ºô¯¸¾ÉÄý | ·|­ûµn¤J | ³sµ¸§Ú­Ì

­º­¶ Ãö©ó­Z°T ²£«~¬d¸ß «ÈªA±M°Ï ·|­û±M°Ï ·s»D±M°Ï ¤H¤~©Û¶Ò ¥þ¬Ù¾ÚÂI °ê¨¾°VÀx ±j©T«¬µ§¹q



­Z°T¹q¸£
±ý¬d¸ß¸ê°T

§ä¤£¨ìµª®×?

­Z°T¥Î¤ß´£¿ô¡G»P¥»­¶¬ÛÃö¸ê®Æ¬°¡u¨ä¥L°ÝÃD¡v¡u¨ä¥L¡v¡C


ÀH¨­ºÐ¸Ì­±¥u¦³¥X²{autorun.inf~¨S¦³RECYCLERªº¸ê®Æ§¨ §R±¼¤F·|´_­ì ³o¼Ë¦³¼vÅT¶Ü................ ¸Ó§R¶Ü? ¸Ó§Rªº¸Ü «ç»ò§R°Ç?



­º¥ý®¥³ß§A¡A§A¤¤¤F©Ò¿×ªºÀH¨­ºÐ«¬¯f¬r¡A³o¬O¤@­Ó·|·P¬V©Ò¦³¥i²¾°£¦¡´CÅ骺¯f¬r¡A¨ä¤¤¤]¥]¬A§Aªº¤@¯ëµwºÐ¡A¥L·|¦b§AªºÀH¨­ºÐ²£¥ÍAutorun.inf³o­Ó¦Û°Ê¦w¸ËÀÉ»PÃþ¦üShell.exe³o­Ó°õ¦æÀÉ¡A·í§A¶i¤J§AªºÀH¨­ºÐªº®É­Ô¡A¤]´N¬O·í§A¥Î·Æ¹«³sÂI2¤U§AªºÀH¨­ºÐºÏ°Ïªº¦P®É¡AÀH¨­ºÐ·|¹³¦w¸Ë¥úºÐ¤@¼Ë¸ü¤JAutorun.inf¦w¸ËÀÉ¡A¨Ã¥B°õ¦æ¥L©Ò©w¸qªº°õ¦æÀÉ¡AµM«á§Aªº©Ò¦³ºÏ°Ï(ºÏºÐ¾÷¤]ºâ)
³£·|³Q·P¬V¡A¤]·|²£¥Í¸òÀH¨­ºÐ¤@¼Ëªº¯f¬r¥X²{¡A³o­Ó¯f¬rªº¼vÅT­n¬Ý¦¹¯f¬rªºÅܧΨì­þ­Óµ{«×¡A¤£¹L¤@¯ë¬O¤£·|³y¦¨¤Ó¤jªº¯}Ãa¡A¥Lªº¼vÅT¦p¤U¡G
1.¥i¯à·|¯}Ãa¨Ã§R°£¥H¤Uªºµn¤JÀɸê®Æ¡GHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun
2.ÅѨú§A¬ÛÃöªº¹CÀ¸±b¸¹»P±K½X
3.·|¨Ï§A¦b³sÂI¨â¤U¶i¤J§A·Q¶i¤JªººÏ°Ïªº®É­Ô¡A³y¦¨µLªk¶i¤J¨Ã¥B¦³¥i¯à·|³y¦¨¨t²Î¥X²{¿ù»~
4.·í§A­n°õ¦æ©Ò¦³°ÆÀɦW¬°exeÀɪº®É­Ô·|¥X²{§ä¤£¨ì¥i¥H¶}±Ò¬ÛÃöexeÀɪºµ{¦¡¤§¿ù»~
-------------------------------------------------------------------------------------------
¥ý»¡©ú¤@¤U¥LªºAutorun.infªº¤º®e¡A§A¥i¥H¥Î·Æ¹«¥kÁä«ö¤U½s¿è¬d¬Ý¤º®e¡A¤@¯ë³£¬O¹³¤U­±ªº¤è¦¡¨Ó½s¼g¡G
[autorun]
shell1=Open
shell1Command=shell.exe -s
-------------------------------------------------------------------------------------------
¨ä¤¤ shell.exe ´N¬O¯f¬r°õ¦æÀÉ¡A¦]¦¹ svchost.exe ¦pªG¥X²{¦b³oÃäÀ³¸Ó¤]¬O­Ó¯f¬r¡A¤£¹Lsvchost.exe¬OÄÝ©ó§@·~¨t²Î¥»¨­´N¦³ªºÀ³¥Îµ{¦¡ÀÉ¡A¦ý¬O¥L¥¿½T¦s©ñªº¸ô®|À³¸Ó¦p¤U¡GC:WindowsSystem32¡C
¦pªGsvchost.exe¥X²{¦b¨ä¥L«DSystem32¥Ø¿ý´N¬O¤@­Ó¯f¬rÀÉ
ª©Åv«Å§i:¥»ºô­¶©Ò´£¨Ñ¤§¸ê°T,ª©Åv¬ÒÄݸê®Æ¨Ó·½ºô¯¸©Î­Ó¤H,¦p¦³¬ÛÃöºÃ°Ý,½Ð»P§Ú­Ì³sµ¸