USBÈÇÉ´õ·éECXÉöµÜµ½B gh}CNÐÈÇÅuWORM_ONLINEG.VQZvÆ\L³êéECXÅ·B Îôû@ðo¦«ÆµÄcµÄ¨«Ü·ÌÅAKvÈûÍAQlɵĺ³¢B PjECXª®µÄ¢éêA±ñÈÇóª èÜ·B±ÌECXÍA©ªðuBµt@CvɵÄöñŢܷB»Ì½ßAGNXv[ÌtH_IvVÅu·×ÄÌt@CÆtH_ð\¦·évðIðµÄ¨¯Î©³êé¤Å·B µ©µA»êðB·½ßÉA±ÌÝèðÏXÅ«È¢æ¤ÉWXgðüϵܷB ïÌIÉÍuBµt@C¨æÑBµtH_ð\¦µÈ¢vÉÝèÏXµÄµÜ¤óÅ·ªA±êðè®Åu·×ÄÌcvÉÏXµÄàAÉvpeBæÊ ðJ¢½ÉÍuBµt@C¨æÑcvÉÏíÁĵÜÁĢܷB uÉvpeBæÊðJ¢½vÆ¢¤ÌÍAÝèãuOKvðNbNµ½¼ãÉAÄÑJAÆ¢¤^C~OÅùÉuBµt@C¨æÑcvÌûÉA `FbNóªÚ®µÄ¢éÙÇÌX|XÅ·B ÂÜèA±ÌECXÉ´õµÄ¢é©Û©ÍA
Æ¢¤ÅªèÜ·B ÁÉQÉY·éêAm¦Å´õµÄ¢Ü·B ÉmF·éÌÍWXgÅ·B WXgGfB^iregedit)ÅAÌL[ÌlðmFµÜ·B HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
±ÌÉAummvavÈÇÆ¢¤Úª êÎmÀÅ·B ïÌIÉÍAȺÌGg[ª¶Ýµ½çAECX´õµÄ¢é±ÆÉÈèÜ·B mmva = "\mmvo.exe"
®Aó̪ÍAWindowsÌVXetH_ð\µÜ·B Windows2000ÈçAuc:\winnt\system32vA WindowsXPÍuc:\windows\system32v ÉAWindows98/MeÍuc:\windows\systemv Å·B ܽAíÉæÁÄÍummvvÈ~̶ñªÙÈéP[Xà éæ¤Å·B ÐÆܸA´õªªÁ½_ÅAgpÌUSBÍâÎÉgíÈ¢æ¤ÉµÄA²¢Äu¢Äº³¢B »µÄAÌèÅÎôðs¢Ü·B QjÎXebvPF©®N®·éECXð³øÉ·éJ¢Ä¢éWXgGfB^ðgÁÄAæÙÇmFµ½ummva=cvÆ¢¤ÚðíµÜ·B±êðí·éÅAñN®ÉECXðN®µÈÈèÜ·B Úðíµ½çA¼¿ÉuVbg_EvðsÁĺ³¢B ±ÌÛAuÄN®vðgí¸AêUAd¹ðØÁĺ³¢B ·×ÄÌP[Xů¶±Æª¾¦Ü·ªAd¹ðØçÈ¢ÅÄN®·éÆA³ÊÉt@CÈǪLbV ³êÄ¢éP[Xª ÁÄAÏXµ½îñªKp³ êÈ¢êª èÜ·B d¹ªØê½çATbÙÇÒÁÄÄÑd¹ðüµÜ·B RjÎXebvQFüϳê½WXgÌCN®ãAªÒÁÄ©çAÄÑWXgGfB^ðN®µÜ·B»µÄummva=vÆ¢¤ÚªµÄ¢È¢©mFµÄº³¢B µÄ¢éêADZ©ÉECXªöñŢܷB»Ì¼Ì©®N®ÚÉsRÈt@CªÈ¢©mFµÄº³¢B ummva=vÌGg[ªÈÈÁÄ¢½çAüϳê½ÌÚðC³µÜ·B êFHKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Explorer\Advanced
liüϳ
ê½ljFHidden = "dwordF00000002"
li±ÌlÉC³jFHidden = "dwordF00000001" êFHKEY_CURRENT_USER\Software\Microsoft\Windows\ CurrentVersion\Explorer\Advanced liüϳ
ê½ljFShowSuperHidden = "dwordF00000000"
li±ÌlÉC³jFShowSuperHidden = "dwordF00000001" êFHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL liüϳê½ljFCheckedValue = "dwordF00000000"
li±ÌlÉC³jFCheckedValue = "dwordF00000001" lðC³µ½çAWXgGfB^ð¶ÄAÄÑVbg_EµÜ·B ±ÌECXðì·é¾¯ÈçA{ÍKvÌÈ¢Vbg_EÅ·ªAO̽ßVbg_EµÄº³¢B »µÄAæÙÇƯlAd¹ªØê½çATbÙÇÒÁÄÄÑd¹ðüµÜ·B SjÎXebvRFECX¾ÙÌmFN®ãAWXgGfB^ðN®µAÎXebvPAQÅsÁ½ÎôªL`ƽf³êÄ¢é©mFµÄº³¢B³É½f³êÄ¢½çAGNXv[ðN®µÄAtH_IvVðmFµÜ·B ±Ì_ÅIðªu·×ÄÌt@CÆtH_ð\¦·évÉÏX³êÄ¢é͸ŷB ÏX³ê½ÌðmFµ½çAêxAuOKvðNbNµÄ»ÌæÊð¶AÄÑAtH_IvVðmFµÄº³¢B ECXª®µÄ¢È¯êÎAu·×ÄÌcvÌÜÜÉÈÁĢܷB±êÅA®SÉECX;ٵܵ½B TjÎXebvSFECXt@CÌì PECXt@CÍAUSB¾¯ÅÈA¶Ý·éhCu·×ÄÉECXð«ÝÜ·BChCuàáOÅÍ èܹñÌÅAܸÍChCuÉcÁÄ¢éECXt@CðíµÜ·B ÌSÈÍA±Ì_ÅECXðÒ®³¹éuautorun.infvªBµt@CƵĶݵĢéÆA»êÉæÁÄu©®N®vªLøÉÈÁÄ ¢é_Å·B ]ÁÄAu}CRs [^vÈÇ©çAChCuð_uNbN·éÆu©®N®vªKp³êAÄÑECXð´õ³¹ÄµÜ¢Ü·B t@Cðí·éÜÅAâÎÉGNXv[ÈÇÅChCuÈÇðJ©È¢ªdvÅ·B R}hvvgðpµÜ·B èÁæè¢û@Íut@C¼ðwèµÄÀsvÅucmdvÆüÍ·éÅ·B ±êÅAR}hvvgªJ«Ü·B ܸABµt@Cª¶Ý·é©Û©ðmFµÜ·B R}hvvgÅÌR}hðü͵ÄmFµÜ·B iR}hvvgÅÍå¶A¬¶ÍæʵܹñBDOSðgÁ½±ÆªÈ¢lª½¢ÌűñÈà¾àüêÈ«áÈçñÌÅ·Ëj DIR C:\ /AH
±êÅABµt@CÌêª\¦³êÜ·B »ÌÉAÌt@Cª êÎA»êªECX{ÌÅ·B 9rhtx.bat
ܽA{ÈçChCuÉsvÈuautorun.infvªA»êàBµt@CŶݵĢéàªèÜ·B autorun.inf
±êçQÂÌt@CÍuBµt@C®«vÅuVXet@C®«vÅuÇæêp®«vÆ¢¤RÂÌ®«ª©¯çêĢܷB ÀÉIÅ·ªA»êçÌ®«ðÌR}hÅðµÜ·B attrib
-h -s -r c:\9rhtx.bat
attrib -h -s -r c:\autorun.inf ±êÅA®«ªð³êÜ·ÌÅA±¯ÄAÌR}hÅíµÜ·B DEL
c:\9rhtx.bat
DEL c:\autorun.inf gÁÄ¢ép\RÉDhCuâEhCuÈÇA¼ÌhCuª¶Ý·éêAÎôÌuC:\v̪ðuD:\vâuE:\vÉu«·¦ÄA·×ÄÌ tH_ÅECXÖAÌt@CðíµÄº³¢B UjÎXebvTFECXt@CÌìQ±¢ÄAVXetH_ÉcÁÄ¢éECXÌêÌÌìðs¢Ü·B¯¶AR}hvvg©çÌR}hÅAECXt@CÌmFðs¢Ü·B DIR c:\windows\system32\mmv*.* /AH
iWindows98/MeÈçAc:\windows\system\mmv*.*A Windows2000ÍAc:\winnt\system32\mmv*.* ÉÈèÜ·Bj ECXt@CÍummv^vÆ¢¤t@C¼ÅAVXetH_àÉcÁĢܷB ECXª¶Ý·êÎAåïÌêQÂÌt@Cª©Â©é¤Å·B i»êÈã éêÍAVXeãAKvÈt@CÅ éÂ\«ª èÜ·B»ÌÛÍA{Ésv©Û©»fµÄ©çíµÄº³¢Bj ÎXebvSƯlA±êçÌt@CÍ©¦È¢æ¤É³êĢܷÌÅAattribR}hÅ®«ððµÜ·B attrib -h -s
-r c:\windows\system32\mmv*.*
±êÅAð³êܵ½ÌÅAt@CðíµÜ·B DEL
C:\windows\system32\mmv*.*
±êÅAECXÌêÌàí³êܵ½B OÉÍOðüêA±±ÜÅÎôµ½_ÅAVbg_E¨ÄN®ðsÁÄA®ÌL³ðmFµÄº³¢B VjÎXebvUFUSBÈÇ[oufB A©çÌí´õµ½USBÉàA¼ÌhCuƯlÉu9rhtx.batvÆuautorun.infvªBµ®«Å«ÜêĢܷB½¾AïîÈÌÍAUSBðÚ±µ½_ÅA´õ·é°êª éAÆ¢¤Å·B ÁÉA©®Ä¶ðLøɵĢÈÄàA½ç©ÌìÅ´õ·é|êª èÜ·ÌÅAUSBÍuShiftL[ ðµÈªçvÚ±µÄº³¢B ShiftL[ÍAUSBðÚ±µ½ãAµÎçAµÁÏȵɵĺ³¢B åïÌêALEDvÈǪµ_ŵܷªA_ŪûÜÁ½ AShiftL[ð£µÜ·B »µÄA´õµÄ¢éÆvíêéUSBðÚ±µ½çA»ÌhCuðmFµÜ·B µ©µA±±ÅGNXv[â}CRs [^ðJ¢ÄµÜ¤Æu©®N®vÌaHÉÈéÂ\«ªñíɢŷB ]ÁÄA¡ÜÅÌÎƯlÉR}hvvgðg¢Üµå¤B ÙÆñÇÌêAhCu¼Í{ÌÉgíêÄ¢éhCu¼ÌÌAt@xbgªèÄçêÜ·B p\R{ÌÉuChCuvuDhCuvª éêAÚ±µ½USBÍuEhCuvÉÈèÜ·ªACD/DVDhCuÈǪ¢ĢêÎA »¿çªuEhCuvÉÈÁÄ¢é¤Å·ÌÅAUSBÍuFhCuvÉÈèÜ·B um©A±ÌRs [^¾ÆAUSBÍEhCu¾æÈvÆ¢¤êA ¦ÄÌæ¤Éü͵ÄÝܵå¤B E:
¼ÉAEhCuª¶ÝµÈ¯êÎ w
è³ê½hCuª©Â©èܹñB
Æ¢¤bZ[Wª\¦³êÜ·B ܽA f
oCXÌõªÅ«Ä¢Ü¹ñB
Æ\¦³êêÎAEhCuÍCD-ROMÈÇÌüÁĢȢCD/DVDhCuÆ¢¤ÉÈèÜ·B Æè ¦¸Aà¾ãÍUSBªuEhCuvÅ éƼè·éÆABµt@CÉÈÁÄ¢éECXðì·éÌÍA¡ÜůlÌèÅÌæ¤É ü͵ÄA®«ððµíµÜ·B attrib
-h -s -r e:\9rhtx.bat
attrib -h -s -r e:\autorun.inf DEL e:\9rhtx.bat DEL e:\autorun.inf ±êÅAUSBãÌECXàì³êܵ½B »µÄA±Ì_ÅAÄÑÄN®ðs¢Ü·BWindowsÌLbV ÉA©®N®ÌîñªcÁÄ¢éêª é©çÅ·B à¿ëñAECX{Ìu9rhtx.batvÍíÏÝÈÌÅAN®³¹é±ÆÍoܹñªAXAC¿«¢ÌÅÄN®³¹é̪³ïÅ·B WjÅImFÈãÅAÎôÍ·×ÄI¹Å·BÅãÌdã°ÆµÄA´õµÄ¢½ÆvíêéUSBðp\RÉÚ±µÜµå¤B Ú±µ½ãAêÔÅÉmFµ½tH_IvVÌ®ðÄmFµÜ·B L`Æè®Åu·×ÄÌt@CÆtH_ð\¦·évªIðÅ«ÄAêx¶½ãàAÝèªèÉÏíçȯêÎìÍ®¹Å·B ½¾µAWindowsXPÈÇÅu³|CgvðLøɵĢéêÍA»êçð³øɵܷB ECXðÜñ¾ÜÜÌßÌÝèªcÁÄ¢éÂ\«ª èÜ·ÌÅAêUA³øɵÄAíµÄº³¢B êxíµ½ãÍAKvɶÄLøɵĺ³¢B ܽAECXì\tgð±üµÄ¢éêuuu.exev©A»êÉÞ·é¼OÌECXt@Cªì³ê éêª èÜ·ªA±êÍPÌÅì³êét@CÈÌÅA ÜèCɵÈÄà\¢Ü¹ñB GNXv[Ìvr [@\ÉæÁÄAC^[lbgGNXv[ÌêtH_©ço³êéêà èÜ·ªA±êàì³êé¶ÝÈÌÅAC ɵÂÂàA»¤¢¤m¾ÆvÁľ³¢B ªÁĵܦÎAìû@ÍPìÆÅ·ªAí©éÜŪ\åÏÈECXÆ̬¢B ܽAìàA¿åÁƵ½sÓÅÄÑ´õ³¹ÄµÜ¤àµÎµÎÅAá¦éÈçÎAÃdC¾ç¯Ì¼èðgÁÄAzṞð·éæ¤ÈìÆ ÉĢܷBPÉCCµÜ·B ÐÆܸAƯ¶VXeÇÒÌFlÉÆÁÄA±ÌèªQlÉÈêÎK¢Å·B 2009.03.16 @ÇL ±êçÌECXAàµÍíÈǪf«o·t@CÉÍAȺÌæ¤ÈàÌà éæ¤Å·B eipctcc.bat
fudtnmje.bat ±êçÌt@CàattribR}hÅA®«ððµÄí·éAÆ¢¤î{IÈèÅí·éªoÜ·B |