作者:
sai7sai
執行它之後,它會下載幾個檔案(不正常之行為,除非有正常理由):
[Added process]
C:\WINDOWS\intranet.exe
C:\WINDOWS\winlogin.exe
C:\WINDOWS\explore.exe
C:\WINDOWS\taskmor.exe
[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\explore[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\intranet[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\ntssl[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\taskmor[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\winlogin[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\count[1].txt
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\tupdate[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\versioni[1].txt
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\eupdate[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\iupdate[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\wupdate[1].exe
C:\Documents and Settings\Administrator\Recent\count.hta.lnk
C:\Documents and Settings\Administrator\Recent\Temp.lnk
C:\WINDOWS\eupdate.exe
C:\WINDOWS\explore.exe
C:\WINDOWS\intranet.exe
C:\WINDOWS\iupdate.exe
C:\WINDOWS\taskmor.exe
C:\WINDOWS\tupdate.exe
C:\WINDOWS\winlogin.exe
C:\WINDOWS\wupdate.exe
[Added Registry]
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Value=Explore.exe||Data=C:\WINDOWS\explore.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Value=Taskmor.exe||Data=C:\WINDOWS\taskmor.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Value=Intranet||Data=C:\WINDOWS\intranet.exe
HKU\S-1-5-21-515967899-583907252-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run\Value=Explore.exe||Data=C:\WINDOWS\explore.exe
HKU\S-1-5-21-515967899-583907252-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run\Value=Taskmor.exe||Data=C:\WINDOWS\taskmor.exe
趕快清除你的系統吧。
書籤