<P>shu ri fa gua le,kan niao yu ba</P>
<P>task manager</P>
<P>kill the process:shohost.exe</P>
<P>run regedit</P>
<P>del</P>
<P>hkey_local_machine\system\controlset001\services\windows management server</P>
<P>//my winxp is eng edition,but the discription is chs in this key.</P>
<P>del </P>
<P>$system$\sytem32\shohost.exe</P>
<P>del every local disk </P>
<P>sxs.com/sxs.exe&autorun.inf by search</P>
<P>reboot</P>
<P>del $system$\winmt.ini</P>
<P>ps:this is trojan,destination is 59.34.37.112 (sansanbajiu.9966.org) , destination port is 8000</P>
<P>caution please~~!!!,a hide,autorun link in the home page.the domainame of the link is <a href="http://www.2683350.com/" target="_blank" ><FONT color=#ff0033>www.2683350.com</FONT></A> (caution trojan in,don't click it),ip is 61.188.38.51.</P>
<P>adminitrator,kill it quickly please~~~!!!</P>
<P>i'm not sure it now,internal pages is have hide,autorun links:wpa.qq.com&qpslogos.qq.com </P>
<P><br><br> </P>
[此贴子已经被作者于2006-8-11 0:29:47编辑过]
|