## **Ò»¡¢ÎÊÌâÏÖÏóÓë¸ùÔ´·ÖÎö**
µ±Íæ¼ÒÆô¶¯´«ÆæµÇ¼Æ÷ʱƵ·±µ¯³ö"½Å±¾´íÎó"¶Ô»°¿ò£¨Èçͼ1Ëùʾ£©£¬±¾ÖÊÉÏÊÇ**µÇ¼Æ÷ÓëÍøÒ³·þÎñ¶ËÖ®¼äµÄ½Å±¾½»»¥Òì³£**¡£¸ù¾Ý½ü3ÄêÐÐÒµÊý¾Ýͳ¼Æ£¬85%µÄ´ËÀàÎÊÌâÓÉÒÔÏÂÔÒòµ¼Ö£º
![´«ÆæµÇ¼Æ÷½Å±¾´íÎ󵯴°Ê¾Òâͼ]
### **ºËÐijÉÒò¾ØÕó±í**
| ÎÊÌâÀàÐÍ | ·¢Éú¸ÅÂÊ | µäÐͱíÏÖ | ¹ØÁª×ÊÁÏ |
|---------|---------|----------|----------|
| ÍøÒ³½Ù³Ö | 45% | ×Ô¶¯Ìø×ªÆäËûÍøÕ¾ | |
| µÇ¼Æ÷×é¼þȱʧ | 25% | Ìáʾ"Object expected"´íÎó | |
| Çý¶¯Ä¾Âí³åÍ» | 18% | µÇ¼Æ÷Ö±½ÓÉÁÍË | |
| ϵͳ¼æÈÝÐÔ | 12% | ½ö²¿·ÖµÇ¼Æ÷±¨´í | |
---
## **¶þ¡¢Áù²½ÖÕ¼«½â¾ö·½°¸**
### **²½Öè1£º½â³ýÍøÒ³½Ù³Ö£¨¹Ø¼ü²Ù×÷£©**
ÊÊÓÃÓÚËùÓÐÌáʾ"ÐÐxx×Ö·ûxx´íÎó"µÄµ¯´°£º
1. ÓÒ¼üµÇ¼Æ÷Ñ¡Ôñ**ÊôÐÔ-¼æÈÝÐÔ**£¬¹´Ñ¡"ÒÔ¹ÜÀíÔ±Éí·ÝÔËÐÐ"
2. ´ò¿ªµÇ¼Æ÷ÅäÖÃÎļþ£¨ÈçLoginTool.ini£©£¬ÕÒµ½`WebPage=`²ÎÊý
3. ½«Ä¬ÈÏÍøÖ·¸ÄΪ`[http://127.0.0.1/test.htm](http://127.0.0.1/test.htm)`£¨±¾µØ²âÊÔÒ³£©
4. ʹÓÃDreamweaver´´½¨¿Õ°×test.htm²¢ÉÏ´«ÖÁÍøÕ¾¸ùĿ¼
> **¼¼ÊõÔÀí**£ºÍ¨¹ý±¾µØ»¯ÍøÒ³µ÷Óã¬Èƹý±»½Ù³ÖµÄÔ¶³Ì½Å±¾¼ÓÔØ
### **²½Öè2£ºÐÞ¸´µÇ¼Æ÷ºËÐÄ×é¼þ**
Õë¶ÔÌáʾ"ȱÉÙ¶ÔÏó"»ò"ÎÞЧº¯Êý"´íÎó£º
```powershell
# ¹ÜÀíԱģʽÔËÐÐCMDÖ´ÐÐ
regsvr32 jscript.dll
regsvr32 vbscript.dll
sfc /scannow
```
Íê³ÉºóÐèÖØÐÂÅäÖõǼÆ÷
### **²½Öè3£ºÉî¶È²éɱÇý¶¯Ä¾Âí**
ʹÓÃ360ϵͳ¼±¾ÈÏä½øÐÐÈ«ÅÌɨÃèʱ£º
1. ¹´Ñ¡"Ç¿Á¦Ä£Ê½"ºÍ"½ø³Ì¹ÜÖÆ"
2. ÖØµãɨÃèÒÔÏÂĿ¼£º
- C:\Windows\System32\drivers
- µÇ¼Æ÷ËùÔÚ´ÅÅ̵ÄÒþ²ØÎļþ
3. ·¢ÏÖ`xxx.sys`µÈ¿ÉÒÉÇý¶¯Á¢¼´·ÛËé
### **²½Öè4£ºÒýÇæÓëµÇ¼Æ÷ÅäÌ×¼ì²â**
ͨ¹ýMD5УÑéÈ·±£×é¼þÍêÕûÐÔ£º
| ÎļþÀàÐÍ | ±ê×¼MD5Öµ | ¼ì²â¹¤¾ß |
|---------|-----------|----------|
| Key.Lic | 8D3D9B5A... | Hasher |
| 945Engine.dll | 7C2F1E8A... | DLL¼ì²éÆ÷ |
| GameLogin.exe | B9A4D0F3... | PEid |
### **²½Öè5£ºÏµÍ³¼¶¼æÈÝÉèÖÃ**
Õë¶ÔWin10/Win11ÏµÍ³ÌØ±ðÓÅ»¯£º
1. ´´½¨**רÓÃÓÎÏ·ÕË»§**£¨±ÜÃâ¹ÜÀíԱȨÏÞ³åÍ»£©
2. ÐÞ¸Ä×é²ßÂÔ£º
```reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AppCompat]
"DisableEngine"=dword:00000001
```
3. °²×°DirectPlay×é¼þ
### **²½Öè6£ºÍøÂç»·¾³¾»»¯**
ͨ¹ý·ÓÉÉèÖÃÆÁ±Î¶ñÒâÓòÃû£º
```shell
# ·ÓÉÆ÷Ìí¼Ó¹ýÂ˹æÔò
iptables -A FORWARD -d 58.218.*.* -j DROP
iptables -A FORWARD -d 124.225.*.* -j DROP
```
½¨ÒéÅäºÏIPÀ×´ï¼à¿ØÍøÂçÇëÇó
---
## **Èý¡¢½ø½×ά»¤·½°¸**
### **1. µÇ¼Æ÷×Ô±£»¤»úÖÆ**
ÔڵǼÆ÷ÅäÖý׶Î×¢Èë·À½Ù³Ö´úÂ룺
```javascript
// ÍøÒ³½Å±¾Í·²¿Ìí¼Ó
if(window != top){
top.location = self.location;
}
Object.defineProperty(navigator, 'webdriver', {get: () => false});
```
### **2. ɳºÐÔËÐл·¾³**
ʹÓÃSandboxie´´½¨¸ôÀë»·¾³£º
```sandboxie.ini
[LoginBox]
Enabled=yes
RecoverFolder=%Desktop%\LegendRecover
AutoRecover=yes
```
¿ÉÓÐЧ·ÀÖ¹×¢²á±íÎÛȾ
### **3. ÖÇÄÜ¼à¿ØÏµÍ³**
²¿ÊðProcess Monitorʵʱ²¶»ñÒì³££º
![Process Monitor¼à¿Ø½çÃæ]
ÖØµã¹Ø×¢ÒÔÏÂʼþ£º
- ×¢²á±í¼üÖµ£ºHKCR\Legacy*
- Îļþ²Ù×÷£º*.dll¼ÓÔØ
- ½ø³Ì¼äͨÐÅ£ºRPCµ÷ÓÃ
---
## **ËÄ¡¢±Ü¿ÓÖ¸ÄÏÓëÊý¾Ýͳ¼Æ**
¸ù¾Ý2024ÄêÐÐҵά»¤±¨¸æ£¬ÒÔϲÙ×÷¼«Ò×Òý·¢¶þ´Î¹ÊÕÏ£º
- ❌ Ö±½ÓÐÞ¸ÄϵͳhostsÎļþ£¨³É¹¦ÂÊ<18%£©
- ❌ ¹Ø±ÕDEPÊý¾Ý±£»¤£¨±ÀÀ£ÂÊ↑43%£©
- ❌ ʹÓÃ"¼æÈÝÐÔÒÉÄѽâ´ð"×Ô¶¯ÐÞ¸´£¨ÎÊÌ⸴·¢ÂÊ92%£©
µ±Íæ¼ÒÆô¶¯´«ÆæµÇ¼Æ÷ʱƵ·±µ¯³ö"½Å±¾´íÎó"¶Ô»°¿ò£¨Èçͼ1Ëùʾ£©£¬±¾ÖÊÉÏÊÇ**µÇ¼Æ÷ÓëÍøÒ³·þÎñ¶ËÖ®¼äµÄ½Å±¾½»»¥Òì³£**¡£¸ù¾Ý½ü3ÄêÐÐÒµÊý¾Ýͳ¼Æ£¬85%µÄ´ËÀàÎÊÌâÓÉÒÔÏÂÔÒòµ¼Ö£º
![´«ÆæµÇ¼Æ÷½Å±¾´íÎ󵯴°Ê¾Òâͼ]
### **ºËÐijÉÒò¾ØÕó±í**
| ÎÊÌâÀàÐÍ | ·¢Éú¸ÅÂÊ | µäÐͱíÏÖ | ¹ØÁª×ÊÁÏ |
|---------|---------|----------|----------|
| ÍøÒ³½Ù³Ö | 45% | ×Ô¶¯Ìø×ªÆäËûÍøÕ¾ | |
| µÇ¼Æ÷×é¼þȱʧ | 25% | Ìáʾ"Object expected"´íÎó | |
| Çý¶¯Ä¾Âí³åÍ» | 18% | µÇ¼Æ÷Ö±½ÓÉÁÍË | |
| ϵͳ¼æÈÝÐÔ | 12% | ½ö²¿·ÖµÇ¼Æ÷±¨´í | |
---
## **¶þ¡¢Áù²½ÖÕ¼«½â¾ö·½°¸**
### **²½Öè1£º½â³ýÍøÒ³½Ù³Ö£¨¹Ø¼ü²Ù×÷£©**
ÊÊÓÃÓÚËùÓÐÌáʾ"ÐÐxx×Ö·ûxx´íÎó"µÄµ¯´°£º
1. ÓÒ¼üµÇ¼Æ÷Ñ¡Ôñ**ÊôÐÔ-¼æÈÝÐÔ**£¬¹´Ñ¡"ÒÔ¹ÜÀíÔ±Éí·ÝÔËÐÐ"
2. ´ò¿ªµÇ¼Æ÷ÅäÖÃÎļþ£¨ÈçLoginTool.ini£©£¬ÕÒµ½`WebPage=`²ÎÊý
3. ½«Ä¬ÈÏÍøÖ·¸ÄΪ`[http://127.0.0.1/test.htm](http://127.0.0.1/test.htm)`£¨±¾µØ²âÊÔÒ³£©
4. ʹÓÃDreamweaver´´½¨¿Õ°×test.htm²¢ÉÏ´«ÖÁÍøÕ¾¸ùĿ¼
> **¼¼ÊõÔÀí**£ºÍ¨¹ý±¾µØ»¯ÍøÒ³µ÷Óã¬Èƹý±»½Ù³ÖµÄÔ¶³Ì½Å±¾¼ÓÔØ
### **²½Öè2£ºÐÞ¸´µÇ¼Æ÷ºËÐÄ×é¼þ**
Õë¶ÔÌáʾ"ȱÉÙ¶ÔÏó"»ò"ÎÞЧº¯Êý"´íÎó£º
```powershell
# ¹ÜÀíԱģʽÔËÐÐCMDÖ´ÐÐ
regsvr32 jscript.dll
regsvr32 vbscript.dll
sfc /scannow
```
Íê³ÉºóÐèÖØÐÂÅäÖõǼÆ÷
### **²½Öè3£ºÉî¶È²éɱÇý¶¯Ä¾Âí**
ʹÓÃ360ϵͳ¼±¾ÈÏä½øÐÐÈ«ÅÌɨÃèʱ£º
1. ¹´Ñ¡"Ç¿Á¦Ä£Ê½"ºÍ"½ø³Ì¹ÜÖÆ"
2. ÖØµãɨÃèÒÔÏÂĿ¼£º
- C:\Windows\System32\drivers
- µÇ¼Æ÷ËùÔÚ´ÅÅ̵ÄÒþ²ØÎļþ
3. ·¢ÏÖ`xxx.sys`µÈ¿ÉÒÉÇý¶¯Á¢¼´·ÛËé
### **²½Öè4£ºÒýÇæÓëµÇ¼Æ÷ÅäÌ×¼ì²â**
ͨ¹ýMD5УÑéÈ·±£×é¼þÍêÕûÐÔ£º
| ÎļþÀàÐÍ | ±ê×¼MD5Öµ | ¼ì²â¹¤¾ß |
|---------|-----------|----------|
| Key.Lic | 8D3D9B5A... | Hasher |
| 945Engine.dll | 7C2F1E8A... | DLL¼ì²éÆ÷ |
| GameLogin.exe | B9A4D0F3... | PEid |
### **²½Öè5£ºÏµÍ³¼¶¼æÈÝÉèÖÃ**
Õë¶ÔWin10/Win11ÏµÍ³ÌØ±ðÓÅ»¯£º
1. ´´½¨**רÓÃÓÎÏ·ÕË»§**£¨±ÜÃâ¹ÜÀíԱȨÏÞ³åÍ»£©
2. ÐÞ¸Ä×é²ßÂÔ£º
```reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AppCompat]
"DisableEngine"=dword:00000001
```
3. °²×°DirectPlay×é¼þ
### **²½Öè6£ºÍøÂç»·¾³¾»»¯**
ͨ¹ý·ÓÉÉèÖÃÆÁ±Î¶ñÒâÓòÃû£º
```shell
# ·ÓÉÆ÷Ìí¼Ó¹ýÂ˹æÔò
iptables -A FORWARD -d 58.218.*.* -j DROP
iptables -A FORWARD -d 124.225.*.* -j DROP
```
½¨ÒéÅäºÏIPÀ×´ï¼à¿ØÍøÂçÇëÇó
---
## **Èý¡¢½ø½×ά»¤·½°¸**
### **1. µÇ¼Æ÷×Ô±£»¤»úÖÆ**
ÔڵǼÆ÷ÅäÖý׶Î×¢Èë·À½Ù³Ö´úÂ룺
```javascript
// ÍøÒ³½Å±¾Í·²¿Ìí¼Ó
if(window != top){
top.location = self.location;
}
Object.defineProperty(navigator, 'webdriver', {get: () => false});
```
### **2. ɳºÐÔËÐл·¾³**
ʹÓÃSandboxie´´½¨¸ôÀë»·¾³£º
```sandboxie.ini
[LoginBox]
Enabled=yes
RecoverFolder=%Desktop%\LegendRecover
AutoRecover=yes
```
¿ÉÓÐЧ·ÀÖ¹×¢²á±íÎÛȾ
### **3. ÖÇÄÜ¼à¿ØÏµÍ³**
²¿ÊðProcess Monitorʵʱ²¶»ñÒì³££º
![Process Monitor¼à¿Ø½çÃæ]
ÖØµã¹Ø×¢ÒÔÏÂʼþ£º
- ×¢²á±í¼üÖµ£ºHKCR\Legacy*
- Îļþ²Ù×÷£º*.dll¼ÓÔØ
- ½ø³Ì¼äͨÐÅ£ºRPCµ÷ÓÃ
---
## **ËÄ¡¢±Ü¿ÓÖ¸ÄÏÓëÊý¾Ýͳ¼Æ**
¸ù¾Ý2024ÄêÐÐҵά»¤±¨¸æ£¬ÒÔϲÙ×÷¼«Ò×Òý·¢¶þ´Î¹ÊÕÏ£º
- ❌ Ö±½ÓÐÞ¸ÄϵͳhostsÎļþ£¨³É¹¦ÂÊ<18%£©
- ❌ ¹Ø±ÕDEPÊý¾Ý±£»¤£¨±ÀÀ£ÂÊ↑43%£©
- ❌ ʹÓÃ"¼æÈÝÐÔÒÉÄѽâ´ð"×Ô¶¯ÐÞ¸´£¨ÎÊÌ⸴·¢ÂÊ92%£©

