3721±À¥X¤F§ó¬°´Ý¼Éªºªk¦è´µ¤â¬q¡A±j­¢¦w¸Ëºô¸ô¹ê¦W 


3721±À¥X¤F§ó¬°´Ý¼Éªºªk¦è´µ¤â¬q¡A±j­¢¦w¸Ëºô¸ô¹ê¦W

³Ìªñ¡A3721 ¨t²Î­è­èª@¯Å¡A¤â¬q§ó¬°¨õ¦H¤ÎÅQ¹D¡C

1 ¦b³]³ÆÅX°Ê¼h¥[¤F«OÅ@¡A¦Ó¥B¬Oboot®É¥ß§Y±Ò°Ê¡A§Y¨Ï¦b¦w¥þ¼Ò¦¡®É¤]·|±Ò°Ê¡C³o­Ó³]³Æªº¦W¦r¥s°µ cnsminkp,ÅX°Êµ{¦¡¦ì©ówindows\system32\drivers\cnsminkp.sys
2 cnsminkp.sys ¤@¥¹¸ü¤J¡AµLªk¥Î«ü¥O¤è¦¡¨ø¸ü³o­ÓÅX°Êµ{¦¡¡A§Y net stop cnsminkp ¬OµLªk°±¤î³o­ÓÅX°Êªº¡C cnsminkp.sys ªº¤å¥ó¤é´Á¬O2004-02-15, ¬O«e´X¤Ñ¤~release¥X¨Óªº¡C
3 ³o­ÓÅX°Ê¤£°±¦aÀË´úcnsminkp.sys ¬O§_¦s¦b¡Acnsmin.dll¬O§_¦s¦b¡A¦pªG¤£¦s¦b¡A¥ß§Y·|­««Ø³o¨â­Ó¤å¥ó¡A¨Ã¥B¤£°±ÀË´úservice ©Msoftware ¤U­±ªºµù¥Uªí¡A½T«Ocnsminkp³o­ÓªA°Èªº°Ñ¼Æ«O«ù©M¥¦³]©wªº¤@­P¡A¦pªG³Q§ï°Ê¡A¥ß§Y·|«ì´_¦¨­ì¨Óªº¼Ë¤l¡C¥t¥~¡AÁÙ½T«O run ¸Ì¦³cnsmin.dll
4 ³oºØ¦º¥Ö¿àÁyªº¤è¦¡¡A¬O¨M¤ß­n¦b°O¾ÐÅé©MµwºÐ¤W¾n¯dcnsminkp.sys ©Mcnsmin.dll,¨Ï¨t²Î®Ä¯à¨³³t¤U­°¡C
§ï¤Fµù¥Uªí¡A¨S¦³¥Î¡A§A¤@­«·s¾ã²z¡A°¨¤WÁÙ­ì¤F¡C
¤@§R¤å¥ó¡A¦Adir ¤@¬Ý¡A¤S¦^¨Ó¤F¡C
¦]¬°cnsminkp.sys ªºµ{¦¡½X¦³¦Û§ÚÁÙ­ì¥\¯à¡C¤@¥¹±Ò°Ê«á¡A´N¶}©l¤£°±¦a±½ºË¡A¦³²§±`«K¥ß§YÁÙ­ì¡C³o¬qµ{¦¡½X±N¤j¤j­°§C¾÷¾¹ªº®Ä¯à

¸Ñ¨M¤èªk¡C
1 ¦w¸Ë¥t¥~¤@­Ó°®²bªºwindows ¨t²Î
2 ±q³o­Ó°®²bªº¨t²Î±Ò°Ê¡A§R°£©Ò¦³ªºcnsminpk.sys cnsmin.dll¤å¥ó
3 ±q­ì¨Óªºwindows¨t²Î±Ò°Ê
4 °õ¦æspybot³nÅé¡A²M°£3721,¨Ã¥B¥[¤W§K¬Ì«OÅ@

cnsminkp.sys ¬O§_ªí¥Ü cnsmin keep ÁÙ¬Ocnsmin kill protect ? ¥u­n§Aªºwindows\system32\drivers¤U¦³cnsminkp.sys ,ªÖ©w¤¤©Û¤F¡C

¤µ¤Ñ¤£¤Öºô¤Íµo²{3721³o­Ó¦Ñ±D¤l¤S´«¤F·sªá¼Ë¡A¥Ñ©ó¥L­Ìªº±±¥ó¨S¦³§@¼Æ¦rñ¦W¡A©Ò¥H´N¤£·|¥X²{±±¥ó¦w¸Ë®É­Ôªº¼t°Ó«H®§¡A¦ô­p¥L­Ì¬O¥æ¤£°_¨º°ª©ùªº¼Æ¦rñ¦WÃҮѶO¡C

¦Ó¥B²{¦bªº3721¦w¸Ë¤§«á¡A§A·|µo²{¡AµL½×§A«ç»ò¼Ë·j´M¡A³£¤£·|¦bµwºÐ¤W§ä¨ì¥L­Ìªº¤å¥ó¡]¦pªG¬O­Ó§g¤l¡A·F¤°»òÁôÂäå¥ó¡H¡^¡C

¤£¹L¡A§Úµo²{¤@­Ó·N¥~ªº¦¬Ã¬¡A¦pªG§A´¿¸g¦w¸Ë¹L3721¡A¨Ã¥B¨ø¸ü¹L¥¦¡A¥L­Ì¥H«á´N¤£·|¦A¼u¥X±D¤lªº¦w¸Ë¹ï¸Üµøµ¡

¾Þ§@¤èªk¦p¤U¡G

¦b¤U­±ªºµù¥Uªí±M®×¤¤
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main

·s¼W¤@­Ó¦r¦ê¦êÁä­È
©R¦W¬°CNSUIN¡A­È¬°1¡C

¸ÓÁä­Èªí¥Ü¡A¥Î¤á´¿¸g¨ø¸ü¹L3721¡C

þWw i n d o w s R e g i s t r y E d i t o r V e r s i o n 5 . 0 0 



[ H K E Y _ C U R R E N T _ U S E R \ S o f t w a r e \ M i c r o s o f t \ I n t e r n e t E x p l o r e r \ M a i n ] 

" C N S U I N " = " 1 "


==================================
¯¸±±¥ó§K¬Ì­×¥¿ÀÉBanActiveX_V0.03
¼W¥[¹ï·sªº3721ª@¯Å¥]ªº¾B³¬
¤U­±¬O¶Â¦W³æ¡A¨Ï¥Î¤èªk¥u»Ý­n¿ï§Y¥i¡A¸Ñ°£¥u­n¤£¿ï
B83FC273-3522-4CC6-92EC-75CC86678DA4$3721ºô¸ô¹ê¦W
1B0E7716-898E-48CC-9690-4E338E8DE1D3$3721¤Wºô§U¤â
4EDBBAEA-F509-49F6-94D1-ECEC4BE5B686$3721¤¤¤å¶l
8D898B17-976D-44c1-84E6-AF38842AC9EC$3721ª@¯Å¥]
9BBC1154-218D-453C-97F6-A06582224D81$¦Ê«×·jÅQ
BC207F7D-3E63-4ACA-99B5-FB5F8428200C$¦Ê«×·j´M¦ñ«Q
9A578C98-3C2F-4630-890B-FC04196EF420$CNNIC³q¥Î°ì¦W
CF051549-EDE1-40F5-B440-BCD646CF2C25$ºô©öªwªw
15DDE989-CD45-4561-BF99-D22C0D5C2B74$·s®öÂIÂI³q
98FA5667-513F-4F15-8A15-C171477B8847$·s®öIE³q
2D0C7226-747E-11D6-83F0-00E04C4A2F90$·jª°µøÃx¼½©ñ¾¹
484FF54A-CC44-467E-9C31-5B89FC753007$·jª°¤u§@¦C
018B7EC3-EECA-11D3-8E71-0000E82C6C0D$XXXToolbar
E8EDB60C-951E-4130-93DC-FAF1AD25F8E7$Mtree Dialers 1
FC87A650-207D-4392-A6A1-82ADBC56FA64$Mtree Dialers 2


or:
°õ¦æBanActiveX.exe
¿ï»Ý­n¾B³¬ªºActiveX¡AÃö³¬µ{§Ç§Y¥i
¨ú®ø¾B³¬¥u»Ý­n¨ú®ø¿ï§Y¥i¡C

¼W¥[¦Û­q¸ê®Æ®w¡Aª½±µ½Ð½s¿èBanActiveX.ini¡A®æ¦¡¨£¤U­±ªº¡A´X¥G¤£»Ý­n»¡©ú

µ{§Ç¶}©ñ¨Ó·½½X

¸ê®Æ®w®æ¦¡¡G
B83FC273-3522-4CC6-92EC-75CC86678DA4$3721ºô¸ô¹ê¦W
ActiveX id $¤À¹j²Å ¦W¦r

­ì§@ªÌ¡G´_¥¹¤j¾ÇLucian

¡@