积极答复者
重新安装的XP系统为什么会经常蓝屏?

问题
答案
-
如上所说很有可能是木马或间谍软件。
这个木马生成如下文件(如果有这个文件就删除了)
C:\Documents and Settings\All Users\Application Data\spysure\servircess.exe
- C:\Documents and Settings\All Users\Application Data\spysure\servirsess.exe
- C:\Documents and Settings\All Users\Application Data\spysure\setup.dat
- C:\Documents and Settings\All Users\Application Data\spysure\spysure.zip
- C:\Documents and Settings\All Users\Application Data\spysure\spysureinstallzip.exe
- C:\Documents and Settings\All Users\Application Data\spysure\syservice.exe
- C:\Documents and Settings\All Users\Application Data\spysure\test.bmp
- C:\Documents and Settings\All Users\Application Data\spysure\testlog.txt
- C:\Documents and Settings\All Users\Application Data\spysure\testlog2.txt
- C:\Documents and Settings\All Users\Application Data\spysure\updater.exe
- C:\Documents and Settings\All Users\Application Data\spysure\ashcd.dat
- C:\Documents and Settings\All Users\Application Data\spysure\ashprot.sys
- C:\Documents and Settings\All Users\Application Data\spysure\ashsetup.dat
- C:\Documents and Settings\All Users\Application Data\spysure\DrvFltIp.sys
- C:\Documents and Settings\All Users\Application Data\spysure\gmon.out
- C:\Documents and Settings\All Users\Application Data\spysure\help.html
- C:\Documents and Settings\All Users\Application Data\spysure\logo.gif
- C:\Documents and Settings\All Users\Application Data\spysure\Project2.dll
- C:\Documents and Settings\All Users\Application Data\spysure\readme.txt
- %System%\ashprot.sys
- %System%\DrvFltIp.sys
Next, it creates the following folder:创建的文件夹
C:\Documents and Settings\All Users\Application Data\spysure\tempdir
The program then adds zipped screenshots to the following folder:
C:\Documents and Settings\All Users\Application Data\spysure\screenzip
注册表HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DrvFltIp
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpFilterDriver\Enum
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ashprot
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\spyservice
全部回复
-
如上所说很有可能是木马或间谍软件。
这个木马生成如下文件(如果有这个文件就删除了)
C:\Documents and Settings\All Users\Application Data\spysure\servircess.exe
- C:\Documents and Settings\All Users\Application Data\spysure\servirsess.exe
- C:\Documents and Settings\All Users\Application Data\spysure\setup.dat
- C:\Documents and Settings\All Users\Application Data\spysure\spysure.zip
- C:\Documents and Settings\All Users\Application Data\spysure\spysureinstallzip.exe
- C:\Documents and Settings\All Users\Application Data\spysure\syservice.exe
- C:\Documents and Settings\All Users\Application Data\spysure\test.bmp
- C:\Documents and Settings\All Users\Application Data\spysure\testlog.txt
- C:\Documents and Settings\All Users\Application Data\spysure\testlog2.txt
- C:\Documents and Settings\All Users\Application Data\spysure\updater.exe
- C:\Documents and Settings\All Users\Application Data\spysure\ashcd.dat
- C:\Documents and Settings\All Users\Application Data\spysure\ashprot.sys
- C:\Documents and Settings\All Users\Application Data\spysure\ashsetup.dat
- C:\Documents and Settings\All Users\Application Data\spysure\DrvFltIp.sys
- C:\Documents and Settings\All Users\Application Data\spysure\gmon.out
- C:\Documents and Settings\All Users\Application Data\spysure\help.html
- C:\Documents and Settings\All Users\Application Data\spysure\logo.gif
- C:\Documents and Settings\All Users\Application Data\spysure\Project2.dll
- C:\Documents and Settings\All Users\Application Data\spysure\readme.txt
- %System%\ashprot.sys
- %System%\DrvFltIp.sys
Next, it creates the following folder:创建的文件夹
C:\Documents and Settings\All Users\Application Data\spysure\tempdir
The program then adds zipped screenshots to the following folder:
C:\Documents and Settings\All Users\Application Data\spysure\screenzip
注册表HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DrvFltIp
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IpFilterDriver\Enum
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ashprot
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\spyservice