<?xml version="1.0" encoding="gb2312"?>
<rss version="2.0">
<channel>
<title><![CDATA[mopery]]></title>
        <image>
        <title>http://hi.baidu.com</title>
        <link>http://hi.baidu.com</link>
        <url>http://img.baidu.com/img/logo-hi.gif</url>
        </image>
<description><![CDATA[..︷ωo′゛︷.нoнo﹎． .﹏．х]]></description>
<link>http://hi.baidu.com/mopery</link>
<language>zh-cn</language>
<generator>www.baidu.com</generator>
<ttl>5</ttl>


<item>
        <title><![CDATA[Worm.Win32.AutoRun.qvb llwzjy081018.exe 解决方案]]></title>
        <link><![CDATA[http://hi.baidu.com/mopery/blog/item/9e92dafc72fd29fbfc037fde.html]]></link>
        <description><![CDATA[
		
		<p>文件名称: llwzjy081018.exe<br>
文件大小: 38164 bytes<br>
MD5: 318334b3316bf8d50096650e630322d8<br>
加壳: WinUpack<br>
编写语言: delphi <br>
病毒名: kaspersky: Worm.Win32.AutoRun.qvb<br>
            rising: Worm.Win32.Autorun.exk<br>
            duba: N/A<br>
<br>
详细资料:<br>
<br>
文件变化: <br>
释放文件<br>
%WINDIR%\system\llwzjy081018.exe<br>
%WINDIR%\system\mvjaj32dla.dll<br>
%ALLUSERSPROFILE%\jjdf32.ini<br>
%ALLUSERSPROFILE%\jjjydf16.ini<br>
<br>
jjdf32.ini 内容:<br>
[sys]<br>
install=20081019</p>
<p>时间即中此病毒当日时间<br>
<br>
jjjydf16.ini 内容:<br>
[mydown]<br>
old_exe=<br>
old_dll32=<br>
ver=081018<br>
fnexe=%WINDIR%\system\llwzjy081018.exe<br>
reg_start=dlnajjbdfa<br>
fn_dll=%WINDIR%\system\mvjaj32dla.dll<br>
[kill]<br>
window=32353530383837333637313337373831222525<br>
[run]<br>
delay=90<br>
pzjg=180<br>
xxjg=10</p>
<p>注册表变动:<br>
病毒创建启动项<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run] <br>
&quot;dlnajjbdfa&quot;=&quot;%WINDIR%\system\llwzjy081018.exe&quot;</p>
<p>修改注册表项禁用&quot;显示所有文件和文件夹&quot;<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\<br>
Hidden\SHOWALL] <br>
&quot;CheckedValue&quot;=dword:00000000</p>
<p>其他行为:<br>
调用 IE 访问以下URL下载盗号木马<br>
http://www.poplkot.cn/[REMOVED]/mhxy.exe<br>
http://www.poplkot.cn/[REMOVED]/kd.exe<br>
http://www.poplkot.cn/[REMOVED]/jx.exe<br>
http://www.poplkot.cn/[REMOVED]/hx.exe<br>
http://www.poplkot.cn/[REMOVED]/fy.exe<br>
http://www.poplkot.cn/[REMOVED]/dnf.exe<br>
http://www.poplkot.cn/[REMOVED]/dj.exe<br>
http://www.poplkot.cn/[REMOVED]/rxjh.exe<br>
http://www.poplkot.cn/[REMOVED]/my.exe<br>
http://www.poplkot.cn/[REMOVED]/cqsj.exe<br>
http://www.poplkot.cn/[REMOVED]/pt.exe<br>
http://www.poplkot.cn/[REMOVED]/jz.exe<br>
http://www.poplkot.cn/[REMOVED]/zx.exe<br>
http://www.poplkot.cn/[REMOVED]/zt.exe<br>
http://www.poplkot.cn/[REMOVED]/cqwz.exe<br>
http://www.poplkot.cn/[REMOVED]/zf.exe<br>
http://www.poplkot.cn/[REMOVED]/yy.exe<br>
http://www.poplkot.cn/[REMOVED]/wow.exe<br>
http://www.poplkot.cn/[REMOVED]/wl.exe<br>
http://www.poplkot.cn/[REMOVED]/wd.exe<br>
http://www.poplkot.cn/[REMOVED]/tl.exe<br>
http://www.poplkot.cn/[REMOVED]/rxcq.exe<br>
http://www.poplkot.cn/[REMOVED]/qqhx.exe<br>
http://www.poplkot.cn/[REMOVED]/qq.exe<br>
http://www.poplkot.cn/[REMOVED]/qn.exe<br>
http://www.poplkot.cn/[REMOVED]/cb.exe<br>
http://www.lk[REMOVED].cn/1.exe<br>
http://cnzz.back[REMOVED].cn/sky.exe<br>
<br>
创建 <strong>Image File Execution Options</strong> 劫持安全相关程序<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\360rpt.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\360Safe.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\360tray.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\adam.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\AgentSvr.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\AppSvc32.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\auto.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\AutoRun.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\autoruns.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\avgrssvc.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\AvMonitor.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\avp.com] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\avp.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\CCenter.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\ccSvcHst.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\cross.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\FileDsty.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\FTCleanerShell.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\guangd.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\HijackThis.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\IceSword.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\iparmo.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\Iparmor.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\isPwdSvc.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\kabaload.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KaScrScn.SCR] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KASMain.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KASTask.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KAV32.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KAVDX.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KAVPFW.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KAVSetup.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KAVStart.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KISLnchr.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KMailMon.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KMFilter.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KPFW32.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KPFW32X.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KPFWSvc.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KRegEx.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KRepair.COM] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KsLoader.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KVCenter.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KvDetect.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KvfwMcl.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KVMonXP.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KVMonXP_1.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\kvol.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\kvolself.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KvReport.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KVSrvXP.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KVStub.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\kvupload.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\kvwsc.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KvXP.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KWatch.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KWatch9x.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\KWatchX.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\loaddll.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\MagicSet.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\mcconsol.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\mmqczj.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\mmsk.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\NAVSetup.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\nod32krn.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\nod32kui.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\PFW.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\PFWLiveUpdate.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\QHSET.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\QQDoctor.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\Ras.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\Rav.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\RavMon.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\RavMonD.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\RavStub.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\RavTask.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\RegClean.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\rfwcfg.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\RfwMain.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\rfwProxy.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\rfwsrv.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\RsAgent.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\Rsaupd.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\RStray.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\runiep.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\safelive.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\scan32.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\SDGames.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\shcfg32.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\ShuiNiu.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\SmartUp.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\sos.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\SREng.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\svch0st.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\symlcsvc.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\SysSafe.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\Systom.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\taskmgr.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\TNT.Exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\TrojanDetector.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\Trojanwall.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\TrojDie.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\TxoMoU.Exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\UFO.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\UIHost.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\UmxAgent.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\UmxAttachment.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\UmxCfg.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\UmxFwHlp.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\UmxPol.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\UpLive.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\WoptiClean.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\XP.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution <br>
Options\zxsweep.exe]</p>
<p>清除方法:<br>
1. 结束进程 <strong>iexplore.exe</strong><br>
<br>
2. 删除病毒文件<br>
%WINDIR%\system\llwzjy081018.exe<br>
%WINDIR%\system\mvjaj32dla.dll<br>
%ALLUSERSPROFILE%\jjdf32.ini<br>
%ALLUSERSPROFILE%\jjjydf16.ini<br>
<br>
3. 删除病毒创建启动项<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run] <br>
&quot;dlnajjbdfa&quot;</p>
<p>4. 修改注册表项恢复被禁用&quot;显示所有文件和文件夹&quot;<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\<br>
Hidden\SHOWALL] <br>
&quot;CheckedValue&quot;=dword:00000001</p>
<p>5. 删除病毒创建的 <strong>Image File Execution Options</strong> 劫持项<br>
<br>
备注:<strong><font color="#ff0000">本处理方法不能清除病毒联网下载的病毒.</font></strong></p> <a href="http://hi.baidu.com/mopery/blog/item/9e92dafc72fd29fbfc037fde.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/mopery/blog/category/%B2%A1%B6%BE%B2%E9%C9%B1">病毒查杀</a>&nbsp;<a href="http://hi.baidu.com/mopery/blog/item/9e92dafc72fd29fbfc037fde.html#comment">查看评论</a>]]></description>
        <pubDate>2008-10-19  17:05</pubDate>
        <category><![CDATA[病毒查杀]]></category>
        <author><![CDATA[berrykwok]]></author>
		<guid>http://hi.baidu.com/mopery/blog/item/9e92dafc72fd29fbfc037fde.html</guid>
</item>

<item>
        <title><![CDATA[暴风主页被劫持(电信访问才能显示代码)]]></title>
        <link><![CDATA[http://hi.baidu.com/mopery/blog/item/3e58ae3e2414d9fc828b13cc.html]]></link>
        <description><![CDATA[
		
		<p> </p>
<p> </p>
<p>3点左右在群里有人说暴风被挂,奔去看看,果然...</p>
<p> </p>
<div forimg="1">
<p><a target="_blank" href="http://hiphotos.baidu.com/mopery/pic/item/5eb1185510d3c2dfb645ae02.jpg"><img class="blogimg" border="0" small="1" src="http://hiphotos.baidu.com/mopery/abpic/item/5eb1185510d3c2dfb645ae02.jpg"></a></p>
<p>电信用户访问暴风才会出现,其他网络访问无异常..</p>
<p>http://www.baofeng.com/<br>
|-&gt;http://www.woaiwf.cn/index.html?05<br>
&nbsp;&nbsp;  |-&gt;http://www.woaiwf.cn/flash.htm<br>
&nbsp;&nbsp;  |  |-&gt;http://www.woaiwf.cn/i1.html<br>
&nbsp;&nbsp;  |  |  |-&gt;http://www.woaiwf.cn/swfobject.js<br>
&nbsp;&nbsp;  |  |-&gt;http://www.woaiwf.cn/f2.html<br>
&nbsp;&nbsp;  |&nbsp;&nbsp;&nbsp;&nbsp;  |-&gt;http://www.woaiwf.cn/swfobject.js<br>
&nbsp;&nbsp;  |-&gt;http://www.woaiwf.cn/cx.htm<br>
&nbsp;&nbsp;  |-&gt;http://www.woaiwf.cn/06014.htm<br>
&nbsp;&nbsp;  |-&gt;http://www.woaiwf.cn/ff.htm<br>
&nbsp;&nbsp;  |-&gt;http://www.woaiwf.cn/xl.htm<br>
&nbsp;&nbsp;  |-&gt;http://www.woaiwf.cn/mi.htm<br>
&nbsp;&nbsp;  |-&gt;http://www.woaiwf.cn/real10.htm<br>
&nbsp;&nbsp;  |-&gt;http://www.woaiwf.cn/real11.htm<br>
&nbsp;&nbsp;  |-&gt;http://js.users.51.la/2186512.js<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  |-&gt;http://icon.ajiang.net/icon_0.gif</p>
<p>漏洞下载</p>
<p>http://www.poplkot.cn/1.exe</p>
</div> <a href="http://hi.baidu.com/mopery/blog/item/3e58ae3e2414d9fc828b13cc.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/mopery/blog/category/%D7%CA%D1%B6%C7%B0%D1%D8">资讯前沿</a>&nbsp;<a href="http://hi.baidu.com/mopery/blog/item/3e58ae3e2414d9fc828b13cc.html#comment">查看评论</a>]]></description>
        <pubDate>2008-10-19  16:37</pubDate>
        <category><![CDATA[资讯前沿]]></category>
        <author><![CDATA[berrykwok]]></author>
		<guid>http://hi.baidu.com/mopery/blog/item/3e58ae3e2414d9fc828b13cc.html</guid>
</item>

<item>
        <title><![CDATA[10月份windows系统补丁安全公告]]></title>
        <link><![CDATA[http://hi.baidu.com/mopery/blog/item/6d6d3c738a3b521a8601b012.html]]></link>
        <description><![CDATA[
		
		微软发布了针对windows系统的10月最新补丁,CSI提醒广大计算机用户及时更新您的windows,以免受到漏洞造成的恶意攻击.<br>
<br>
<a href="http://www.microsoft.com/china/technet/security/bulletin/ms08-oct.mspx" target="_blank"><span style="color: #0000ff">Microsoft 安全公告摘要（2008 年 10 月）</span></a><br>
<br>
本月的安全公告如下所示（按严重性排序）：<br>
<strong><span style="color: #ff0000">严重 (4)</span></strong><br>
Microsoft 安全公告 MS08-060<br>
<a href="http://www.microsoft.com/china/technet/security/bulletin/ms08-060.mspx" target="_blank"><span style="color: #008000">Active Directory 中的漏洞可能允许远程执行代码 (957280)</span></a><br>
此安全更新可解决 Microsoft Windows 2000 Server 上的 Active Directory 实施中一个秘密报告的漏洞。 如果攻击者获得受影响网络的访问权限，则该漏洞可能允许远程执行代码。 此漏洞仅影响配置为主域控制器的 Microsoft Windows 2000 服务器。 如果 Microsoft Windows 2000 服务器没有被提升为域控制器，则它不会侦听轻量目录访问协议 (LDAP) 或 LDAP over SSL (LDAPS) 查询，因此不会被暴露给此漏洞。<br>
<br>
Microsoft 安全公告 MS08-058<br>
<a href="http://www.microsoft.com/china/technet/security/bulletin/ms08-058.mspx" target="_blank"><span style="color: #008000">Internet Explorer 的累积性安全更新 (956390)</span></a><br>
此安全更新可消除五个秘密报告的漏洞以及一个公开披露的漏洞。 如果用户使用 Internet Explorer 查看特制网页，这些漏洞可能允许泄露信息或远程执行代码。 那些帐户被配置为拥有较少系统用户权限的用户比具有管理用户权限的用户受到的影响要小。<br>
<br>
Microsoft 安全公告 MS08-059<br>
<a href="http://www.microsoft.com/china/technet/security/bulletin/ms08-059.mspx" target="_blank"><span style="color: #008000">Host Integration Server RPC 服务中的漏洞可能允许远程执行代码 (956695)</span></a><br>
此安全更新解决了 Microsoft Host Integration Server 中一个秘密报告的漏洞。 如果攻击者向受影响的系统发送特制的远程过程调用 (RPC) 请求，则该漏洞可能允许远程执行代码。 遵循最佳方案并将 SNA RPC 服务帐户配置为对系统具有较少用户权限的客户所受到的影响可能比将 SNA RPC 服务帐户配置为具有管理用户权限的客户所受到的影响要小。<br>
<br>
Microsoft 安全公告 MS08-057<br>
<a href="http://www.microsoft.com/china/technet/security/bulletin/ms08-057.mspx" target="_blank"><span style="color: #008000">Microsoft Excel 中的漏洞可能允许远程执行代码 (956416)</span></a><br>
此安全更新解决了 Microsoft Office Excel 中三个秘密报告的漏洞，如果用户打开特制的 Excel 文件，这些漏洞可能允许远程执行代码。 成功利用这些漏洞的攻击者可以完全控制受影响的系统。 攻击者可随后安装程序；查看、更改或删除数据；或者创建拥有完全用户权限的新帐户。 那些帐户被配置为拥有较少系统用户权限的用户比具有管理用户权限的用户受到的影响要小。<br>
<br>
<strong><span style="color: #ff0000">重要 (6)</span></strong><br>
Microsoft 安全公告 MS08-066<br>
<a href="http://www.microsoft.com/china/technet/security/bulletin/ms08-066.mspx" target="_blank"><span style="color: #008000">Microsoft 辅助功能驱动程序中的漏洞可能允许特权提升 (956803)</span></a><br>
此安全更新可解决 Microsoft 辅助功能驱动程序中一个秘密报告的漏洞。 成功利用此漏洞的本地攻击者可以完全控制受影响的系统。 攻击者可随后安装程序；查看、更改或删除数据；或者创建拥有完全用户权限的新帐户。<br>
<br>
Microsoft 安全公告 MS08-061<br>
<a href="http://www.microsoft.com/china/technet/security/bulletin/ms08-061.mspx" target="_blank"><span style="color: #008000">Windows 内核中的漏洞可能允许特权提升 (954211)</span></a><br>
此安全更新可解决 Windows 内核中一个公开披露和两个秘密报告的漏洞。 成功利用这些漏洞的本地攻击者可以完全控制受影响的系统。 匿名用户无法利用这些漏洞，也无法以远程方式利用这些漏洞。<br>
<br>
Microsoft 安全公告 MS08-062<br>
<a href="http://www.microsoft.com/china/technet/security/bulletin/ms08-062.mspx" target="_blank"><span style="color: #008000">Windows Internet 打印服务中的漏洞可能允许远程执行代码 (953155)</span></a><br>
此更新解决了 Windows Internet 打印服务中一个秘密报告的漏洞，该漏洞可能允许在当前用户的上下文中远程执行代码。 如果用户使用管理用户权限登录，成功利用此漏洞的攻击者便可完全控制受影响的系统。 攻击者可随后安装程序；查看、更改或删除数据；或者创建拥有完全用户权限的新帐户。 那些帐户被配置为拥有较少系统用户权限的用户比具有管理用户权限的用户受到的影响要小。<br>
<br>
Microsoft 安全公告 MS08-063<br>
<a href="http://www.microsoft.com/china/technet/security/bulletin/ms08-063.mspx" target="_blank"><span style="color: #008000">SMB 中的漏洞可能允许远程执行代码 (957095)</span></a><br>
此安全更新解决了 Microsoft 服务器消息块 (SMB) 中一个秘密报告的漏洞。 该漏洞可能允许在共享文件或文件夹的服务器上远程执行代码。 成功利用这些漏洞的攻击者可以安装程序；查看、更改或删除数据；或者创建拥有完全用户权限的新帐户。<br>
<br>
Microsoft 安全公告 MS08-064<br>
<a href="http://www.microsoft.com/china/technet/security/bulletin/ms08-064.mspx" target="_blank"><span style="color: #008000">虚拟地址描述符操作中的漏洞可能允许特权提升 (956841)</span></a><br>
此安全更新可解决虚拟地址描述符中一个秘密报告的漏洞。 如果用户运行特制的应用程序，则该漏洞可能允许特权提升。 成功利用此漏洞并经过身份验证的攻击者可以在受影响的系统上获得特权提升。 攻击者随后可安装程序；查看、更改或删除数据；或者创建拥有完全管理权限的新帐户。<br>
<br>
Microsoft 安全公告 MS08-065<br>
<a href="http://www.microsoft.com/china/technet/security/bulletin/ms08-065.mspx" target="_blank"><span style="color: #008000">消息队列中的漏洞可能允许远程执行代码 (951071)</span></a><br>
此安全更新解决了 Microsoft Windows 2000 系统上消息队列服务 (MSMQ) 中一个秘密报告的漏洞。 此漏洞可能允许在启用了 MSMQ 服务的 Microsoft Windows 2000 系统上远程执行代码。<br>
<br>
<strong><span style="color: #ff0000">中等 (1)</span></strong><br>
Microsoft 安全公告 MS08-056<br>
<a href="http://www.microsoft.com/china/technet/security/bulletin/ms08-056.mspx" target="_blank"><span style="color: #008000">Microsoft Office 中的漏洞可能允许信息泄露 (957699)</span></a><br>
此安全更新解决了 Microsoft Office 中一个秘密报告的漏洞。 如果用户点击特制的 CDO URL，该漏洞可能允许信息泄露。 成功利用此漏洞的攻击者可以在用户的浏览器中注入客户端脚本，该脚本可能欺骗内容、泄露信息或执行用户可以在受影响的网站上执行的任何操作。 <a href="http://hi.baidu.com/mopery/blog/item/6d6d3c738a3b521a8601b012.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/mopery/blog/category/%D7%CA%D1%B6%C7%B0%D1%D8">资讯前沿</a>&nbsp;<a href="http://hi.baidu.com/mopery/blog/item/6d6d3c738a3b521a8601b012.html#comment">查看评论</a>]]></description>
        <pubDate>2008-10-16  00:42</pubDate>
        <category><![CDATA[资讯前沿]]></category>
        <author><![CDATA[berrykwok]]></author>
		<guid>http://hi.baidu.com/mopery/blog/item/6d6d3c738a3b521a8601b012.html</guid>
</item>

<item>
        <title><![CDATA[weiai15.exe 解决方案]]></title>
        <link><![CDATA[http://hi.baidu.com/mopery/blog/item/095db1cc15356c1600e92817.html]]></link>
        <description><![CDATA[
		
		<p>文件名称: weiai15.exe<br>
文件大小: 36468 bytes<br>
MD5: 2EEF6AFD50B6C811FAC8C86805F1611A<br>
加壳: Upack<br>
编写语言: delphi <br>
病毒名: kaspersky: N/A<br>
          rising: N/A<br>
          duba: N/A<br>
<br>
详细资料:<br>
<br>
文件变化: <br>
释放文件<br>
<strong>%WINDOWS%\system32\weiai15.exe</strong><br>
<br>
各分区根目录释放<br>
<strong>X:\weiai15.exe<br>
X:\AutoRun.inf</strong><br>
<br>
autorun.inf 内容:<br>
[AutoRun]<br>
Open=weiai15.exe<br>
Shell\Open=打开(&amp;O)<br>
Shell\Open\Command=weiai15.exe<br>
Shell\Open\Default=1<br>
Shell\Explore=资源管理器(&amp;X)<br>
Shell\Explore\Command=weiai15.exe</p>
<p>注册表变动:<br>
病毒创建启动项<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <br>
&quot;weiai15&quot;=&quot;%WINDOWS%\system32\weiai15.exe&quot;</p>
<p>修改注册表项禁用&quot;显示所有文件和文件夹&quot;<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] <br>
&quot;CheckedValue&quot;=dword:00000000</p>
<p>其他行为:<br>
调用IE下载 http://www.888[REMOVED].com/www.txt 依据文档内的地址下载盗号木马.<br>
<br>
监视安全相关程序窗口和进程,发现相关程序活动,则立即关闭程序.<br>
<br>
创建 <strong>Image File Execution Options</strong> 劫持安全相关程序,当被劫持程序运行,实际运行的是病毒主程序.<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360hotfix.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adam.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AgentSvr.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiArp.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppSvc32.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\arvmon.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AutoGuarder.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrssvc.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.com] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileDsty.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\findt2005.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FTCleanerShell.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iparmo.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IsHelp.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\isPwdSvc.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kabaload.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KaScrScn.SCR] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASMain.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASTask.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAV32.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVDX.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPFW.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVSetup.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVStart.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\killhidepid.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KISLnchr.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMailMon.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMFilter.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32X.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFWSvc.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRegEx.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRepair.COM] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KsLoader.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVCenter.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvDetect.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvfw.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvfwMcl.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP_1.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvol.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvolself.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvReport.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVScan.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVSrvXP.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVStub.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvupload.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvwsc.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP_1.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch9x.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatchX.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\loaddll.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MagicSet.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcconsol.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmqczj.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmsk.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVSetup.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32krn.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32kui.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFWLiveUpdate.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QHSET.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctor.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ras.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavCopy.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStore.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ravt08.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegClean.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RfwMain.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwolusr.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwProxy.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsAgent.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rsaupd.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RSTray.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safebank.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safelive.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shcfg32.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartassistant.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREng.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREngPS.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\syscheck.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Syscheck2.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SysSafe.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ToolsUp.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanDetector.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Trojanwall.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.kxp] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UIHost.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAgent.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAttachment.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxCfg.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxFwHlp.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxPol.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UpLive.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WoptiClean.exe] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zxsweep.exe]</p>
<p>清除方法:<br>
1. 使用 <strong><a href="http://bbs.ikaka.com/attachment.aspx?attachmentid=442357" target="_blank"><strong>xdelbox</strong></a></strong> 删除病毒文件.(<strong><font color="#ff0000"><a href="http://bbs.ikaka.com/showtopic-8442813.aspx" target="_blank"><strong><font color="#ff0000">xdelbox 使用方法</font></strong></a></font></strong>)<br>
%WINDOWS%\system32\weiai15.exe<br>
X:\weiai15.exe<br>
X:\AutoRun.inf<br>
<br>
2. 删除病毒创建启动项<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <br>
&quot;weiai15&quot;</p>
<p>3. 修改注册表项恢复被禁用&quot;显示所有文件和文件夹&quot;<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] <br>
&quot;CheckedValue&quot;=dword:00000001</p>
<p>4. 删除病毒创建的 <strong>Image File Execution Options </strong>劫持项<br>
<br>
备注:<br>
<font color="#ff0000"><strong>本处理方法不能清除病毒联网下载的病毒.<br>
联网下载的病毒杀软也都可查杀,绝大多数下载的病毒是HB系列盗号木马,<a target="_blank" href="http://bbs.duba.net/thread-21978027-1-1.html">附件</a>为金山HB系列专杀可以尝试使用.</strong></font></p> <a href="http://hi.baidu.com/mopery/blog/item/095db1cc15356c1600e92817.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/mopery/blog/category/%B2%A1%B6%BE%B2%E9%C9%B1">病毒查杀</a>&nbsp;<a href="http://hi.baidu.com/mopery/blog/item/095db1cc15356c1600e92817.html#comment">查看评论</a>]]></description>
        <pubDate>2008-10-16  00:31</pubDate>
        <category><![CDATA[病毒查杀]]></category>
        <author><![CDATA[berrykwok]]></author>
		<guid>http://hi.baidu.com/mopery/blog/item/095db1cc15356c1600e92817.html</guid>
</item>

<item>
        <title><![CDATA[Virus.Win32.VB.eu schedl.exe 解决方案]]></title>
        <link><![CDATA[http://hi.baidu.com/mopery/blog/item/5c7418d175092dd5562c8433.html]]></link>
        <description><![CDATA[
		
		文件名称: schedl.exe<br>
文件大小: 223676 bytes<br>
MD5: 1487e413823e8827f054020b7bb27da9<br>
加壳: N/A<br>
编写语言: VB <br>
病毒名: kaspersky: Virus.Win32.VB.eu<br>
          rising: N/A<br>
          duba: Win32.Virut.n.84480<br>
<br>
详细资料:<br>
<br>
文件变化: <br>
释放文件<br>
<strong>%WINDOWS%\WINDOWS.exe <br>
%WINDOWS%\Help\schedl.exe <br>
X:\Documents and Settings\All Users\Documents\My Music\My Music.exe<br>
X:\Documents and Settings\All Users\Documents\My Pictures\My Pictures.exe<br>
X:\Documents and Settings\All Users\Documents\My Videos\My Videos.exe<br>
X:\Documents and Settings\当前用户\My Documents\Downloads\Downloads.exe<br>
X:\Documents and Settings\当前用户\My Documents\My Ducuments.exe<br>
X:\Documents and Settings\当前用户\My Documents\My Music\My Music.exe<br>
X:\Documents and Settings\当前用户\My Documents\My Pictures\My Pictures.exe<br>
X:\Documents and Settings\Documents and Settings.exe<br>
X:\Program Files\Program Files.exe<br>
X:\RECYCLER\RECYCLER.exe</strong><br>
<br>
<font color="#ff0000"><strong>X = 系统盘</strong></font><br>
<br>
依照盘符名称,在对应盘符根目录生成以盘符命名的病毒副本.<br>
如下:<br>
<strong>C:\C.exe<br>
D:\D.exe<br>
E:\E.exe<br>
........</strong><br>
<br>
注册表变动:<br>
病毒创建启动项
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <br>
&quot;schedl&quot;=&quot;%WINDOWS%\Help\schedl.exe&quot; <br>
<br>
其他行为:<br>
病毒在除系统盘以外的盘内,依据文件夹命名,在该文件夹内生成与文件夹命名相同的病毒副本<br>
<br>
清除方法:<br>
1. 结束进程 <br>
<strong>%WINDOWS%\Help\schedl.exe</strong><br>
<br>
2. 删除病毒文件<br>
<strong>%WINDOWS%\WINDOWS.exe <br>
%WINDOWS%\Help\schedl.exe <br>
X:\Documents and Settings\All Users\Documents\My Music\My Music.exe<br>
X:\Documents and Settings\All Users\Documents\My Pictures\My Pictures.exe<br>
X:\Documents and Settings\All Users\Documents\My Videos\My Videos.exe<br>
X:\Documents and Settings\当前用户\My Documents\Downloads\Downloads.exe<br>
X:\Documents and Settings\当前用户\My Documents\My Ducuments.exe<br>
X:\Documents and Settings\当前用户\My Documents\My Music\My Music.exe<br>
X:\Documents and Settings\当前用户\My Documents\My Pictures\My Pictures.exe<br>
X:\Documents and Settings\Documents and Settings.exe<br>
X:\Program Files\Program Files.exe<br>
X:\RECYCLER\RECYCLER.exe</strong><br>
<br>
3. 删除各盘符根目录病毒副本<br>
<br>
4. 删除病毒创建启动项</div>
<div class="msgborder" >[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <br>
&quot;schedl&quot;</div>
<br>
5. 在删除各盘符根目录病毒副本时,查看一下病毒副本所创建的时间,搜索除系统盘以外盘符,搜索出来的文件大小为 223676 字节,图标为文件夹图标的.exe 文件全部删除<br>
<br>
备注: N/A<br> <a href="http://hi.baidu.com/mopery/blog/item/5c7418d175092dd5562c8433.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/mopery/blog/category/%B2%A1%B6%BE%B2%E9%C9%B1">病毒查杀</a>&nbsp;<a href="http://hi.baidu.com/mopery/blog/item/5c7418d175092dd5562c8433.html#comment">查看评论</a>]]></description>
        <pubDate>2008-10-14  23:39</pubDate>
        <category><![CDATA[病毒查杀]]></category>
        <author><![CDATA[berrykwok]]></author>
		<guid>http://hi.baidu.com/mopery/blog/item/5c7418d175092dd5562c8433.html</guid>
</item>

<item>
        <title><![CDATA[Worm.Win32.DownLoad.iz GR.PIF 解决方案 收藏]]></title>
        <link><![CDATA[http://hi.baidu.com/mopery/blog/item/a198247afa75f5eb2f73b32c.html]]></link>
        <description><![CDATA[
		
		<p>原帖地址:<a href="http://www.vaid.cn/bbs/viewthread.php?tid=129&amp;extra=page%3D1">http://www.vaid.cn/bbs/viewthread.php?tid=129&amp;extra=page%3D1</a></p>
<p>文件名称: GR.PIF<br>
文件大小: 12036 bytes<br>
MD5: eb92f0f76fdf5316c193cef1f56c2238<br>
加壳: WinUpack<br>
编写语言: N/A <br>
病毒名: kaspersky: Worm.Win32.AutoRun.otv<br>
          rising: Worm.Win32.DownLoad.iz<br>
          duba: Win32.TrojDownloader.RessdxT.uk.253952<br>
<br>
详细资料:<br>
<br>
文件变化: <br>
释放文件<br>
%SystemRoot%\system32\wanifts.dll<br>
c:\temp.temp<br>
<br>
替换系统文件<br>
%SystemRoot%\system32\wuauclt.exe<br>
%SystemRoot%\system32\dllcache\wuauclt.exe<br>
%SystemRoot%\system32\Drivers\beep.sys<br>
<br>
各分区根目录释放<br>
X:\GR.PIF<br>
X:\AUTORUN.INF<br>
<br>
autorun.inf 内容:<br>
[AutoRun] shell\open=打开(&amp;O) shell\open\Command=GR.PIF shell\open\Default=1 shell\explore=资源管理器(&amp;X) shell\explore\command=GR.PIF<br>
<br>
注册表变动:<br>
病毒创建启动项<br>
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run]<br>
&quot;internetnet&quot;=&quot;%SystemRoot%\system32\wuauclt.exe&quot;<br>
<br>
修改注册表项禁用&quot;显示所有文件和文件夹:[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]<br>
&quot;CheckedValue&quot;=dword:00000002<br>
<br>
删除注册表项破坏&quot;安全模式&quot;<br>
[HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]<br>
[HKLM\System\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]</p>
<div class="msgborder" >
<p><br>
其他行为:<br>
通过 cacls.exe 命令修改下列文件访问控制权限<br>
%SystemRoot%\system32\packet.dll<br>
%SystemRoot%\system32\pthreadVC.dll<br>
%SystemRoot%\system32\wpcap.dll<br>
%SystemRoot%\system32\drivers\npf.sys<br>
%SystemRoot%\system32\npptools.dll<br>
%SystemRoot%\system32\drivers\acpidisk.sys<br>
%SystemRoot%\system32\wanpacket.dll<br>
c:\Documents and Settings\All Users\「开始」菜单\程序\启动</p>
</div>
<div class="msgborder" >
<p><br>
调用ie访问 58.53.128.146 下载病毒..<br>
<br>
病毒修改系统年份:<br>
2004<br>
<br>
创建 Image File Execution Options 劫持安全相关程序,当被劫持程序运行,实际运行的是病毒主程序.<br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safe.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ANTIARP.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ast.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AutoRun.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AutoRunKiller.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVP.COM] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVP.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Frameworkservice.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GFUpd.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GuardField.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASARP.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPFW.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavstart.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kmailmon.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRegEx.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonxp.KXP] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVSrvXP.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVWSC.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kwatch.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Mmsk.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapsvc.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32krn.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nod32kui.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctor.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAV.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Regedit.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwProxy.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwstub.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RSTray.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Runiep.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREngLdr.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanDetector.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Trojanwall.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.KXP] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VPC32.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VPTRAY.EXE] <br>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WOPTILITIES.EXE] <br>
<br>
清除方法:<br>
1. 下载 <font color="#ff0000"><a href="http://mail.ustc.edu.cn/~jfpan/download/IceSword122cn.zip" target="_blank"><font color="#ff0000">IceSword(冰刃)</font><br>
</a></font><a href="http://mail.ustc.edu.cn/~jfpan/download/IceSword122cn.zip" target="_blank"></a><br>
    解压 运行冰刃<br>
<br>
2.  文件(冰刃界面左上)-设置<br>
    勾上 禁止进线程创建 和 禁止协议功能<br>
<br>
3.  冰刃=&gt;进程=&gt;结束下列进程 wuauclt.exe 和 GR.PIF 进程=&gt;关闭冰刃<br>
<br>
4.  下载本帖附件=&gt;解压=&gt;运行 killgr.bat <br>
<br>
5.  重启计算机<br>
<br>
6.  下载<strong><font color="#0000ff"><a href="http://www.kztechs.com/sreng/download.html" target="_blank"><strong><font color="#0000ff">System Repair Engineer</font></strong></a> （点击下载）</font></strong><font color="#0000ff"><br>
</font>解压=&gt;运行=&gt;系统修复=&gt;高级修复=&gt;修复安全模式<br>
<br>
7.  修改系统时间<br>
<br>
8.  从相同的操作系统中拷贝下列系统文件,复制到相同位置<br>
%SystemRoot%\system32\wuauclt.exe<br>
%SystemRoot%\system32\dllcache\wuauclt.exe<br>
%SystemRoot%\system32\Drivers\beep.sys<br>
<br>
备注: <strong><font color="#ff0000">本处理方法不能清除病毒联网下载的病毒.</font></strong></p>
<p>killgr.bat  <a href="http://www.mopery.cn/tools/killgr.rar">http://www.mopery.cn/<u><font color="#0000ff">tools/killgr.rar</font></u></a></p>
</div> <a href="http://hi.baidu.com/mopery/blog/item/a198247afa75f5eb2f73b32c.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/mopery/blog/category/%B2%A1%B6%BE%B2%E9%C9%B1">病毒查杀</a>&nbsp;<a href="http://hi.baidu.com/mopery/blog/item/a198247afa75f5eb2f73b32c.html#comment">查看评论</a>]]></description>
        <pubDate>2008-09-30  13:56</pubDate>
        <category><![CDATA[病毒查杀]]></category>
        <author><![CDATA[berrykwok]]></author>
		<guid>http://hi.baidu.com/mopery/blog/item/a198247afa75f5eb2f73b32c.html</guid>
</item>

<item>
        <title><![CDATA[System Repair Engineer (SREng) 2.6 正式发布]]></title>
        <link><![CDATA[http://hi.baidu.com/mopery/blog/item/b0abc607eb2833c87a89473c.html]]></link>
        <description><![CDATA[
		
		Smallfrogs 刚刚发布了 System Repair Engineer (SREng) 2.6 (2.6.11.992) <br>
相关具体说明请点击 发行说明 查看..<br>
<br>
<br>
<strong>2.6.10.992 (2.6 Final) </strong><br>
发布日期：2008/06/30
<ul>
    <li>增加将SREng在受限桌面下启动功能（需要使用参数 /safedesktop 启动（注意大小写），示例：SREngLdr.EXE /safedesktop）</li>
    <li>增加对AppInit_Dlls HOOK的免疫</li>
    <li>增加文件存在检测</li>
    <li>集成TrayTooltipFix功能</li>
    <li>智能扫描提速50%</li>
    <li>修正数字签名检查时内部发生的随机违例</li>
    <li>修正logonui提示信息错误</li>
    <li>修正部分资源错误</li>
    <li>其他内部调整和优化</li>
</ul>
<p><span ><strong><font color="#ff0000" size="4">由于刚刚发布服务器可能超负荷运作,请大家尽量通过其他站点下载(霏凡,华军,天空等等),以减轻 Smallfrogs 网站服务器负荷..谢谢..</font></strong><br>
<br>
<a href="http://www.fs2you.com/zh-cn/files/674d5642-45fc-11dd-bf22-001143e7b41c/" target="_blank">http://www.fs2you.com/zh-cn/files/674d5642-45fc-11dd-bf22-001143e7b41c/</a><br>
SREng 官方分流..</span></p>
<p><span ><a href="http://www.mopery.cn/Smallfrogs/sreng2.zip" target="_blank">http://www.mopery.cn/Smallfrogs/sreng2.zip</a></span></p>
<p><span >本人网站分流..</span></p>
<p><span ><strong><font color="#ff0000" size="4">各位在签名中转向sreng官方连接的,请更新一下你们的签名,在这几天尽量不要直接转向 kztechs.com ..</font></strong></span></p> <a href="http://hi.baidu.com/mopery/blog/item/b0abc607eb2833c87a89473c.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/mopery/blog/category/%D7%CA%D1%B6%C7%B0%D1%D8">资讯前沿</a>&nbsp;<a href="http://hi.baidu.com/mopery/blog/item/b0abc607eb2833c87a89473c.html#comment">查看评论</a>]]></description>
        <pubDate>2008-06-30  01:26</pubDate>
        <category><![CDATA[资讯前沿]]></category>
        <author><![CDATA[berrykwok]]></author>
		<guid>http://hi.baidu.com/mopery/blog/item/b0abc607eb2833c87a89473c.html</guid>
</item>

<item>
        <title><![CDATA[我们这的赛车比赛]]></title>
        <link><![CDATA[http://hi.baidu.com/mopery/blog/item/6c7be9ed3dd92c4a79f05526.html]]></link>
        <description><![CDATA[
		
		<p> </p>
<p> </p>
<p>说实话,福建这地方很少能见到名车.(宝马 奔驰 倒是满大街)</p>
<p>昨天在我这个鸟地方,举行了直线竞速比赛.</p>
<p>把我家门前整条路给封了,公交都不走我这路了,这俩天路没少走,累啊..</p>
<p>本来是想去凑热闹看看比赛,没想到能见到名车(在我们这算是名车)..</p>
<p>法拉利 一辆跑车,一辆敞篷 保时捷 一辆跑车,一辆商务车 奥迪&amp;三菱&amp;奔驰 跑车</p>
<p>上几张图..=.= 从来都在网路上看到名车. 现实真少见.. 摸一下都爽..</p>
<p> </p>
<div forimg="1">
<p><a target="_blank" href="http://hiphotos.baidu.com/mopery/pic/item/147a908b6d551fc1fd1f10ba.jpg"><img class="blogimg" border="0" small="1" src="http://hiphotos.baidu.com/mopery/abpic/item/147a908b6d551fc1fd1f10ba.jpg"></a></p>
<p> </p>
<div forimg="1">
<p><a target="_blank" href="http://hiphotos.baidu.com/mopery/pic/item/d183618d88398e00b31bba85.jpg"><img class="blogimg" border="0" small="1" src="http://hiphotos.baidu.com/mopery/abpic/item/d183618d88398e00b31bba85.jpg"></a></p>
<p> </p>
</div>
</div> <a href="http://hi.baidu.com/mopery/blog/item/6c7be9ed3dd92c4a79f05526.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/mopery/blog/category/%B8%F6%C8%CB%C8%D5%BC%C7">个人日记</a>&nbsp;<a href="http://hi.baidu.com/mopery/blog/item/6c7be9ed3dd92c4a79f05526.html#comment">查看评论</a>]]></description>
        <pubDate>2008-04-27  13:49</pubDate>
        <category><![CDATA[个人日记]]></category>
        <author><![CDATA[berrykwok]]></author>
		<guid>http://hi.baidu.com/mopery/blog/item/6c7be9ed3dd92c4a79f05526.html</guid>
</item>

<item>
        <title><![CDATA[windows xp sp3]]></title>
        <link><![CDATA[http://hi.baidu.com/mopery/blog/item/029f87cab1138d83c8176804.html]]></link>
        <description><![CDATA[
		
		<p> </p>
<p>花了半天把自己的系统换成了英文版xp sp3</p>
<p>用得非常舒服..</p>
<p>进入系统的速度变慢了点.. 浏览文件速度快了..</p>
<p>=.= 剩下探讨中...  还有就是 QQ医生 漏洞扫描sp3 挂..</p>
<p> </p>
<div forimg="1"><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/mopery/pic/item/b9d11db31677ddb5d9335a81.jpg"></div> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/mopery/blog/category/%B8%F6%C8%CB%C8%D5%BC%C7">个人日记</a>&nbsp;<a href="http://hi.baidu.com/mopery/blog/item/029f87cab1138d83c8176804.html#comment">查看评论</a>]]></description>
        <pubDate>2008-04-25  17:19</pubDate>
        <category><![CDATA[个人日记]]></category>
        <author><![CDATA[berrykwok]]></author>
		<guid>http://hi.baidu.com/mopery/blog/item/029f87cab1138d83c8176804.html</guid>
</item>

<item>
        <title><![CDATA[小记]]></title>
        <link><![CDATA[http://hi.baidu.com/mopery/blog/item/00ff8c2fc703013d1f3089f5.html]]></link>
        <description><![CDATA[
		
		<p><font size="3">好久没来写blog了..</font></p>
<p><font size="3">其实天天都有来自己的blog..每次都想写些什么,最后都没有写..</font></p>
<p><font size="3">突然想起很早很早之前的我..总是喜欢写些自己的情感..每次都能写下自己一大堆事..</font></p>
<p><font size="3">现在把以前的日记拿出来看.. 有些日记觉得很无知,很傻.. 有些日记能让我感觉到伤感..</font></p>
<p><font size="3">不过这些日记都能让我回忆起刚上网时的种种事情..</font></p>
<p><font size="3">一路在网路上&quot;成长&quot;过来..........</font></p>
<p><font size="3">现在自己写日记感觉上文不对下文.. 条理等等都很乱.. 写着写着就不知道写什么了.</font></p>
<p> </p>
<p><font size="5">烦躁.....不写了...</font></p> <a href="http://hi.baidu.com/mopery/blog/item/00ff8c2fc703013d1f3089f5.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/mopery/blog/category/%B8%F6%C8%CB%C8%D5%BC%C7">个人日记</a>&nbsp;<a href="http://hi.baidu.com/mopery/blog/item/00ff8c2fc703013d1f3089f5.html#comment">查看评论</a>]]></description>
        <pubDate>2008-04-24  20:54</pubDate>
        <category><![CDATA[个人日记]]></category>
        <author><![CDATA[berrykwok]]></author>
		<guid>http://hi.baidu.com/mopery/blog/item/00ff8c2fc703013d1f3089f5.html</guid>
</item>


</channel>
</rss>