ÊÖ»úÕ¾
ÍøÍ¨·ÖÕ¾
µçÐÅÖ÷Õ¾
ÃÜ¡¡Âë:
Óû§Ãû£º
µ±Ç°Î»Öà : Ö÷Ò³>·þÎñÆ÷¼¼Êõ>°²È«·À»¤>Áбí

ºÚ¿Í¾­Ñé֮ʵÀý½²½âľÂíµÄ·ÖÎö·½·¨

À´Ô´£º»¥ÁªÍø ×÷Õߣºwest263.com ʱ¼ä£º2008-02-23
Î÷²¿ÊýÂë-È«¹úÐéÄâÖ÷»ú10Ç¿£¡40ÓàÏîÐéÄâÖ÷»ú¹ÜÀí¹¦ÄÜ,È«¹úÁìÏÈ!Ë«Ïß¶àÏßÐéÄâÖ÷»úÄϱ±·ÃÎʳ©Í¨ÎÞ×è!Ãâ·ÑÔùËÍÆóÒµÓʾÖ,.CNÓòÃû,×ÔÖú½¨Õ¾480ÔªÆð,Ãâ·ÑÊÔÓÃ7Ìì,ÂúÒâÔÙ¸¶¿î! P4Ö÷»ú×âÓÃ799Ôª/ÔÂ.Ô¸¶Ãâѹ½ð!

ÒÔǰÓйýÒ»¿î¹ú²úľÂí£¬ËüÓиöºÃÌýµÄÃû×Ö£¬½Ð×ö¡°¹ãÍâÅ®Éú¡±¡£Õâ¸öľÂíÊǹ㶫ÍâÓïÍâó´óѧ¡°¹ãÍâÅ®Éú¡±ÍøÂçС×éµÄ×÷Æ·£¬Ëü¿ÉÒÔÔËÐÐÓÚWIN98£¬WIN98SE£¬WINME£¬WINNT£¬WIN2000»òÒѾ­°²×°Winsock2.0µÄWin95/97ÉÏ¡£ÓëÒÔÍùµÄľÂíÏà±È£¬Ëü¾ßÓÐÌå»ý¸üС¡¢Òþ²Ø¸üΪÇÉÃîµÄÌØµã¡£¿ÉÒÔÔ¤ÁÏ£¬ÔÚ½«À´µÄÈÕ×ÓÀïËü»á³ÉΪ¼Ì¡°±ùºÓ¡±Ö®ºóµÄÓÖÒ»Á÷ÐеÄľÂíÆ·ÖÖ¡£

ÓÉÓÚ¡°¹ãÍâÅ®Éú¡±Õâ¸öľÂíµÄפÁô¡¢Æô¶¯µÄ·½·¨±È½Ï¾ßÓеäÐÍÐÔ£¬ÏÂÃæÎÒ¾Íͨ¹ý¶ÔÕâÖÖÐÂÐÍľÂíµÄÏêϸ·ÖÎö¹ý³ÌÀ´Ïò´ó¼Ò²ûÊö¶ÔÒ»°ãľÂíµÄÑо¿·½·¨¡£ÏÂÃæµÄ²âÊÔ»·¾³ÎªWindows2000ÖÐÎİ档

Ò»¡¢ËùÐ蹤¾ß

1.RegSnap v2.80 ¼àÊÓ×¢²á±íÒÔ¼°ÏµÍ³Îļþ±ä»¯µÄ×îºÃ¹¤¾ß

2.fport v1.33 ²é¿´³ÌÐòËù´ò¿ªµÄ¶Ë¿ÚµÄ¹¤¾ß

3.FileInfo v2.45a ²é¿´ÎļþÀàÐ͵Ť¾ß

4.ProcDump v1.6.2 Íѿǹ¤¾ß

5.IDA v4.0.4 ·´»ã±à¹¤¾ß

¶þ¡¢·ÖÎö²½Öè

Ò»Çй¤¾ß×¼±¸¾ÍÐ÷ÁË£¬ÎÒÃÇ¿ªÊ¼·ÖÎöÕâ¸öľÂí¡£Ò»°ãµÄľÂíµÄ·þÎñÆ÷¶ËÒ»µ©ÔËÐÐÖ®ºó¶¼»á¶Ô×¢²á±íÒÔ¼°ÏµÍ³Îļþ×öһЩÊֽţ¬ËùÒÔÎÒÃÇÔÚ·ÖÎö֮ǰ¾ÍÒªÏȶÔ×¢²á±íÒÔ¼°ÏµÍ³Îļþ×öÒ»¸ö±¸·Ý¡£

Ê×ÏÈ´ò¿ªRegSnap£¬´Ófile²Ëµ¥Ñ¡new,È»ºóµãOK¡£ÕâÑù¾Í¶Ôµ±Ç°µÄ×¢²á±íÒÔ¼°ÏµÍ³Îļþ×öÁËÒ»¸ö¼Ç¼£¬Ò»»á¶ùÈç¹ûľÂíÐÞ¸ÄÁËÆäÖÐijÏÎÒÃǾͿÉÒÔ·ÖÎö³öÀ´ÁË¡£±¸·ÝÍê³ÉÖ®ºó°ÑËü´æÎªRegsnp1.rgs¡£

È»ºóÎÒÃǾÍÔÚÎÒÃǵĵçÄÔÉÏÔËÐС°¹ãÍâÅ®Éú¡±µÄ·þÎñÆ÷¶Ë£¬²»Òªº¦Å£¬ÒòΪÎÒÃÇÒѾ­×öÁ˱ȽÏÏêϸµÄ±¸·ÝÁË£¬Ëü×öµÄÊÖ½ÅÎÒÃǶ¼¿ÉÒÔÕÕÔ­Ñù¸Ä»ØÀ´µÄ¡£Ë«»÷gdufs.exe£¬È»ºóµÈһС»á¶ù¡£Èç¹ûÄãÕýÔÚÔËÐÐ×Å¡°ÌìÍø·À»ðǽ¡±»ò¡°½ðɽ¶¾°Ô¡±µÄ»°£¬Ó¦¸Ã·¢ÏÖÕâÁ½¸ö³ÌÐò×Ô¶¯Í˳öÁË£¬ºÜÆæ¹ÖÂð£¿ÇÒÌýÎÒÃǺóÃæµÄ·ÖÎö¡£ÏÖÔÚľÂí¾ÍÒѾ­×¤ÁôÔÚÎÒÃǵÄϵͳÖÐÁË¡£ÎÒÃÇÀ´¿´Ò»¿´Ëü¾¿¾¹¶ÔÎÒÃǵÄ×öÁËÄÄЩ²Ù×÷¡£ÖØÐ´ò¿ªRegSnap£¬´Ófile²Ëµ¥Ñ¡new,È»ºóµãOK£¬°ÑÕâ´ÎµÄsnap½á¹û´æÎªRegsnp2.rgs¡£

´ÓRegSnapµÄfile²Ëµ¥Ñ¡ÔñCompare£¬ÔÚFirst snapshotÖÐÑ¡Ôñ´ò¿ªRegsnp1.rgs£¬ÔÚSecond snapshotÖÐÑ¡Ôñ´ò¿ªRegsnp2.rgs£¬²¢ÔÚÏÂÃæµÄµ¥Ñ¡¿òÖÐÑ¡ÖÐShow modifiedkey names and key values¡£È»ºó°´OK°´Å¥£¬ÕâÑùRegSnap¾Í¿ªÊ¼±È½ÏÁ½´Î¼Ç¼ÓÖÊ²Ã´Çø±ðÁË£¬µ±±È½ÏÍê³Éʱ»á×Ô¶¯´ò¿ª·ÖÎö½á¹ûÎļþRegsnp1-Regsnp2.htm¡£

¿´Ò»ÏÂRegsnp1-Regsnp2.htm£¬×¢ÒâÆäÖеģº

Summary info:

Deleted keys: 0

Modified keys: 15

New keys : 1

Òâ˼¾ÍÊÇÁ½´Î¼Ç¼ÖУ¬Ã»ÓÐɾ³ý×¢²á±í¼ü£¬ÐÞ¸ÄÁË15´¦×¢²á±í£¬ÐÂÔö¼ÓÁËÒ»´¦×¢²á±í¡£ÔÙ¿´¿´ºó±ßµÄ£º

File list in C:\WINNT\System32\*.*



Summary info:

Deleted files: 0

Modified files: 0

New files : 1



New files

diagcfg.exe Size: 97 792 , Date/Time: 2001Äê07ÔÂ01ÈÕ 23:00:12

--------------

Total positions: 1

ÕâÒ»¶Î»°µÄÒâ˼¾ÍÊÇ£¬ÔÚC:\WINNT\System32\Ŀ¼ÏÂÃæÐÂÔö¼ÓÁËÒ»¸öÎļþdiagcfg.exe£¬Õâ¸öÎļþ·Ç³£¿ÉÒÉ£¬ÒòΪÎÒÃÇÔڱȽÏÁ½´ÎϵͳÐÅÏ¢Ö®¼äÖ»ÔËÐÐÁË¡°¹ãÍâÅ®Éú¡±Õâ¸öľÂí£¬ËùÒÔÎÒÃÇÓÐÀíÓÉÏàÐÅdiagcfg.exe¾ÍÊÇľÂíÁôÔÚϵͳÖеĺóÃųÌÐò¡£²»ÐŵϰÄã´ò¿ªÈÎÎñ¹ÜÀíÆ÷¿´Ò»Ï£¬»á·¢ÏÖÆäÖÐÓÐÒ»¸öDIAGCFG.EXEµÄ½ø³Ì£¬Õâ¾ÍÊÇľÂíµÄÔ­Éí¡£µ«Õâ¸öʱºòǧÍò²»ÒªÉ¾³ýDIAGCFG.EXE£¬·ñÔòϵͳ¾ÍÎÞ·¨Õý³£ÔËÐÐÁË¡£

ľÂíÒ»°ã¶¼»áÔÚ×¢²á±íÖÐÉèÖÃһЩ¼üÖµÒÔ±ãÒÔºóÔÚϵͳÿ´ÎÖØÐÂÆô¶¯Ê±Äܹ»×Ô¶¯ÔËÐС£ÎÒÃÇÔÙÀ´¿´¿´Regsnp1-Regsnp2.htmÖÐÄÄЩע²á±íÏî·¢ÉúÁ˱仯£¬Æ¾½è¾­ÑéÓ¦¸Ã×¢Òâµ½ÏÂÃæÕâÌõÁË£º

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\@



Old value: String: ""%1" %*"

New value: String: "C:\WINNT\System32\DIAGCFG.EXE "%1" %*"

Õâ¸ö¼üÖµÓÉÔ­À´µÄ"%1" %*±»ÐÞ¸ÄΪÁËC:\WINNT\System32\DIAGCFG.EXE "%1" %*£¬ÒòΪÆäÖаüº¬ÁËľÂí³ÌÐòDIAGCFG.EXEËùÒÔ×îΪ¿ÉÒÉ¡£ÄÇôÕâ¸ö×¢²á±íÏîÓÐʲô×÷ÓÃÄØ£¿

Ëü¾ÍÊÇÔËÐпÉÖ´ÐÐÎļþµÄ¸ñʽ£¬±»¸Ä³ÉC:\WINNT\System32\DIAGCFG.EXE "%1"¡£%*Ö®ºóÿ´ÎÔÙÔËÐÐÈκοÉÖ´ÐÐÎļþʱ¶¼ÒªÏÈÔËÐÐC:\WINNT\System32\DIAGCFG.EXEÕâ¸ö³ÌÐò¡£

Ô­À´Õâ¸öľÂí¾ÍÊÇͨ¹ýÕâÀï×öÁËÊֽţ¬Ê¹×Ô¼ºÄܹ»×Ô¶¯ÔËÐУ¬ËüµÄÆô¶¯·½·¨ÓëÒ»°ãÆÕͨľÂí²»Ì«Ò»Ñù£¬Ò»°ãµÄľÂíÊÇÔÚ

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run*

ÎÄÕÂÕûÀí£ºÎ÷²¿ÊýÂë--רҵÌṩÓòÃû×¢²á¡¢ÐéÄâÖ÷»ú·þÎñ
http://www.west263.com
ÒÔÉÏÐÅÏ¢ÓëÎÄÕÂÕýÎÄÊDz»¿É·Ö¸îµÄÒ»²¿·Ö,Èç¹ûÄúÒª×ªÔØ±¾ÎÄÕÂ,Çë±£ÁôÒÔÉÏÐÅÏ¢£¬Ð»Ð»!