×÷¼Ò
怬

Script.VBS.Agent.ai juan.vbsרɱ

×÷Õߣº À´Ô´£ºwww.28hudong.com 2013-03-30 08:32:05 ÔĶÁ´Î ÎÒÒªÆÀÂÛ

HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedShowSuperHidden Öµ£ºType: REG_DWORD, Length: 4, Data: 0 HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHidden SHOWALLCheckedValue Öµ£ºType: REG_DWORD, Length: 4, Data: 0 ÆäËü·½Ã棺 ÿ¸ôÒ»¶Îʱ¼ä×Ô¶¯¸´ÖƸ±±¾µ½c:WINDOWS%username%.vbs¡¢c:WINDOWSsystem32%username%.vbs£¬²¢¶Ô¶Ô×¢²á±í×÷³öÉÏÃæµÄÐ޸ģ» Õû¸övbsÎļþ·ÖΪºÃ¼¸¸öÄ£¿é£¬ÔÚ¸ÐȾµÄʱºò»á´òÂÒ²¢ÖØÐÂ×éºÏÕâЩģ¿é£¬¶øÄ£¿éµÄÃû³ÆÒ²»á¸Ä±ä£» Èç¹û¸ÐȾµÄÎļþ³¬¹ý2000¸ö£¬Ôò»áµ¯´°¶Ô»°¿ò£º"ÄúÒÑÓг¬¹ý2000¸öÎļþ±»¸ÐȾ!²»¹ýÇë·ÅÐÄ£¬´Ë²¡¶¾ºÜÈÝÒ×±»Çå³ý!ÇëÁªÏµ418465***-_- !" ¼àÊÓÈçϵĽø³Ì"ras.exe", "360tray.exe", "taskmgr.exe", "cmd.exe", "cmd.com", "regedit.exe", "regedit.scr", "regedit.pif", "regedit.com", "msconfig.exe", "SREng.exe", "USBAntiVir.exe" £¬·¢ÏÖºó¾Í½áÊøÖ®£» c:WINDOWSsystem32%GetUserName%.iniÀïÃæ¼Ç¼ÁËһЩÊý¾Ý£¬°üÀ¨¸ÐȾÈÕÆÚ£¬ÓÃÓÚÈÕºó×÷³ö¶ÔÕÕ¡£ ½áÓ ¶ÔvbsµÄÁ˽âÖ»ÄÜÈÃÎÒ·ÖÎöµ½ÕâÀïÁË£¬ÆäËüµÄÓдývbs´ïÈË£¨Ä³U³öÀ´¿´¿´À²£©·ÖÎö£» ÁíÍâ²»ÖªÕâ¸ö¶«Î÷»á²»»á±»¿¨°ÍÃüÃûΪ Virus.VBS.KillAV.a ÄØ£¬¹þ¹þ£¡[:14:]

¡¡¡¡ÍƼöÔĶÁ

¡¡¡¡Ê¹ÓÃaspϵÄadodb.stream ÏÂÔØÎļþ¶ø²»ÊÇ´ò¿ª

ÔÚä¯ÀÀÆ÷µÄµØÖ·À¸ÀïÖ±½ÓÊäÈëÒ»¸ödoc»òxls»òjpgµÄÎļþµÄurl·¾¶£¬ÄÇô¸ÃÎļþ»áÖ±½ÓÏÔʾÔÚä¯ÀÀÆ÷Àï¡£¶øÔںܶàʱºòÎÒÃÇÏ£ÍûÄÜÖ±½Óµ¯³öÏÂÔØÌáʾ¿òÈÃÓû§ÏÂÔØ£¬ÎÒÃǸÃÔõô°ìÄØ£¿ÕâÀïÓÐÁ½ÖÖ·½·¨£º 1¡¢ÉèÖÃÄãµÄ·þÎñÆ÷µÄi>>>ÏêϸÔĶÁ


±¾ÎıêÌ⣺Script.VBS.Agent.ai juan.vbsרɱ

µØÖ·£ºhttp://www.17bianji.com/kaifa2/ASP/32325.html

¹Ø¼ü´Ê£º ̽Ë÷·¢ÏÖ

ÀÖ¹º¿Æ¼¼²¿·ÖÐÂÎż°ÎÄÕÂתÔØ×Ô»¥ÁªÍø£¬¹©¶ÁÕß½»Á÷ºÍѧϰ£¬ÈôÓÐÉæ¼°×÷Õß°æȨµÈÎÊÌâÇ뼰ʱÓëÎÒÃÇÁªÏµ£¬ÒÔ±ã¸üÕý¡¢É¾³ý»ò°´¹æ¶¨°ìÀí¡£¸ÐлËùÓÐÌṩ×ÊѶµÄÍøÕ¾£¬»¶Ó­¸÷ÀàýÌåÓëÀÖ¹º¿Æ¼¼½øÐÐÎÄÕ¹²ÏíºÏ×÷¡£

ÍøÓѵãÆÀ
×ÔýÌåרÀ¸

ÆÀÂÛ

ÈȶÈ

¾«²Êµ¼¶Á
À¸Ä¿ID=71µÄ±í²»´æÔÚ(²Ù×÷ÀàÐÍ=0)