ×îбäÖÖ:XP21TM~1.DLL¡¡
·¸×ï±íÏÖ¡¡
¡¡ Óû§ÖÐÕк󳣻áĪÃûÆäÃ³ö¹ã¸æÍøÒ³,ÓеÄÒòΪÒѾ­±»É±¶¾Èí¼þ²éɱ£¬¿ª»ú»áµ¯³öÆô¶¯ÏîÌáʾÕÒ²»µ½¸ÃÎļþ¡£Èçͼ£º[attach]259118[/attach]¡¡
Èç¹û°²×°ÓзÀ»ðǽµÄÓû§»¹»áÌáʾ:À¹½Øµ½ÏµÍ³·ÃÎÊedmchinaÍøÕ¾.ÔÚϵͳÄÚÉú³ÉÒÔϼ¸¸öÎļþ£º¡¡
%Temp%\RarSFX0\dtservice.dll¡¡
%Temp%\RarSFX0\ext\dtdl.dll¡¡
%Temp%\RarSFX0\ext\dtsm.dll¡¡
%Windows%\dtapconfig¡¡
%System%\dtap.dll¡¡
»òÉú³É%Windows%\dtapconfig¡¡


%System%\dtap.dll¡¡
%System%\dtservice.dll¡¡
%System%\ext\dtdl.dll¡¡
%System%\ext\dtsm.dll¡¡
²¢ÁªÍøÏÂÔØһЩ¸Ã¹ã¸æ²¡¶¾±¾ÉíµÄÅäÖÃÐÅÏ¢(ÒÔ·½±ãÉý¼¶±äÖÖ)£º¡¡
http://ww*w.edmchina.com/download/dtapconfig¡¡
http://ww*w.edmchina.com/download/update3¡¡
http://ww*w.edmchina.com/download/clist¡¡
»¹¿ÉÄÜ»áÏÂÔØÁíÍâµÄ²å¼þ£º¡¡
http://ww*w.qqbao.net/download/microapmddt.dll£¨MacroMediapd£©¡¡
http://ww*w.edmchina.com/download/xresdmr£¨Õâ¸öÓмÓÃÜ£©¡¡
ÆäÖУ¬%Temp%\RarSFX0\dtservice.dllÓ¦¸ÃÊÇÖ÷³ÌÐò°É£¬ÔÚSoftware\Microsoft\Windows\CurrentVersion\Policies\Explorer\RunϽ¨Á¢ÓÐÆô¶¯Ï%System%\dtap.dll×¢²áΪBHO£¬%Temp%\RarSFX0\ext\dtdl.dllºÍ%Temp%\RarSFX0\ext\dtsm.dll»á±»µ÷ÓÃ×¢ÈëExplorer.exe½ø³Ì£¬¶ø%Windows%\dtapconfigÔòÊÇÒ»¸ö¹ã¸æÅäÖÃÎļþ¡£¡¡
ÓÉÓÚ³öÏÖÁ˱äÖֺͲ¡¶¾²å¼þ±¾ÉíµÄÉý¼¶,Ç°¼¸´ÎÔÚÌáÎÊÇøÔøÓöµ½¹ýЩÁúÓÑÖÐÁ˸ò¡¶¾,Ôø°´³£¹æµÄ½â¾ö·½·¨½¨ÒéÓÃHIJACKTHISɨÃèºÍMSCONFIG²é¿´Æô¶¯ÏîÄ¿µ«Ã»²éµ½,µ±Ê±¾õµÃÄÉÃÆ..×òÍíͨ¹ýÔ¶³ÌЭÖúÇ××Ô²Ùµ¶°ïÅóÓÑÔ×ɱÁ˸ò¡¶¾..ÓÃϵͳ°²È«ÐÞ¸´Èí¼þSystem Repair EngineerÈí¼þ(¼ò³ÆSRE,ÓÉÁ¬ÐøÁ½Äê»ñµÃMicrosoft MVP£¨Î¢Èí×îÓмÛֵר¼Ò£©³ÆºÅµÄSmallfrogs±àдµÄ)ɨÃè·¢ÏÖÁËÓÃHIJACKTHIS¶¼É¨Ãè²»µ½µÄÆô¶¯ÏîÄ¿ÈçÏÂ:¡¡
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]¡¡
£¼DTService£¾£¼rundll32.exe C:\DOCUME~1\win\LOCALS~1\Temp\RarSFX0\DTSERV~1.DLL,Load£¾ ¡¡
ÒÔÏÂÁ½ÏîÊDz¡¶¾²åÈ뵽ϵͳ½ø³Ìexplorer.exeµÄɨÃ豨¸æ,Òò´Ë¸øÇåÀíÔì³ÉÁËÒ»¶¨µÄÀ§ÄÑ,ÇåÀí²»³¹µ×µÄ»°ÈÝÒ×·´¸´·¢×÷¡¡
Çå³ý°ì·¨¡¡
·½·¨Ò»:¡¡
ÕÒµ½C:\DOCUME~1\win\LOCALS~1\Temp\RarSFX0\Ŀ¼²¢°ÑËü¸ÄÃû£¬ËÑË÷dtapconfig,dtap.dll,dtservice.dll,dtdl.dll,dtsm.dllÈ«²¿¸ÄÒ»ÏÂÃû×Ö£¬½ÓÏÂÀ´ÖØÐÂÆô¶¯Ò»Ï¼ÆËã»ú£¬ÖØÆôºó¾Í¿ÉÒÔÖ±½Óɾ³ý¸Õ²Å¸ÄÃûµÄC:\DOCUME~1\win\LOCALS~1\Temp\RarSFX0\Ŀ¼ºÍËÑË÷µ½µÄÉÏÊöÌáµ½µÄÎļþÁË£¬È»ºóÓÃSREÐÞ¸´ÏÂÆô¶¯Ïî[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]¡¡
£¼DTService£¾£¼rundll32.exe C:\DOCUME~1\win\LOCALS~1\Temp\RarSFX0\DTSERV~1.DLL,Load£¾¡¡
ÓÃSREÐÞ¸´¡°ä¯ÀÀÆ÷¼ÓÔØÏÀïµÄ%System%\dtap.dllÏîÄ¿¡£¡¡
·½·¨¶þ:¡¡
ÓÃSREÐÞ¸´Æô¶¯Ïî[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]¡¡
£¼DTService£¾£¼rundll32.exe C:\DOCUME~1\win\LOCALS~1\Temp\RarSFX0\DTSERV~1.DLL,Load£¾¡¡
ÓÃSREÐÞ¸´¡°ä¯ÀÀÆ÷¼ÓÔØÏÀïµÄ%System%\dtap.dllÏîÄ¿¡£¡¡
ÊÂÏÈËÑË÷dtapconfig,dtap.dll,dtservice.dll,dtdl.dll,dtsm.dllµÄλÖÃ(ÒòΪ³ýÁËÔÚÁÙʱÎļþ¼Ð»¹¿ÉÄÜÔÚSYSTEM32Ŀ¼)¡¡
¼Ç¼ÏÂλÖÃ,ÈÎÎñÀ¸¹ÜÀíÆ÷---£¾½áÊøexplorer.exe³ÌÐò,----£¾Îļþ---£¾ÐÂÈÎÎñ---£¾ä¯ÀÀ----£¾µ½[C:\DOCUME~1\win\LOCALS~1\Temp\RarSFX0\Ŀ¼,ºÍ¸Õ¸Õ¼Ç¼ÏµÄËÑË÷µ½SYSTEM32µÄλÖÃÈ«²¿É¾³ýÕÒµ½µÄDTÏà¹ØÎļþ.¡¡
×îºó¾ÍÊÇ´òɨս³¡ÇåÀí×¢²á±í²ÐÓàÁË:×¢²á±í--±à¼­--ÒÀ´Î²éÕÒ---£¾dtapconfig,dtap.dll,dtservice.dll,dtdl.dll,dtsm.dllÕÒµ½Ò»¸öɾ³ýÒ»¸ö(µ±È»µÃ¿´Çå³þÊDz»ÊÇDTÏà¹ØÏîÔÙɾ³ý.ÊÇɾ³ýDTµÄ¼üÏî,¿É²»Òª°ÑËüÇ°ÃæµÄ¸ù¼üÏîÒ²¸øɾ³ýÁË.Èç:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\DTSERV~1.DLL,ÊÇɾ³ýRUNϵÄDT¼üÏî,¶ø²»ÊÇPOLOCES.) ¡¡
¡¡
×ï·¸Èý£º¶à¶àQQ±íÇéϵÁУ¨°üº¬Á½ÖÖÁ÷Ã¥Èí¼þ£¬³£ºÍQQ¶à¶à±íÇéÀ¦°óÒ»ÆðÀDZ·Îª¼é¹ÃÇҺϳÆΪ¶à¶àQQ±íÇ飩¡£¡¡
·¸×ï±íÏÖ¡¡
´ó¶àÊÇÔÚÓû§²»ÖªÇéµÄÇé¿öÏ£¨±íÏÖΪÔÚ°²×°Ïà¹ØÈí¼þÀ¦°ó°²×°»òÉÏÍø¹ý³ÌÖÐ×Ô¶¯£©±»°²×°¡£¡¡
°²×°³ÌÐòÔËÐкó»á²úÉúÒÔÏÂÎļþ£º¡¡
%ProgramFiles%\Common Files\SAN\AdInstall.exe¡¡
%ProgramFiles%\Common Files\SAN\diskman.exe¡¡
%ProgramFiles%\Common Files\SAN\svr.dat¡¡
%ProgramFiles%\Common Files\SAN\updatesr.ini¡¡
%ProgramFiles%\Common Files\Upd\update.dat¡¡
%ProgramFiles%\Common Files\Upd\update.exe¡¡
%ProgramFiles%\qqhelper\index.txt¡¡
%ProgramFiles%\qqhelper\uninstall.exe¡¡
%ProgramFiles%\qqhelper\¶à¶àQQ±íÇé.exe¡¡
²¢°Ñdiskman.exe½ø³Ì×¢²áΪϵͳ·þÎñ£¬Ëæ»ú×Ô¶¯Æô¶¯¡£·þÎñÃûΪ¡°Universal Disk Manager¡±¡£¡¡
¸Ã·þÎñµÄÃèÊöÊÇ£º¡°¼à²âºÍ¼àÊÓеÄͨÓôÅÅÌÇý¶¯Æ÷²¢ÏòÂß¼­´ÅÅ̹ÜÀíÆ÷¹ÜÀí·þÎñ·¢Ë;íµÄÐÅÏ¢ÒÔ±ãÅäÖá£Èç¹û´Ë·þÎñ±»ÖÕÖ¹£¬¶¯Ì¬´ÅÅÌ״̬ºÍÅäÖÃÐÅÏ¢»á¹ýʱ¡£Èç¹û´Ë·þÎñ±»½ûÓã¬ÈκÎÒÀÀµËüµÄ·þÎñ½«ÎÞ·¨Æô¶¯¡£¡±£¨ÕâÀïÊǸÃÁ÷Ã¥Èí¼þαװÏëÃÔ»óÎÒÃÇÓû§£¬Ê¹ÎÒÃÇÒÔΪÊÇÕý³£µÄϵͳ·þÎñ¡££©¡¡
ÎÒÃÇʹÓÃHIJACKJTHISɨÃè¿ÉÒÔ¼ì²âµ½¸Ã¿ÉÒÉ·þÎñÏ¡¡
O23 - NT ·þÎñ: Universal Disk Manager - Unknown owner - C:\Program Files\CommonFiles\SAN\diskman.exe¡¡
ÁíÍâdiskman.exe»¹°²²åµ½×¢²á±íÆô¶¯Ï¡¡
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]¡¡
£¢Update£¢=£¢%ProgramFiles%\Common Files\Upd\update.exe£¢¡¡
Ó÷À»ðǽµÄÓû§¿ª»ú³£»áÌáʾÀ¹½Ø¸ÃÏîÄ¿µÄÆô¶¯¡£¡£¡¡
Çå³ý°ì·¨¡¡
1£©ÔËÐÐ%ProgramFiles%\qqhelper\uninstall.exe¿ÉÒÔжÔØ¡°¶à¶àQQ±íÇ顱£¬µ«Ò²Ö»ÊÇɾ³ýÁËÕâÈý¸öÎļþ£º¡¡
%ProgramFiles%\qqhelper\index.txt¡¡
%ProgramFiles%\qqhelper\uninstall.exe¡¡
%ProgramFiles%\qqhelper\¶à¶àQQ±íÇé.exe¡¡
2£©ÓÒ»÷ÈÎÎñÀ¸µÄ¿Õ°×´¦£¬µãÑ¡¡°ÈÎÎñ¹ÜÀíÆ÷¡±»ò°´Ctrl Alt Del¼ü¡£½áÊø¡°diskman.exe¡±½ø³Ì¡¡
3£©¿ªÊ¼²Ëµ¥¡úÔËÐÐservices.msc×Ô¶¯´ò¿ªÏµÍ³·þÎñÅäÖýçÃ棬°ÑUniversal Disk Manager·þÎñÉèÖÃΪ½ûÖ¹¡£¡¡
4£©É¾³ýϵͳProgram Files\Common Files\SANĿ¼ºÍProgram Files\Common Files\UpdĿ¼¡£¡¡
5£©ÔËÐÐSRE¡úÆô¶¯ÏîÄ¿¡ú×¢²á±í¡úµãÑ¡¡¡
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]¡¡
£¢Update£¢=£¢%ProgramFiles%\Common Files\Upd\update.exe£¢ÐÞ¸´¡£¡£¡¡
6£©ÎҵĵçÄÔ¡ú¡°É豸¹ÜÀíÆ÷¡±¡ú¡°²é¿´¡±²Ëµ¥¡úÑ¡ÖС°ÏÔʾÒþ²ØµÄÉ豸¡±¡úÔÚÏÔʾÇøÄÚ¶à³öÒ»Ïî¡°·Ç¼´²å¼´ÓÃÇý¶¯³ÌÐò¡±£¬ÕÒµ½¡°Universal Disk Manager¡±£¬ÓÒ¼üÑ¡Ôñ¡°Ð¶ÔØ¡±£¬ÔËÐÐregedit´ò¿ª×¢²á±í£¬±à¼­¡ú²éÕÒ¡°Universal Disk Manager¡±ÕÒµ½Ò»¸öɾ³ýÒ»¸ö¡£¡£»òÕßÖ±½ÓÕ¹¿ªµ½[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ServicesĿ¼Ï£¬ÕÒµ½Universal Disk Manager¼üÏ³¹µ×ɾ³ý¡£Õ¹¿ªµ½[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\Ŀ¼ÏÂÕÒµ½LEGACY_Universal Disk Manager³¹µ×ɾ³ý¡£¡£¡¡
7£©Èç¹ûÄãûÓж¯ÊÖÄÜÁ¦£¬»ò¾õµÃ·³Ëö¡£Äã¿ÉÒÔÏÂÔØ×îаæµÄ¡°Á÷Ã¥Èí¼þÇåÀíÖúÊÖ¡±£¬ÖØÐÂÆô¶¯°´F8µ½°²È«Ä£Ê½ÏÂÓá°Á÷Ã¥Èí¼þÇåÀíÖúÊÖ¡±À´×Ô¶¯ÇåÀí¡£¶ÔÓÚ¸ö±ðÎÞ·¨ÇåÀíµÄ×¢²á±í²ÐÓ࣬ºÍһ¥ɾ³ýU88µÄ·½·¨Ò»Ñù£¬µã»÷ÄãҪɾ³ýµÄ×¢²á±í²ÐÓàÏÓÒ¼üÊôÐÔ¡úȨÏÞ¡ú¸³ÓèeveryoneÍêȫȨÏÞ ¡úÈ·¶¨¼´¿Éɾ³ý¡£¡¡
×îºóÐèҪעÒâµÄÊÇÁ÷Ã¥Èí¼þÒ²ÔÚ²»¶ÏµÄÉý¼¶£¬×î½ü¶à¶àQQ±íÇéÓÖ³öÏÖÁËбäÖÖ£º¡¡
%ProgramFiles%\Common Files\SAN\diskman.exe ¡úÉý¼¶Îª%ProgramFiles%\Common Files\SAND\client.exe¡£¡¡
·þÎñÒ²³öÏÖÁËзþÎñÃû£º[QQFace / QQFace]¡¡
ÒÔÏÂÊÇSREɨÃèµ½µÄ±ä»¯µÄзþÎñÏ¡¡
[QQFace / QQFace]¡¡
£¼C:\Program Files\Common Files\SAND\qqfacerclient.exe£¾¡¡
µ«»»ÌÀ²»»»Ò©£¬¾ßÌåÇåÀí°ì·¨»¹ÊÇÒ»ÑùµÄ¡£Ö»Êǽø³ÌÃû²»Ò»Ñù°ÕÁË¡¡
¡¡
×ï·¸ËÄ£ºstdup.dll¡¡
·¸×ïÊÂʵ¡¡
ä¯ÀÀÆ÷²»¶Ï³öÏÖµ¯³ö¹ã¸æ´°¿Ú£¬Ö÷Ò³±»Ëø¶¨Îªww*w.9991.comÎÞ·¨¸ü¸Ä¡£¡¡
ÓÃSREɨÃè·¢ÏÖ±¨¸æÈçÏ£º¡¡
[std software]¡¡
{6A512BF7-EC78-4E8D-9841-6C02E8FA9838} £¼C:\WINDOWS\System32\stdup.dll, AOL Corp.£¾¡¡
stdup.dll»¹²åÈ뵽ϵͳ½ø³ÌEXPLORER.exeÏ¡£¡¡
ÓÃHIJACKTHISɨÃ豨¸æÀï±È½ÏÆÕ±é³öÏÖµÄÓÐÒÔϼ¸¸ö£º¡¡
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL¡¡
O2 - BHO: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\system32\stdup.dll¡¡
O4 - Æô¶¯ÏîHKLM\\Run: [Update] C:\WINDOWS\system32\Update.exe¡¡
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: £¾£¾ ²ÊÐÅ·¢ËÍ £¼£¼ - res://C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm¡¡
O9 - ä¯ÀÀÆ÷¶îÍâµÄ°´Å¥: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL¡¡
O9 - ä¯ÀÀÆ÷¶îÍâµÄ¡°¹¤¾ß¡±²Ëµ¥Ïî: MMSAssist¹¤¾ßÌõÉèÖà - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL¡¡
½â¾ö°ì·¨¡¡
ÔËÐÐHijackthis£¬É¨Ãè½áÊøºóÔÚÏÂÁÐÑ¡ÏîÇ°´òÉϹ´£¬È»ºóÑ¡ÐÞ¸´¡°Fix Checked¡±£º¡¡
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL¡¡
O2 - BHO: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\system32\stdup.dll¡¡
O4 - Æô¶¯ÏîHKLM\\Run: [Update] C:\WINDOWS\system32\Update.exe¡¡
O8 - IEÓÒ¼ü²Ëµ¥ÖеÄÐÂÔöÏîÄ¿: £¾£¾ ²ÊÐÅ·¢ËÍ £¼£¼ - res://C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL/mms.htm¡¡
O9 - ä¯ÀÀÆ÷¶îÍâµÄ°´Å¥: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL¡¡
O9 - ä¯ÀÀÆ÷¶îÍâµÄ¡°¹¤¾ß¡±²Ëµ¥Ïî: MMSAssist¹¤¾ßÌõÉèÖà - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL¡¡
ÔÚбäÖÖÀÔö¼ÓÁËÒ»¸öϵͳ·þÎñÏÔö¼ÓÁ˸ò¡¶¾µÄ×ÔÎÒ±£»¤ÐÔ¡£ÓÃHIJACKTHISɨÃè²»³öÀ´¡£µ«ÓÃSREɨÃèÈÃÆäÎÞËù¶ÝÐС£¡£±¨¸æÕª³­ÈçÏ£º¡¡
[StdService / StdService]¡¡
£¼C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\STDSVER.DLL,Service£¾£¼N/A£¾¡¡
Õë¶Ô¸ÃбäÖÖµÄÌصãÎÒÃÇ¿ÉÒÔÔÚ½øÐÐÇ°Ã漸²½²Ù×÷µÄ»ù´¡ÉÏ£¬ÎÒÃÇ¿ÉÒÔ½Ó×ÅÈçϲÙ×÷£º¡¡
1¡¢¿ªÊ¼¡ú¿ØÖÆÃæ°å¡úÐÔÄܺÍά»¤¡ú¹ÜÀí¹¤¾ß¡ú·þÎñ¡ú²éÕÒStdService¡úÓÒ»÷¡úÊôÐÔ¡úÆô¶¯ÀàÐÍ¡ú½ûÖ¹¡úÓ¦ÓáúÍ£Ö¹¡úÈ·¶¨¡£ ¡¡
2¡¢ÖØÐÂÆô¶¯µçÄÔ, ¿ª»ú¼ì²âÍêºó, °´[F8]¼ü(¿ÉÒÔÒ»Ö±°´µ½Æô¶¯²Ëµ¥³öÀ´ÎªÖ¹), Ñ¡Ôñ°²È«Ä£Ê½½øÈëWindows¡¡
ÏÔʾÒþ²ØÎļþ¡¡
Ë«»÷ÎҵĵçÄÔ--¹¤¾ß---Îļþ¼ÐÑ¡Ïî--²é¿´Ñ¡Ï--µ¥»÷Ñ¡È¡£¢ÏÔʾÒþ²ØÎļþ»òÎļþ¼Ð£¢--Çå³ý£¢Òþ²ØÊܱ£»¤µÄ²Ù×÷ϵͳÎļþ£¨ÍƼö£©£¢¸´Ñ¡¿ò¡£ÔÚÌáʾÄúÈ·¶¨¸ü¸Äʱ£¬µ¥»÷¡°ÊÇ¡±--µ¥»÷¡°È·¶¨¡±¡£ ¡¡
È»ºóÕÒµ½ÈçÏÂÎļþ²¢É¾³ý¡¡
C:\WINDOWS\system32\STDSVER.DLL¡¡
C:\WINDOWS\system32\stdcache\Õû¸öĿ¼¡¡
×ï·¸Î壺_IS_WEBH.dll¡¡
·¸×ïÊÂʵ:¡¡
½â¾ö°ì·¨¡¡
Ò»¡¢ÊÖ¶¯Çå³ý¡£¡¡
¡¡¡¡ÇëÔÝʱ¹Ø±Õϵͳ»¹Ô­¹¦Äܲ¢¹Ø±ÕËùÓеÄIE´°¿Ú£¬ÖØÐÂʹÓÃHijackThisɨÃèÒ»±éºóÐÞ¸´ÒÔÏÂÏîÄ¿£¬ÐÞ¸´Ç°ÇëÔÊÐíHijackThis±£Áô±¸·Ý¡£¡¡
¡¡¡¡O2 - BHO: EyeOnBrowser Class - {1272F701-349D-4DB3-BBCD-10CBDCD049FE} - C:\WINDOWS\Downlo~1\_IS_WEBH.dll¡¡
¡¡¡¡O4 - Æô¶¯ÏîHKLM\\Run: [advapi32] RUNDLL32 C:\WINDOWS\Downlo~1\_IS_ISC.DLL,isc¡¡
¡¡¡¡ÖØÆôÖÁ°²È«Ä£Ê½£¬µ÷ÓÃÃüÁîÌáʾ·û£¬¼üÈ룺¡¡
¡¡¡¡Del C:\_IS_ISC.DLL /s/a»Ø³µ£¨×¢ÒâÖ´ÐÐDeleteʱÇëÎñ±Ø¼ÓÉÏ/s/aÕâÁ½¸ö²ÎÊý£©¡¡
¡¡¡¡Del C:\_IS_WEBH.DLL /s/a »Ø³µ£¨×¢ÒâÖ´ÐÐDeleteʱÇëÎñ±Ø¼ÓÉÏ/s/aÕâÁ½¸ö²ÎÊý£©¡¡
¡¡¡¡Del C:\Windows\backup\*.*»Ø³µ¡¡
¡¡¡¡Rd C:\Windows\backup»Ø³µ¡£¡¡
¡¡¡¡´ò¿ª×¢²á±í±à¼­Æ÷£º¡¡
¡¡¡¡¶¨Î»HKEY_CURRENT_USER\Software£¬ÕÒµ½advapi32£¬É¾³ý£¡¡¡
¡¡¡¡¶¨Î»HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run£¬ÕÒµ½advapi32£¬É¾³ý£¡¡¡
¡¡¡¡¶¨Î»HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects£¬ÕÒµ½{1272F701-349D-4DB3-BBCD-10CBDCD049FE}£¬É¾³ý£¡¡¡
¡¡¡¡¶¨Î»HKEY_CLASSES_ROOT\CLSID£¬ÕÒµ½{1272F701-349D-4DB3-BBCD-10CBDCD049FE}£¬É¾³ý£¡¡¡
¡¡¡¡¶¨Î»HKEY_CLASSES_ROOT\CLSID£¬ÕÒµ½{1CC08B2F-AFF1-11D9-9651-0003FF7E92CE}£¬É¾³ý£¡¡¡
¡¡¡¡¶¨Î»HKEY_CLASSES_ROOT\TypeLib£¬ÕÒµ½{1CC08B21-AFF1-11D9-9651-0003FF7E92CE}£¬É¾³ý£¡¡¡
¡¡¡¡¶¨Î»HKEY_CLASSES_ROOT\TypeLib£¬ÕÒµ½{7B781699-1FF6-45B6-8AA7-2CB16B587C24}£¬É¾³ý£¡¡¡
¶þ¡¢°ë×Ô¶¯Çå³ý¡£¡¡
¡¡¡¡1¡¢¶Ï¿ªÍøÂ磬¹Ø±ÕËùÓÐä¯ÀÀÆ÷´°¿Ú£¬Í˳ö/¹Ø±Õ¿ÉÒÔÍ˳ö/¹Ø±ÕµÄÓ¦ÓóÌÐò£¨ÒòΪÆäÎļþ_IS_*.DLL¿ÉÄÜ»á²åÈëÔÚÆäËü½ø³ÌÖУ©£»¡¡
¡¡¡¡2¡¢½áÊøµôRundll32.exe½ø³Ì£¨µ÷ÓÃ_IS_ISC.DLL£©£»¡¡
¡¡¡¡3¡¢½áÊøµôExplorer.exe½ø³Ì£¨ÔÚExplorer.exe½ø³ÌÀïÒ²²åÈëÁ˼¸¸ö_IS_*.DLLÎļþ£¬ÆäÖоÍÓнø³Ì±£»¤µÄDLL¡£Áí£¬½áÊøµôExplorer.exe½ø³Ìºó£¬×ÀÃæ¡¢ÈÎÎñÀ¸»á¶ªÊ§£©ÒÔÉϲ½ÖèÊÇΪÁ˾¡Á¿Ê¹ÄÇЩ_IS_*.DLLÎļþûÓб»µ÷Óã¬Èç¹ûÄã¶ÔϵͳÊìϤҲ¿É²»ÓÃÕâÑù²Ù×÷£¬Ö»ÒªÈ·¶¨µ±Ç°Ã»ÓÐ_IS_*.DLLÎļþ±»µ÷Óü´¿É£»¡¡
¡¡¡¡4¡¢°ÑExplorer.exe½ø³ÌÔÙÔËÐÐÆðÀ´£¨»Ö¸´×ÀÃæ¡¢ÈÎÎñÀ¸¡£Ò²¿ÉÒÔÏȽøÐеÚ5²½É¾³ýÏà¹ØÎļþ£©£»¡¡
¡¡¡¡5¡¢É¾³ý%Windows%\Downloaded Program Files\Ŀ¼ÏÂÃæËùÓÐ_IS_*.*Îļþ£¨¿ÉÒÔʹÓÃWinRAR£¬WinRARÒ²ÊÇÒ»¸öÎļþä¯ÀÀÆ÷ÓÃËü¿ÉÒÔä¯ÀÀµ½Ò»°ã²»ÄÜÖ±½Ó²é¿´µÄDownloaded Program Files\Ŀ¼ÏµÄÎļþ£¬ÓÃWinRARÕÒµ½ÄÇЩ_IS_*.*£¬É¾³ýµô£©£¬ÔÙɾ³ý%Windows%\backup\Ŀ¼£»¡¡
¡¡¡¡6¡¢Ë«»÷µ¼Èë DEL_isc.rar £¨ÔÚ¸½¼þÖУ©ÖеÄREGÎļþ£¬×÷ÓÃÊÇɾ³ýÄÇЩ¶«Î÷ÔÚ×¢²á±íÀïÁôϵÄÆô¶¯ÏîºÍÆäËüÐÅÏ¢¡£¡¡
×ܽ᣺ɱ¶¾Èí¼þ¼¸ºõÿÌ춼ÔÚ¸üÐÂÉý¼¶£¬¶øÁ÷Ã¥¶ñÒâÈí¼þºÍ²¡¶¾²å¼þҲͬÑùÔÚ¸üбäÖÖ¡£Ð½üµÄÁ÷Ã¥¶ñÒâÈí¼þÀïÆÕ±é´øÓÐ×ÔÎÒÁªÍøÏÂÔظüÐÂÎļþÒÔ±äÖÖ¼ÓÇ¿±£»¤µÄ»úÖÆ¡£¡£ÕýÓëаʼÖÕ´¦ÓÚì¶ÜÂÝÐý¶·Õù½»ÌæÉÏÉýÖС£¡£ÖйúÓоäË×»°½Ð£ºµÀ¸ßÒ»³ß£¬Ä§¸ßÒ»ÕÉ¡£Õâµã´Ó½üÀ´ÓеÄÁ÷Ã¥¶ñÒâ²å¼þÒѾ­¿ÉÒÔÌÓ¹ýHIJACKTHISɨÃè¾Í¿ÉÒÔ˵Ã÷ÎÊÌâ¡£¡£µ«Ã»¹Øϵ£¬Èç¹ûHIJACKTHISɨÃè²»³öÀ´¿ÉÒÔÓÃSystem Repair Engineer¡£System Repair Engineer¶ÔһЩÒþ²ØµÄÔ¶³Ì×¢ÈëÏ̵߳ÄÎÞ½ø³ÌľÂí»ò²¡¶¾Ò²Í¬ÑùºÜÓÐÍþÁ¦¡£Òò´ËûÓоø¶Ô°Ù·Ö°ÙÓÐЧµÄ°²È«¹¤¾ß¡£ÒªÖªµÀºÚ¿ÍÃÇ»òľÂí²¡¶¾»òÁ÷Ã¥Èí¼þµÄ×÷ÕßÃÇÒ²ÔÚÑо¿×ÅÎÒÃÇÊÖÀïµÄ°²È«·´½Ù³Ö¹¤¾ß¡£ËùÒÔ´ó¼Ò²»Òª±§×ÅÒ»¿ÅÊ÷µõËÀ¡£Áé»îÔËÓø÷ÖÖ°²È«¹¤¾ß£¬È磺hijackthis,SRE,UPIEA,Á÷Ã¥Èí¼þÇåÀíÖúÊÖ£¬»ÆɽIEÐÞ¸´£¬³¬¼¶ÍÃ×ÓIEÐÞ¸´µÈ»¥ÏàÅäºÏÈ¡³¤²¹¶Ì°Ñ¿É¶ñ°ÔµÀµÄÁ÷Ã¥¶ñÒâÈí¼þ¸Ï³öÎÒÃǵÄϵͳ¡£¡¡


×îºóÒýÓÃħ·¨°æÖ÷µÄ»°À´½áÊø±¾Ö÷Ì⣺¡¡
ºÜ¶à¹ã¸æÀàµÄÈí¼þ¶¼ÊÇ´øÓÐ×Ô¼ºµÄжÔسÌÐòµÄ£¬Ö»²»¹ýÒ»°ã²»»á³öÏÖÔÚ¿ªÊ¼²Ëµ¥ÖУ¬ÎÒÃÇÓöµ½ÕâÖÖÎÊÌ⣬²»Òª¼±×ÅʹÓø÷ÖÖÐÞ¸´¹¤¾ß½øÐÐÐÞ¸´ºÍÇ¿ÐÐɾ³ý£¬ÕâÑù·´¶øÓпÉÄÜÔì³ÉÇå³ý²»ÍêÈ«£¬²ÐÁô²»ÉÙÀ¬»øÐÅÏ¢£¬Ê×ÏÈ¿´Ò»ÏÂËüµÄ²Ù×÷½çÃæÖÐÊÇ·ñÓÐжÔØÏ±ÈÈ磺°Ù¶ÈËÑ°Ô¡¡
ÔÙ¿´¿ØÖÆÃæ°æµÄÌí¼Óɾ³ý³ÌÐòÖÐÊÇ·ñÓÐжÔØÐÅÏ¢£¬±ÈÈ磺¡°MMSAssist¡±¡¢»®´ÊËÑË÷¡¡
ÔÙÕÒµ½ËüµÄ°²×°Ä¿Â¼£¬¿´ÊÇ·ñÓÐжÔسÌÐò£¬Ãû×ÖÒ»°ãΪuninstall.exe»òuninst.exe ±ÈÈ磺ÇàÓéÀÖ¡¢×ÀÃ洫ý¡­¡­¡¡
½øÐйýÒÔÉϲÙ×÷£¬ÕÒ²»µ½Ð¶ÔسÌÐò»òÇå³ý²»³¹µ×µÄ£¬ÔÙʹÓÃÐÞ¸´¹¤¾ß£¬¿ÉÒÔÊ°빦±¶¡£
±êÇ©£º