×¢²á±í±à¼­

    µØÇòÈ˶¼ÖªµÀÒþ²ØÎļþÔÚĬÈÏ״̬ÏÂÊDz»ÏÔʾÔÚÎļþ¼Ð´°¿ÚÖеģ¬¿ÉÊÇÓг¯Ò»ÈÕÎÒÃÇÐèҪʹÓÃÒþ²ØÎļþʱ£¬³£³£»á´ò¿ªÏµÍ³µÄ“Îļþ¼ÐÑ¡Ïî”ÉèÖô°¿Ú£¬À´Ñ¡ÖГÏÔʾËùÓÐÎļþºÍÎļþ¼Ð”£¬½«Òþ²ØÎļþÖØÐÂÏÔʾÔÚÑÛǰ¡£¿ÉÊÂʵÉÏ£¬ÎÒÃÇÓÐʱ¼´Ê¹Ñ¡ÖÐÁË“ÏÔʾËùÓÐÎļþºÍÎļþ¼Ð”£¬Òþ²ØÎļþ»¹ÊDz»¿Ï“ÏÖÉ픣¬ÕâÊÇÔõô»ØÊÂÄØ£¬ÎÒÃÇÓÖ¸ÃÈçºÎ²ÅÄÜÈÃÒþ²ØÎļþ“ÏÖÉí”ÄØ£¿

    ÆäʵÒþ²ØÎļþ²»¿Ï“ÏÖÉ픣¬¶à°ëÊÇϵͳÊܵ½ÁËÒ»ÖÖÃûΪ“sxs.exe”²¡¶¾µÄ¹¥»÷£¬¸Ã²¡¶¾µÄÈ«³Æ½ÐTrojan.PSW.QQPass.pqb²¡¶¾£¬ËüÒ»°ãͨ¹ý³£ÓõÄÉÁÅÌ»òÒÆ¶¯Ó²Å̽øÐзǷ¨´«²¥£¬¸Ã²¡¶¾µÄÖ÷ҪΣº¦¾ÍÊÇÇ¿ÐÐÖÕÖ¹°²×°ÔÚ±¾µØÏµÍ³ÖеķÀ²¡¶¾Èí¼þµÄÓ¦Óýø³Ì£¬½µµÍ±¾µØ¼ÆËã»úϵͳµÄ°²È«µÈ¼¶£¬Í¬Ê±»¹»á͵ÇÔ±¾µØµÄQQÃÜÂëÓëÕʺţ»Ò»µ©¼ÆËã»úϵͳ²»Ð¡ÐĸÐȾÁË“sxs.exe”²¡¶¾ºó£¬ÏµÍ³µÄÿ¸ö·ÖÇø¸ùĿ¼´°¿ÚÖж¼»á³öÏÖ“sxs.exe”ÎļþºÍ“autorun.inf”Îļþ£¬¶øÇÒÓÃÊó±êË«»÷ϵͳ·ÖÇøÅÌ·û£¬ÏµÍ³Ã»ÓÐÈκη´Ó¦£¬¸üÎªÖØÒªµÄÊÇÎÞ·¨½«ÏµÍ³µÄÒþ²ØÎļþÕý³£ÏÔʾ³öÀ´¡£

    Òò´Ë£¬µ±ÎÒÃÇÑ¡ÖÐÁ˱¾µØÏµÍ³ÖеēÏÔʾËùÓÐÎļþºÍÎļþ¼Ð”¹¦ÄÜÑ¡Ïîºó£¬ÈÔÈ»ÎÞ·¨ÈÃÒþ²ØÎļþ“ÏÖÉí”ʱ£¬ÎÒÃÇÖ»Òª½øÈëϵͳÈÎÎñ¹ÜÀíÆ÷µÄ½ø³Ì±êÇ©Ò³Ãæ£¬¿´¿´ÏµÍ³ÖÐÊÇ·ñÔËÐÐÁË“svohost.exe”»ò“sxs.exe”ÕâÑùµÄ·þÎñ½ø³Ì£¬Ò»µ©¿´µ½µÄ»°£¬ÄǾͱíÃ÷Òþ²ØÎļþµÄÈ·Êܵ½ÁË“sxs.exe”²¡¶¾µÄ¿ØÖÆ¡£ÒªÏëÇ¿ÐÐÈÃÒþ²ØÎļþ“ÏÖÉ픣¬ÎÒÃDZØÐë°´ÕÕÈçÏ·½·¨½«“sxs.exe”²¡¶¾ÇÉÃî´ÓϵͳÖÐÇå³ý¸É¾»¡£

    Ê×ÏÈͬʱ°´Ï¼üÅÌÉϵÄCtrl+Alt+Del¸´ºÏ¼ü£¬´ò¿ªÏµÍ³µÄÈÎÎñ¹ÜÀíÆ÷´°¿Ú£¬µ¥»÷¸Ã´°¿ÚÖеē½ø³Ì”±êÇ©£¬²¢ÔÚ¶ÔÓ¦±êÇ©Ò³ÃæÖÐÑ¡ÖГsvohost.exe”»ò“sxs.exe”ÕâÑùµÄ½ø³Ì£¬ÔÙµ¥»÷“½áÊø½ø³Ì”°´Å¥£¬ÕâÑù¾ÍÄܽ«“sxs.exe”²¡¶¾µÄ½ø³ÌÇ¿ÐнûÖ¹ÁË¡£

    ½Ó×ÅÒÀ´Îµ¥»÷“¿ªÊ¼”/“ÔËÐДÃüÁ´ò¿ªÏµÍ³µÄÔËÐжԻ°¿ò£¬ÔÚÆäÖÐÊäÈë“regedit”×Ö·û´®ÃüÁµ¥»÷“È·¶¨”°´Å¥ºó£¬½øÈëµ½±¾µØ¼ÆËã»úµÄϵͳע²á±í±à¼­´°¿Ú£»Ôڸñ༭´°¿ÚµÄ×ó²àÏÔʾ´°¸ñÖУ¬ÓÃÊó±êÕ¹¿ª“HKEY_LOCAL_MACHINE”·ÖÖ§ÏîÄ¿£¬²¢Ôڸ÷ÖÖ§ÏîÄ¿ÏÂÃæÔÙÒÀ´ÎÑ¡Ôñ“SOFTWARE/Microsoft/
Windows/CurrentVersion/Explorer/Advanced/Folder/Hidden/SHOWALL”×ÓÏÔÚ¶ÔÓ¦“SHOWALL”×ÓÏîµÄÓÒ²àÁбíÇøÓòÖУ¨Èçͼ1Ëùʾ£©£¬¼ì²éÒ»ÏÂÊÇ·ñ´æÔÚÒ»¸öÃûΪ“CheckedValue”µÄË«×Ö½ÚÖµ¡£ÔÚÕâÀï´ó¼ÒÐèÒªÁôÐĵÄÊÇ£¬Ò»µ©¼ÆËã»úϵͳÔâÊܵ½“sxs.exe”²¡¶¾µÄ¹¥»÷Ö®ºó£¬“CheckedValue”¼üÖµµÄÀàÐͺÜÓпÉÄܱ»Ð޸ijÉ×Ö·û´®ÖµÀàÐ͵ģ¬ÕâÖÖÀàÐ͵ļüÖµÊǸù±¾Ã»Óõģ»

ͼ1

    Òò´Ëµ±ÎÒÃÇ¿´µ½“SHOWALL”×ÓÏîÏÂÃæ²»´æÔÚ“CheckedValue”¼üÖµ£¬»òÕß·¢ÏָüüÖµÀàÐͲ»¶Ôʱ£¬ÏȽ«ÎÞÓõÄ×Ö·û´®Öµ“CheckedValue”ɾ³ýµô£¬È»ºóÓÃÊó±êÓÒ¼üµ¥»÷“SHOWALL”×ÓÏîÓÒ²àÁбíÇøÓòµÄ¿Õ°×λÖô¦£¬´ÓËæºóµ¯³öµÄ¿ì½Ý²Ëµ¥ÖÐÒÀ´ÎÑ¡Ôñ“н¨”/“DwordÖµ”ÃüÁ²¢½«¸Õ¸Õ´´½¨µÄË«×Ö½ÚÖµÃû³ÆÉèÖÃΪ“CheckedValue”£»½ô½Ó×ÅÓÃÊó±êË«»÷¸Õ¸Õ´´½¨ºÃµÄ“CheckedValue”Ë«×Ö½ÚÖµ£¬ÔÚµ¯³öµÄ±à¼­DwordÖµÉèÖô°¿ÚÖУ¬½«Êý×Ö“1”Ö±½ÓÌîдÔÚ“ÊýÖµÊý¾Ý”Îı¾¿òÖУ¨Èçͼ2Ëùʾ£©£¬ÔÙµ¥»÷“È·¶¨”°´Å¥½áÊøÉèÖòÙ×÷£¬×îºóÔÙ½«¼ÆËã»úÏµÍ³ÖØÐÂÆô¶¯Ò»Ï£»

ͼ2

·ÀÖ¹ÔٴθÐȾ

    ÏÂÃæÎªÁË·ÀÖ¹“sxs.exe”²¡¶¾“¾íÍÁÖØÀ´”£¬ÔٴζÔϵͳ×ö³ö²»ÀûµÄÊÂÇé³öÀ´£¬ÎÒÃÇ»¹ÐèÒªÓÃÊó±êÓÒ¼üµ¥»÷ϵͳ·ÖÇøÅÌ·û£¬´Óµ¯³öµÄ¿ì½Ý²Ëµ¥ÖÐÖ´ÐГ´ò¿ª”ÃüÁºÇºÇ£¬¾¡Á¿²»ÒªÊ¹ÓÃË«»÷Êó±êµÄ·½·¨´ò¿ªÏµÍ³·ÖÇø¸ùĿ¼Ӵ£¬Õâ¿ÉÄÜ»á°ïÖú“sxs.exe”²¡¶¾ÓÖÖ´ÐÐÒ»´ÎÆÆ»µ²Ù×÷Ó´£©£¬½øÈ뵽ϵͳ·ÖÇø¸ùĿ¼´°¿Ú£¬½«ÆäÖеēsxs.exe”ÎļþºÍ“svohost.exe”ÎļþÖ±½Óɾ³ýµô¡£È»ºóÔٴνøÈ뵽ϵͳµÄ×¢²á±í±à¼­´°¿Ú£¬ÓÃÊó±êÕ¹¿ªÆäÖеēHKEY_LOCAL_MACHINE”·ÖÖ§ÏîÄ¿£¬²¢Ôڸ÷ÖÖ§ÏîÄ¿ÏÂÃæÒÀ´ÎÑ¡Ôñ“SOFTWARE/Microsoft/Windows/CurrentVersion/Run”×ÓÏÔÚ¶ÔÓ¦“Run”×ÓÏîµÄÓÒ²àÁбíÇøÓòÖУ¬¼ì²éÒ»ÏÂÊÇ·ñ´æÔÚÒ»¸öÃûΪ“SoundMam”µÄ×Ö·û´®Öµ£¬ÒªÊÇ·¢ÏÖ¸Ã×Ö·û´®Öµ´æÔڵϰ£¬ÔÙÓÃÊó±êË«»÷¸Ã¼üÖµ£¬´Óµ¯³öµÄÊýÖµÉèÖô°¿ÚÖУ¬È·ÈÏһϸÃ×Ö·û´®¼üÖµµÄÄÚÈÝÊÇ·ñΪ“C:/Windows/system32/svohost.exe”£¬Ö®ºóÑ¡ÖГSoundMam”×Ö·û´®Öµ²¢½«Ëüɾ³ýµô£¬²¢Í˳ö×¢²á±í±à¼­´°¿Ú£»

    ÏÖÔÚ´ò¿ªÏµÍ³µÄ×ÊÔ´¹ÜÀíÆ÷´°¿Ú£¬½øÈ뵽ϵͳ·ÖÇøÄ¿Â¼ÏÂÃæµÄ“system32”×ÓÎļþ¼Ð´°¿Ú£¬ÔÙ½«¸Ã´°¿ÚÖеēsxs.exe”ÎļþºÍ“svohost.exe”ÎļþÖ±½Óɾ³ýµô£¬×îºóÔÙ½øÐÐÒ»´ÎϵͳÆô¶¯²Ù×÷£¬ÏàÐÅÕâôһÀ´ÎÒÃÇÔٴδò¿ª“Îļþ¼ÐÑ¡Ïî”ÉèÖô°¿Ú£¬²¢Ñ¡ÖГÏÔʾËùÓÐÎļþºÍÎļþ¼Ð”ʱ£¬¶à°ëÄܹ»½«Òþ²ØµÄϵͳÎļþÖØÐÂÏÔÏÖ³öÀ´ÁË¡£