| ¹ØÓÚÁ½¸ö½ø³ÌÇó½Ì [message #210921] |
So, 04 Juni 2006 07:30 |
|
ÈÎÎñ¹ÜÀíÆ÷ÖÐÓÐÁ½¸ö½ø³Ì£ºLSASS.exeºÍSERVICES.exeÕâÁ½¸ö½ø³ÌºÃÏ ñºÜÖØÒª£¬¹Ø²»ÉÏ¡£ÕâÁ½¸ö½ø³Ìƽʱ²»Õ¼ÓÃỊ̈߳¬µ«×î½ü¿ª»úºóÒ»¶ÎÊ ±¼ä£¬ÓÐʱ¾Í¿ª¸öQQ,ÕâÁ½¸ö½ø³Ì¾ÍÕ¼¾ÝºÜ´óµÄCPUʹÓÃ,Ò»°ã¶¼ÊÇ90%Ò ÔÉÏ£¬Ê¹µÃ±ðµÄ³ÌÐòÎÞ·¨Õý³£ÔËÐУ¬ÕâÊÇÔõô»ØÊ£¬Ôõô½â¾ö£¬Çë¸÷Î »¸ßÊÖÖ¸½Ì
--
[1;32m¡ù À´Ô´:£®Ìì´óÇóʵBBS http://bbs.tju.edu.cn [FROM: 219.243.36.208][m
|
|
|
| Re: ¹ØÓÚÁ½¸ö½ø³ÌÇó½Ì [message #210938 ] |
So, 04 Juni 2006 15:35 |
|
ÕæÊÇ·þÁË
ÕâÑùµÄÎÊÌâ°Ù¶È»ò¹È¸èËæ±ãËÑËѾͿÉÒԵõ½ÁË
lsass-lsass.exe-½ø³ÌÐÅÏ¢
½ø³ÌÎļþ£ºlsass»òÕßlsass.exe
½ø³ÌÃû³Æ£ºLocalSecurityAuthorityService
½ø³ÌÃû³Æ£ºlsass.exeÊÇÒ»¸öϵͳ½ø³Ì£¬ÓÃÓÚ΢ÈíWindowsϵͳµÄ°²È« »úÖÆ¡£ËüÓÃÓÚ±¾µØ°²È«ºÍµÇ½²ßÂÔ¡£×¢Ò⣺lsass.exeÒ²ÓпÉÄÜÊÇWin dang.worm¡¢irc.ratsou.b¡¢Webus.B¡¢MyDoom.L¡¢Randex.AR¡¢Nimos .worm´´½¨µÄ£¬²¡¶¾Í¨¹ýÈíÅÌ¡¢Èº·¢ÓʼþºÍP2PÎļþ¹²Ïí½øÐд«²¥¡£
³öÆ·ÕߣºMicrosoftCorp.
ÊôÓÚ£ºMicrosoftWindowsOperatingSystem
ϵͳ½ø³Ì£ºÊÇ
ºǫ́³ÌÐò£ºÊÇ
ʹÓÃÍøÂ磺·ñ
Ó²¼þÏà¹Ø£º·ñ
³£¼û´íÎó£ºÎ´ÖªN/A
ÄÚ´æÊ¹ÓãºÎ´ÖªN/A
°²È«µÈ¼¶(0-5):0
¼äµýÈí¼þ£º·ñ
¹ã¸æÈí¼þ£º·ñ
Virus:·ñ
ľÂí:·ñ
services.exeÊÇ΢ÈíWindows²Ù×÷ϵͳµÄÒ»²¿·Ö¡£ÓÃÓÚ¹ÜÀíÆô¶¯ºÍÍ£Ö ¹·þÎñ¡£¸Ã½ø³ÌÒ²»á´¦ÀíÔÚ¼ÆËã»úÆô¶¯ºÍ¹Ø»úʱÔËÐеķþÎñ¡£Õâ¸ö³ÌÐ ò¶ÔÄãϵͳµÄÕý³£ÔËÐÐÊǷdz£ÖØÒªµÄ¡£×¢Ò⣺servicesÒ²¿ÉÄÜÊÇW32.R andex.R(´¢´æÔÚ%systemroot%\system32\Ŀ¼)ºÍSober.P (´¢´æÔÚ%systemroot%\Connection Wizard\Status\Ŀ¼)ľÂí¡£¸ÃľÂíÔÊÐí¹¥»÷Õß·ÃÎÊÄãµÄ¼ÆËã»ú£¬ÇÔÈ ¡ÃÜÂëºÍ¸öÈËÊý¾Ý¡£¸Ã½ø³ÌµÄ°²È«µÈ¼¶Êǽ¨ÒéÁ¢¼´É¾³ý¡£
³öÆ·ÕߣºMicrosoft Corp.
ÊôÓÚ£ºMicrosoft Windows Operating System
ϵͳ½ø³Ì£ºYes
ºǫ́³ÌÐò£ºYes
ÍøÂçÏà¹Ø£ºNo
³£¼û´íÎó£ºN/A
ÄÚ´æÊ¹ÓãºN/A
°²È«µÈ¼¶ (0-5): 0
¼äµýÈí¼þ£ºNo
¹ã¸æÈí¼þ£ºNo
²¡¶¾£ºNo
¡¾ ÔÚ mihoo µÄ´ó×÷ÖÐÌáµ½: ¡¿
:
: ÈÎÎñ¹ÜÀíÆ÷ÖÐÓÐÁ½¸ö½ø³Ì£ºLSASS.exeºÍSERVICES.exeÕâÁ½¸ö½ø³ÌºÃÏ ñºÜÖØÒª£¬¹Ø²»ÉÏ¡£ÕâÁ½¸ö½ø³Ìƽʱ²»Õ¼ÓÃỊ̈߳¬µ«×î½ü¿ª»úºóÒ»¶ÎÊ ±¼ä£¬ÓÐʱ¾Í¿ª¸öQQ,ÕâÁ½¸ö½ø³Ì¾ÍÕ¼¾ÝºÜ´óµÄCPUʹÓÃ,Ò»°ã¶¼ÊÇ90%Ò ÔÉÏ£¬Ê¹µÃ±ðµÄ³ÌÐòÎÞ·¨Õý³£ÔËÐУ¬ÕâÊÇÔõô»ØÊ£¬Ôõô½â¾ö£¬Çë¸÷Î »¸ßÊÖÖ¸½Ì
--
http://bbs.tju.edu.cn/TJUBBS/attach/bbscon/robot.jpg?B=QMD&a mp;F=M.1128955840.A&attachpos=185&attachname=/robot. jpg
[1;37m¡ù À´Ô´:£®Ìì´óÇóʵBBS http://bbs.tju.edu.cn [FROM: 202.113.13.188][m
|
|
|