ÎÒÊÇÒ»ÃûÍøÂç¹ÜÀíÔ±£¬¹«Ë¾µÄ·þÎñÆ÷¶¼ÓÉÎÒºÍÁíÒ»ÃûÍø¹Ü¸ºÔð¡£ÔÚʵ¼ÊʹÓùý³ÌÖÐÎÒÃÇÁ½¸ö¶¼ÖªµÀ·þÎñÆ÷µÄÓû§ÃûºÍÃÜÂ룬ÎÒ×Ô¼º¿ª·¢ÁËÒ»¸öС¹¤¾ß£¬ÊǼì²âÍøÂçÖÐÁ÷Á¿µÄ¡£ËùÒÔ°ÑÕâ¸ö³ÌÐò·Åµ½ÁËÆô¶¯ÏîÖУ¬ÕâÑù¿ÉÒÔÔÚÿ´Î·þÎñÆ÷Æô¶¯»òµÇ¼µ½×ÀÃæÊ±×Ô¶¯ÔËÐÐÕâ¸öÁ÷Á¿¼à²â³ÌÐò¡£²»¹ýÓÉÓÚÁíÒ»ÃûÍøÂç¹ÜÀíÔ±Ò²ÖªµÀ·þÎñÆ÷µÄÃÜÂ룬Ëûʱ²»Ê±µÄ×ÜÊÇÒª¹ÜÀíÕą̂·þÎñÆ÷£¬¾³£°ÑÆô¶¯ÏîÖеÄËùÓгÌÐò¶¼Çå¿ÕÀ´ÓÅ»¯ÏµÍ³¡£ÄÇôÏñʹÓÃ×¢²á±íÖÐRUNÖµºÍ³ÌÐòÆô¶¯ÏîµÈ·½·¨À´¼ÓÔØ³ÌÐò¹ýÓÚ¼òµ¥£¬ÊÇ·ñÓÐÒ»ÖÖ·½·¨¿ÉÒÔ°ÑÆÕͨµÄ¿ÉÖ´ÐÐEXE³ÌÐò»òBATÎļþ±ä³Éij¸ö·þÎñµÄÐÎʽÀ´ÔËÐÐÄØ£¿ÕâÑùÄǸö¹ÜÀíÔ±¾Í²»»á´íÎóµÄ½«ÓÃÓÚÍøÂç¹ÜÀíµÄС³ÌÐòɾ³ýÁË¡£ ÎÒÊǹ«Ë¾µÄÍø¹Ü£¬¹«Ë¾ÄÚ²¿Ê¹ÓÃÁËÊý¾Ý¿âÀ´¹ÜÀí×ÊÔ´£¬µ«ÊÇÕâ¸öÊý¾Ý¿âÊÇÒ»¸öEXE³ÌÐò£¬¿ªÊ¼ÎÒ°Ñ´ËEXE³ÌÐò·Åµ½ÁË×¢²á±íÖУ¬µ«ÊÇ·þÎñÆ÷¾³£»á³öÏÖÕâÑù»òÄÇÑùµÄÎÊÌ⣬Èç¹ûÎÒ²»ÔÚÉí±ßÖ»ÄÜͨ¹ýÆäËûÈËÔ±À´ÖØÐÂÆô¶¯¸Ã·þÎñÆ÷£¬µ«ÊÇÓÉÓÚÎÞ·¨¸æËß¶Ô·½Óû§ÃûºÍÃÜÂëËùÒÔ¸ÃEXE³ÌÐòÔÚ×¢²á±íÖÐÊÇÎÞ·¨ÔËÐеģ¬ÒòΪûÓеǼϵͳ¡£¶øÎÒÒ²³¢ÊÔ¹ý½«Æä¼Óµ½¿ª»ú½Å±¾ÖУ¬µ«ÊÇEXE³ÌÐò²»ÏñBATÅú´¦ÀíÎļþÄÇÑù¿ÉÒÔ±»ÕýÈ·Ìí¼Ó£¬ËùÒÔÔÚÕâÀïѯÎÊIT168µÄר¼Ò£¬ÊÇ·ñÓа취½«Õâ¸öEXE³ÌÐò±ä³É·þÎñ£¬²¢ÔÚ¿ª»úºóºÍµÇ¼ϵͳ×ÀÃæÇ°×Ô¶¯ÔËÐÐÄØ£¿ ¡¾ÍøÓѽâ´ð¡¿½«Ä³¸ö³ÌÐò×¢²á³Éϵͳ·þÎñÒ»Ö±ÊÇÖÚ¶àÍøÂç¹ÜÀíÔ±¹ØÐĵϰÌ⣬ÕýÈçÉÏÃæÁ½¸öÍøÓÑÌá³öµÄÎÊÌâÒ»Ñù£¬ºÜ¶àС¹¤¾ßС³ÌÐò²¢²»ÊÇÒÔ·þÎñµÄÉí·Ý½ø×¤ÏµÍ³µÄ£¬¶øÊµ¼ÊÖÐÓÖÐèÒªËûÃǵÄÔËÐС£Õâʱºò¾Í¿ÉÒÔʹÓñ¾ÎĽéÉܵÄС¹¤¾ß½«ÕâЩС¹¤¾ßС³ÌÐò×¢²á³Éϵͳ·þÎñ£¬´Ó¶øÊµÏָóÌÐòËæÏµÍ³µÄÆô¶¯¶øÆô¶¯¡£ ÕâÀïÎÒ¸ø´ó¼Ò½éÉܵÄÈí¼þÃû³ÆÎª¡ª¡ªwindows²Ù×÷ϵͳÖзþÎñµÄÌí¼ÓºÍɾ³ýС¹¤¾ß£¬ËûÖ»ÓÐÒ»¸öservices.exeÎļþ£¬ÊÇÓɸßˮƽµÄÍøÓÑ¿ª·¢²¢·¢²¼µÄ¡£ÕýÈ簲װ˵Ã÷ÖÐËù˵µÄÒ»Ñù£¬services.exeʵ¼ÊÉÏÊÇÒ»¸ö½âѹËõ³ÌÐò£¬¸ÃѹËõ°üÀïÃæ°üº¬ÁËÈý¸ö³ÌÐòsrvinstw.exe,instsrv.exe,srvany.exe¡£ÎÒÃÇÖ±½ÓÔËÐÐservices.exeÀ´Æô¶¯½âѹËõ¹¤×÷¡££¨Èçͼ1£©Í¨¹ý¡°ä¯ÀÀ¡±°´Å¥Ñ¡Ôñ½âѹËõ·¾¶¡£¹ØÓÚservices.exe·þÎñ×¢²á¹¤¾ß½«Ë渽¼þÌṩ¸ø¸÷λ¶ÁÕß¡£
½âѹËõÍê±ÏºóÎÒÃǾͻῴµ½srvinstw.exe£¬instsrv.exe£¬srvany.exeÕâÈý¸ö³ÌÐò¡£ÆäÖÐinstsrv.exeºÍsrvany.exe³ÌÐòÎÒÃDz»ÓÃÀí»á£¬Ö±½ÓÔËÐÐsrvinstw.exe³ÌÐò¼´¿É¡£ËùÓеķþÎñ°²×°ºÍÐ¶ÔØ¹¤×÷¶¼¿ÉÒÔÓÉÕâ¸ö³ÌÐòÍê³É£¬Ëû½«×Ô¶¯µ÷ÓÃinstsrv.exeºÍsrvany.exeÍê³É·þÎñµÄÔö¼õÈÎÎñ¡££¨Èçͼ2£©
| ||||
£¨1£©É¾³ýij¸ö·þÎñ£º
ÎÒÃÇ¿ÉÒÔͨ¹ýsrvinstw.exeÀ´É¨Ãè±¾µØ¼ÆËã»ú²Ù×÷ϵͳÖеÄËùÓзþÎñ£¬¿ÉÒÔ½«ÈκÎÒ»¿î·þÎñɾ³ý£¬ÆäÖаüÀ¨Ò»Ð©ÏµÍ³×Ô´øµÄ·þÎñ¡£ÕâÑù¾Í¿ÉÒÔÈÃÎÒÃǵķþÎñÆ÷ÔËÐÐЧÂʸü¸ß¡£
µÚÒ»²½£ºÔËÐÐsrvinstw.exe³ÌÐò¡££¨Èçͼ3£©
![]() |
| ͼ3 |
µÚ¶þ²½£ºÔÚÑ¡Ôñ²Ù×÷´¦µã¡°remove a service¡±¡£È»ºóµã¡°ÏÂÒ»²½¡±ºó¼ÌÐø¡££¨Èçͼ4£©
![]() |
| ͼ4 |
µÚÈý²½£º½ÓÏÂÀ´ÎÒÃÇ¿ÉÒÔÑ¡Ôñ±¾µØ¼ÆËã»ú»òÕßÔ¶³Ì¼ÆËã»ú£¬Èç¹ûÄãÑ¡ÔñÔ¶³Ì¼ÆËã»úµÄ»°ÐèÒª¸ø³ö¼ÆËã»úÃû²¢ÇÒÒªÌṩ¸Ã¼ÆËã»úµÄ¹ÜÀíÔ±ÕÊ»§ÃûºÍÃÜÂë¡£Ò»°ãÀ´ËµÎÒÃǶ¼Ñ¡Ôñlocal machine±¾µØ¼ÆËã»ú¼´¿É£¬¡°ÏÂÒ»²½¡±ºó¼ÌÐø¡££¨Èçͼ5£©
![]() |
| ͼ5 |
µÚËIJ½£ºÈ»ºóÎÒÃǾͻᷢÏÖÔÚservice name´¦µÄÏÂÀ²Ëµ¥ÏÔʾ³öÁ˱¾µØ¼ÆËã»úÈ«²¿·þÎñÃû³Æ£¬Èç¹ûÎÒÃǰÑÏ·½µÄinclude device driversÒ²¹´Éϵϰ»¹»áÏÔʾ³öËùÓÐÉ豸Çý¶¯¡££¨Èçͼ6£©
![]() |
| ͼ6 |
µÚÎå²½£ºÎÒÃÇËæ±ãÕÒÒ»¸ö·þÎñÀ´ÑÝʾɾ³ý·þÎñµÄÀý×Ó£¬ÀýÈçremote registryÔ¶³Ì×¢²á±í·þÎñ£¬Ò»°ãÕâ¸ö·þÎñûʲôÓã¬Ä¬È϶¼ÊÇÒª½ûÓõģ¬ÕâÑù±ÜÃâÁ˺ڿÍͨ¹ýÍøÂçÁ¬½Ó×¢²á±íÀ´ÈëÇָüÆËã»ú¡£
µÚÁù²½£ºÑ¡Ôñremote registryºóµã¡°ÏÂÒ»²½¡±¡££¨Èçͼ7£©
![]() |
| ͼ7 |
µÚÆß²½£ºÈí¼þÏÔʾ½«ÒªÉ¾³ýremote registry·þÎñ£¬µã¡°Íê³É¡±°´Å¥ºóremote registry·þÎñ½«±»É¾³ý¡££¨Èçͼ8£©
![]() |
| ͼ8 |
µÚ°Ë²½£ºÈí¼þµ¯³öremove successɾ³ý³É¹¦µÄÌáʾ¡££¨Èçͼ9£©
![]() |
| ͼ9 |
µÚ¾Å²½£ºµ±ÎÒÃÇÔÙ´Îͨ¹ý×ÀÃæ¡°¿ªÊ¼->ÔËÐÐ->ÊäÈëservices.msc¡±Æô¶¯·þÎñÉèÖô°¿Úºó½«ÔÙÒ²¿´²»µ½remote registry·þÎñÁË¡£ÎÒÃÇÒѾ½«Ëû³¹µ×ɨ³öϵͳ¡££¨Èçͼ10£©
![]() |
| ͼ10 µã»÷¿´´óͼ |
ͨ¹ýsrvinstw.exe¿ÉÒÔɾ³ýϵͳĬÈϺÍ×Ô´øµÄ·þÎñ£¬Ò²¿ÉÒÔÐ¶ÔØµÚÈý·½Ìí¼ÓµÄϵͳ·þÎñ£¬ÕâÑùÎÒÃǵÄϵͳ½«»áÔËÐеøü¿ì£¬±ÜÃâÁËϵͳ×ÊÔ´µÄÀË·Ñ¡£
£¨2£©Ìí¼Óij¸ö·þÎñ£º
ÕâÀïËù˵µÄÌí¼Óij¸ö·þÎñÊÇÖ¸½«Ä³¸öÓ¦ÓóÌÐò»òµ¥¶À¿ÉÖ´ÐÐÎļþ×¢²á³É·þÎñ£¬²¢ÉèÖÃÎªËæÏµÍ³µÄÆô¶¯¶øÆô¶¯¡£µ±È»¸Ã³ÌÐòµÄÆô¶¯ÊÇÒÔ·þÎñµÄÐÎʽÔËÐеģ¬ËùÒԾ߱¸ÁËËùÓзþÎñÆô¶¯µÄÓŵ㣬¼´¼ÆËã»úÆô¶¯ÔòÆô¶¯£¬ÔÚϵͳºǫ́Æô¶¯£¬¿ÉÒÔÇáËɵÄÐÞ¸ÄÆô¶¯·½Ê½ºÍËæÊ±Í¨¹ý¹Ø±Õ·þÎñÀ´×èÖ¹¸Ã³ÌÐòµÄÔËÐС£Ìí¼Óij¸ö³ÌÐòΪ·þÎñͬÑùÊÇÀûÓÃsrvinstw.exeÀ´Íê³É¡£
µÚÒ»²½£ºÔËÐÐsrvinstw.exe³ÌÐò¡£
µÚ¶þ²½£ºÔÚÑ¡Ôñ²Ù×÷´¦µã¡°install a service¡±¡£È»ºóµã¡°ÏÂÒ»²½¡±ºó¼ÌÐø¡£
µÚÈý²½£º½ÓÏÂÀ´ÎÒÃÇ¿ÉÒÔÑ¡Ôñ±¾µØ¼ÆËã»ú»òÕßÔ¶³Ì¼ÆËã»ú£¬Èç¹ûÄãÑ¡ÔñÔ¶³Ì¼ÆËã»úµÄ»°ÐèÒª¸ø³ö¼ÆËã»úÃû²¢ÇÒÒªÌṩ¸Ã¼ÆËã»úµÄ¹ÜÀíÔ±ÕÊ»§ÃûºÍÃÜÂë¡£Ò»°ãÀ´ËµÎÒÃǶ¼Ñ¡Ôñlocal machine±¾µØ¼ÆËã»ú¼´¿É£¬¡°ÏÂÒ»²½¡±ºó¼ÌÐø¡£
µÚËIJ½£ºÎª×¢²áµÄÕâ¸ö·þÎñÆðÒ»¸öÃû×Ö£¬ÀýÈçÎÒÃÇÏë°ÑQQÕâ¸ö³ÌÐò×¢²á³É·þÎñ£¬ÄÇôÔÚservice name´¦Ð´QQ¡££¨Èçͼ11£©
![]() |
| ͼ11 |
µÚÎå²½£º½ÓÏÂÀ´ÊÇÑ¡ÔñÒª°ÑÄĸö³ÌÐò×¢²á³ÉÃûΪQQµÄ·þÎñ£¬Í¨¹ýbrowse°´Å¥À´Ñ¡Ôñ¡££¨Èçͼ12£©
![]() |
| ͼ12 |
µÚÁù²½£º¶ÔÓÚÄÇЩ½ö½öÓÐÒ»¸öÎļþµÄ³ÌÐòÀ´ËµÎÒÃÇ»¹¿ÉÒÔͨ¹ý¹´Ñ¡move file to system32 directory½«¸ÃÎļþ¸´ÖƵ½ÏµÍ³µÄsystem32Ŀ¼ÖУ¬ÕâÑù¸ü·½±ã¹ÜÀí¡£
µÚÆß²½£ºÈ»ºóÑ¡Ôñ¸Ã·þÎñµÄÀàÐÍ£¬ÒÀ´ÎΪservice is its own process£¨·þÎñΪÆä×ÔÉí½ø³Ì£¬²»µ÷ÓÃÆäËû½ø³Ì£©£¬file system driver£¨ÎļþϵͳÇý¶¯£©£¬device driver£¨É豸Çý¶¯£©¡£Ò»°ãÀ´ËµÎÒÃÇÑ¡ÔñµÚÒ»¸öÈ÷þÎñΪÆä×ÔÉí½ø³Ì£¬²»µ÷ÓÃÆäËû½ø³Ì¼´¿É¡££¨Èçͼ13£©
![]() |
| ͼ13 |
µÚ°Ë²½£ºÈ»ºóÑ¡ÔñÔËÐи÷þÎñµÄÓû§£¬Ñ¡ÖÐother accountºóÊäÈë¾ßÓÐÄܹ»ÔËÐзþÎñȨÏÞµÄÓû§ÃûºÍÃÜÂë¡££¨Èçͼ14£©
![]() |
| ͼ14 |
СÌáʾ£ºÎÒÃÇÒ²¿ÉÒÔÖ±½ÓÑ¡ÉÏÃæµÄsystem account£¬Ëû½«×Ô¶¯ÒÔµ±Ç°ÏµÍ³µÇ¼ÕÊ»§µÄȨÏÞÈ¥Æô¶¯¸Ã·þÎñ¡£
µÚ¾Å²½£ºÈ»ºóÑ¡Ôñ¸Ã·þÎñµÄ×Ô¶¯ÔËÐз½Ê½£¬ºÍÕý³£µÄ·þÎñÒ»ÑùÓÐ×Ô¶¯ÔËÐУ¬ÊÖ¶¯ÔËÐкͽûÖ¹ÔËÐÐÈýÖÖ£¬ÎÒÃǵ±È»Ñ¡automatic×Ô¶¯ÔËÐУ¬·ñÔòËùÓй¤×÷¶¼°×¸ÉÁË¡££¨Èçͼ15£©
![]() |
| ͼ15 |
µÚÊ®²½£ºµã¡°ÏÂÒ»²½¡±°´Å¥ºóÍê³É·þÎñÌí¼Ó¹¤×÷£¬ÎÒÃǽ«qq.exeÌí¼Ó³ÉÁËÃûΪQQµÄ·þÎñ¡££¨Èçͼ16£©
![]() |
| ͼ16 |
µÚʮһ²½£º³É¹¦×¢²á³É·þÎñºóÈí¼þ»á¸ø³öinstall successµÄÌáʾ¡£
µÚÊ®¶þ²½£ºÎÒÃÇÔÙ´Îͨ¹ý×ÀÃæ¡°¿ªÊ¼->ÔËÐÐ->ÊäÈëservices.msc¡±Æô¶¯·þÎñÉèÖô°¿Úºó½«»á¿´µ½ÓÐÒ»¸öÃûΪQQµÄ·þÎñ³öÏÖÔÚÁË·þÎñ´°¿ÚÖУ¬Õâ¸ö¾ÍÊÇÎÒÃǸղÅÌí¼ÓµÄ·þÎñ£¬ÕâÑùµ±ÏµÍ³Æô¶¯Ê±QQ³ÌÐò½«»áÒÔ·þÎñµÄÐÎʽ×Ô¶¯ÔËÐС££¨Èçͼ17£©
![]() |
| ͼ17 µã»÷¿´´óͼ |
СÌáʾ£ºÊ¹ÓÃservices.exe×¢²á·þÎñÖ»ÄÜÕë¶ÔÓÚEXE¼°ÆäËû¿ÉÖ´ÐгÌÐò¶øÑÔ£¬¶ÔÓÚÄÇЩÅú´¦ÀíÎļþÎÒÃÇ»¹ÊÇÖ»ÄÜͨ¹ý¿ª»ú½Å±¾À´Íê³ÉÆäËæÏµÍ³Æô¶¯¶øÆô¶¯£¬´Ê·½·¨¶ÔÅú´¦ÀíµÈ½Å±¾ÎļþÎÞЧ¡£
×ܽ᣺
ͨ¹ýservices.exeÖеÄsrvinstw.exe³ÌÐòÎÒÃÇ¿ÉÒÔÇáËÉʵÏÖ¶Ô·þÎñµÄÌí¼ÓºÍɾ³ý£¬ÕâÑù¾Í¿ÉÒÔ°Ñʵ¼Ê¹¤×÷ºÍѧϰÖÐÐèÒª¾³£Óõ½µÄС³ÌÐò×¢²á³É·þÎñ£¬ÈÃÆäËæÏµÍ³µÄÆô¶¯¶øÆô¶¯£¬Ò²¿ÉÒÔ½«ÏµÍ³ÄÚ²¿µÄһЩûÓõĻòÕß˵¶ÔÓÚÎÒÃÇ×Ô¼º²»ºÏÊʵķþÎñ½øÐÐɾ³ý´Ó¶øÊÍ·Åϵͳ×ÊÔ´ÁË¡£Ê¹Óô˷½·¨¿ÉÒÔÇáËɵĽâ¾öÉÏÃæÁ½Î»ÍøÓÑÌá³öµÄÎÊÌ⣬һ·½ÃæÈóÌÐòÒÔ·þÎñ½øÐмÓÔØÆ¹ýÁíÍâÒ»ÃûÍøÂç¹ÜÀíÔ±£¬ÁíÒ»·½ÃæÒ²¿ÉÒ԰ѳÌÐò×¢²á³É·þÎñËæÏµÍ³µÄÆô¶¯¶øÆô¶¯£¬ÔÙÒ²²»ÐèÒªÊäÈëÓû§ÃûºÍÃÜÂëµÇ¼µ½ÏµÍ³ÖвÅÄÜÔËÐÐÁË¡£
| ×ÔÓÉ¹ã¸æÇø |
| ¡¡ |