ǰÑÔ
½ñÌìÊÕµ½ÍøÓÑÓʼþ£¬Ç¿ÁÒÍÆ¼öÎÒÒ»¿î×îеÄQQÃÜÂëµÁȡľÂíÉú³ÉÆ÷¡ª¡ªÈ«ÄÜQQ´óµÁ¡£ ÎÒ¾ÍÄÉÃÆÄØ£¬ÕâÄêÍ·ÔõôÓÐÕâô¶àÈ˶ÔÕâÍæÒâÕâô¸ÐÐËÈ¤ÄØ¡¡²»¹ÜÔõô˵£¬Ê¢ÇéÄÑÈ´£¬¾ÍÊÕÏÂÕâ¿î±¦±´£¬ÒÔºóÓÃÀ´ÕûÕûÈËÒ²ºÃ¡£
ÏÈÈÃÎÒÃÇÀ´¿´¿´Õâ¿îľÂíµÄ½éÉÜ¡£
ĿǰΪֹ£¬×îÅ£XµÄQQľÂí¡£¿ÉÒÔ»ñÈ¡Óû§Q±ÒÊýÁ¿¡¢ÓÎÏ·±ÒÊýÁ¿¡¢QQ»ý·Ö¡¢QQÓÎÏ·µãµÈÐÅÏ¢¡£ÍêÃÀÆÆ½âQQ2006¼üÅ̱£»¤£¬ÃÜÂë¿ò²»»á³öÏÖºì²æ²æ£¬ ËùÓа汾QQͨɱ£¬°üÀ¨×îеÄQQ2006 Beta2¡£²ÉÓÃÌØÊâµÄÏ̲߳åÈë¼¼Êõ£¬ÎÞÆô¶¯ÏÎÞ½ø³Ì£¬ Í»ÆÆ¸÷Àà·À»ðǽ£¨È磺ÌìÍø¡¢¿¨°Í¡¢ÈðÐÇ¡¢½ðÉ½ÍøïÚ¡¢½Ãñ¡¡£©¡£²ÉÓÃͬÀàQQľÂíµ±ÖУ¬¾ø¶ÔÁìÏȵļ¼Êõ£¬×¼È·»ñÈ¡QQÃÜÂ룬¾øÎÞÆ«²î¡£Óû§µÇ½³É¹¦ºóÔÙ·¢ÐÅ£¬´Ó¶ø¶Å¾øÖظ´·¢ÐÅ¡¢ÃÜÂë´íÎó·¢ÐÅÇé¿ö£¬²»ÔÚÊÕÈ¡ÖØ¸´Ðżþ£¬Ìá¸ßÈí¼þ¹¤×÷ЧÂÊÁ¢¼´É¾³ý×ÔÉí£¬ÈÃľÂí²»ÁôºÛ¼£¡£¾ßÓж¨Ê±¹Ø±ÕQQºÍ·ÀÖØ¸´ÔËÐеŦÄÜ£¡ÏÂÃæÊǽØÍ¼£º

¿´µÄ³öÀ´£¬Õâ¿îÃÜÂëµÁÈ¡Èí¼þÕë¶ÔĿǰ¹úÄÚÍâµÄÖ÷Á÷×ÀÃæ·À»ðǽÈí¼þ×÷³öÁËÕë¶ÔÐԵĸĽø£¬ÇÒ¾ßÓкܸߵÄÒþ±ÎÐÔ£¬Ò»µ©ÔËÐÐÁËľÂíµÄEXE£¬Ëü¾Í¼¸ºõ³¹µ×Òþ²ØÁË×Ô¼º£¬¾ÍÏó¹ã¸æÖÐ˵µÄÒ»Ñù£¬ÎÞÆô¶¯ÏÎÞ½ø³Ì¡£³£¹æµÄ¼ì²â¹¤¾ßÒª¼ì²âËü¾ßÓÐÒ»¶¨µÄÄѶȣ¬ËùÒÔÕâ¿îľÂíÉú³ÉÆ÷Éú³ÉµÄľÂí¶ÔÓÚÆÕͨÓû§À´Ëµ¾ßÓÐÏ൱´óµÄɱÉËÁ¦¡£
ľÂí·ÖÎö
½ÓÏÂÀ´ÎÒÃÇÀ´¿´¿´¸ÃľÂíµÄ¹¤×÷Á÷³Ì£º
ľÂíÔÚ»ñµÃÆô¶¯ÔËÐк󣬾ͻὫ¸´ÖÆÒ»¸ö±¸·Ýµ½C:\Program Files\Internet Explorer\PLUGINS£¬²¢ÖØÃüÃûΪqn911.dll(ÆäʵÕ⻹ÊÇÒ»¸öEXEÎļþ)²¢½«ÆäÎļþÊôÐÔÉèΪÒþ²ØºÍϵͳȻºóÔÚC:\Program Files\Internet Explorer\PLUGINSÊͷųöqn911.sys(ÆäʵÕâÊÇÒ»¸öDLLÎļþ)¡£
ÕâʱºòľÂí»áÔÚϵͳע²á±íÄÚ×¢²áÒ»¸öCLASSID
HKCR\CLSID\{F3D0D422-CE6D-47B3-9CE6-C54DD63F1ADB}
²¢½«¸ÃCLSIDºÍC:\Program Files\Internet Explorer\PLUGINS\qn911.sysÁªÏµÔÚÒ»Æð¡£È»ºó½«¸ÃCLSIDÌí¼ÓÌí¼Óµ½×¢²á±íµÄShellExecuteHooksÏÂ
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
{F3D0D422-CE6D-47B3-9CE6-C54DD63F1ADB}=""
(ÀÏÄñÕâʱºò¾Í»á˵ÁË£¬ÔÀ´ËüµÄÎÞÆô¶¯ÏîºÍÌØÊâµÄÏ̲߳åÈë¼¼Êõ¾ÍÊÇÕâôʵÏֵİ¡¡)
Qn911.sysÄÚº¬Óй³×ÓWH_GETMESSAGE¡£
ÔÚľÂíÏÂÍê¹³×Óºó£¬Íê³ÉµÁÈ¡QQÃÜÂëµÄ×¼±¸¹¤×÷ºó¾Í´´½¨Ò»¸öÃûΪMicroSoft.batµÄÅú´¦ÀíÎļþ£¬ÓÃÓÚɾ³ýľÂíµÄEXEÎļþºÍÅú´¦Àí×ÔÉí.ÕâÑùËüÔÚϵͳÖоÍÊÇ¡±ÎÞ½ø³Ì¡±ÁË¡£
ÕâÀïÓиö²åÇú£¬Ä¾ÂíµÄ×÷Õß»á¸ø·ÖÎöÈËԱһЩÁôÑÔ£¬ÄÚÈÝÈçÏÂ:
wodexiaoshihouchaonaorenxingdeshihou
waiozongshichanggehongwonahsougehaoxiangzheyangchangdewodeguxiangzaiyuanfang
tianheiheitiootiantiandouyaoniaiwodexinsiyounicaibuyaowenwocongnalilai
ÓÉÓÚÎÒµÄСѧƴÒôʵÔÚ²»ÔõôÑù£¬¶øÇÒÓÉÓÚʱ¼ä¹ØÏµ£¬ËùÒÔÕâ¸öÄÚÈÝÁô¸ø¸ÐÐËȤµÄÈËÀ´½â¶Á°É¡£(ûÓбêµã·ûºÅµÄÎÄÕÂʵÔÚºÜÄѶÁ°¡)¡£
ÕâʱÈç¹ûÆô¶¯QQ£¬Í¨¹ýShellExecuteHooks£¬qn911.sys¾Í»á²åÈëµ½QQµÄ½ø³Ì¿Õ¼äÖÐÈ¥ÁË¡£

µÈÄãÊäÈëÃÜÂëºó£¬qn911.sys¾Í»á½«ÃÜÂë·¢Ë͵½ÄãÖ¸¶¨µÄÓÊÏäÖÐÈ¥¡£

ÓʼþÄÚÈÝÈçÏ£º

¶Ô¾ö
Ãæ¶ÔÈç´ËÒ»¸öÐÂÓ±£¬Ç¿º·£¬Òþ±ÎµÄ¶ÔÊÖ£¬ÖÕ½ØÕßÄÜ·ÀÓùÂð£¿Ã«Ö÷ϯ˵¹ý£ºÊµ¼ùÊǼìÑéÕæÀíµÄΨһ±ê×¼£¬ÄÇÎÒÃǾÍÓÃÊÂʵÀ´Ëµ»°°É¡£ÏȽ«QQ¼ÓÈëÖÕ½ØÕßµÄÃÜÂëËø±£»¤ÁбíÄÚ£º

Æô¶¯Ä¾Âí½ø³Ì£¬ÖÕ½ØÕß¶Ô½ø³ÌΣÏÕ³ÌÐòµÄÅжϻ¹ÊǺܾ«×¼µÄ¡£
¸ù¾ÝÎÒµÄʹÓþÑ飬ÄÜÈýø³Ì·À»¤Î£Ïյȼ¶¿òÀµ½µ×µÄ¾ø´ó¶àÊý¶¼ÊÇľÂí²¡¶¾µÈ·ÇÕý³£³ÌÐòÁË¡£

ʵÑéÐèÒª£¬ÎÒÃǷŹý¸ÃľÂí£¬ÔÊÐíËüÔËÐС£
Æô¶¯QQÔËÐУ¬²¢²é¿´Æä½ø³ÌÄ£¿é£¬¿ÉÒÔ¿´µ½£¬½ø³Ì¿Õ¼äÄÚqn911.sysÒѾÎÞ·¨×¢Èëµ½QQµÄ½ø³ÌÖÐÈ¥¡£¿´À´£¬ÖÕ½ØÕß¶ÔShellExecuteHook·½Ê½µÄÏß³Ì×¢È뻹ÊÇÓзÀÓùÊÖ¶ÎÊǷdz£³É¹¦ÓÐЧµÄ¡£¼ÈÈ»qn911.sys²»ÄÜ×¢Èëµ½QQ½ø³Ì¿Õ¼äÖУ¬ÄÇô½ØÈ¡ÃÜÂ뵱ȻҲ¾ÍÎÞ´Ó̸ÆðÁË¡£ÎÒÃÇÔڲ鿴ָ¶¨½ÓÊÕÃÜÂëµÄÓÊÏ䣬ÀïÃæ×ÔȻһÎÞËù»ñ¡£

¾ÍÕâÑùÒ»³¡QQÃÜÂëµÄ¹¥·ÀÕ½¾ÍÔÚÓû§ºÁ²»ÖªÇéµÄ×´¿öÖз¢ÉúºÍ½áÊøÁË¡£
Óû§Î¨Ò»µÄÏßË÷´ó¸Å¾ÍÒªµ½¹Ø±ÕQQʱ£¬²é¿´ÏêϸÐÅϢʱ²ÅÄÜ´ÓÄ£¿éÐÅÏ¢ÁбíÖп´µ½Ä¾ÂíÔø¾À´¹ýµÄÖëË¿Âí¼£¡£

³Ëʤ׷»÷
¸÷λ¿´¹Ù¿´µ½Õ⣬Ïà±È½á¹ûÒѾÃ÷ÁËÁË£¬½ÓÏÂÀ´¾ÍÊÇ´òɨս³¡µÄ¹¤×÷ÁË¡£´ÓÇ°ÃæµÄľÂí·ÖÎöÖпÉÒÔ¿´µ½£¬Ä¾Âí²ÐÁôÔÚϵͳÖÐÓÐÁ½¸öÎļþ
C:\Program Files\Internet Explorer\PLUGINS\qn911.sys
C:\Program Files\Internet Explorer\PLUGINS\qn911.dll
ËùÒÔÓû§Òª×öµÄÊÂÇé¾ÍÊÇɾ³ýÕâÁ½¸öÎļþ¡£µ«qn911.sys»¹ÔÚÆäËû½ø³ÌÖÐÔËÐУ¬´ËʱÊDz»ÄÜɾ³ýµÄ¡£

Õâʱºò£¬ÖÕ½ØÕßµÄÁíÒ»´óÌØÉ«¹¦ÄܾÍÄÜÅÉÉÏÓô¦ÁË¡£

µã»÷ºóÖØÆô£¬¾ÍÔËÐе½Ò»¸ö¾ø¶Ô´¿¾»µÄ»·¾³ÖÐ(²»Òª½«ÆäµÈͬÓÚϵͳµÄ°²È«Ä£Ê½)ÔÚÕâÀïÄã¾ÍÄܺÜÇáÒ×µØÉ¾³ýÉÏÊöÁ½¸öľÂíÎļþÁË¡£ÖÁ´Ë£¬Ä¾ÂíÇåÀíÍê±Ï¡£
½áÊøÓï
Õâ´ÎÖÕ½ØÕßÔâÓöµÄ¶ÔÊÖÊÇÀûÓÃShellExecuteHook¼¼Êõ½øÐÐÃÜÂëµÁÈ¡µÄľÂí¡£¿´µÄ³öÀ´£¬ÖÕ½ØÕßµÄÑз¢ÈËÔ±Õë¶ÔÕâÖÖ¼¼ÊõÌṩÁËÓÐЧµÄ·ÀÓù·½°¸£¬ËùÒÔ²ÅÄÜÇáËÉ»ñʤ¡£¾ÝÎÒËùÖª£¬ÕâÔÚͬÀàÈí¼þÖÐÄÜ×öµ½µÄ²¢²»¶à£¬¿ÉÒÔ˵ÊÇÁÈÁÈÎÞ¼º¡£¶øÇÒÖÕ½ØÕßµÄÄÜÁ¦Ô¶²»Ö¹ÓÚ´Ë£¬ÄÇôÖÕ½ØÕßµÄÏÂÒ»¸ö¶ÔÊÖ»áÊÇËÄØ?
| ×ÔÓÉ¹ã¸æÇø |
| ¡¡ |