[mljl / mljlh][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\mljlh.sys><N/A>
[msqmx / msqmx][Running/Auto Start]
<\??\G:\WINDOWS\system32\drivers\msqmx.sys><N/A>
[ncio / ncio][Running/Auto Start]
<system32\DRIVERS\ncio.sys><N/A>
日志没有贴全。任务管理器中有病毒进程在运行,如rundll2000、.scvmost
exe等等
以上是病毒的驱动。
还有病毒的进程到处插入:
PID: 768][G:\WINDOWS\system32\Ati2evxx.exe] [, ]
[G:\PROGRA~1\mkbd\sxrt.dll] [, 1, 0, 0, 6]
[G:\PROGRA~1\mkbd\ecwv.dll] [ , 1, 0, 0, 6]
[PID: 1728][G:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[G:\WINDOWS\system32\gxqjb.dll] [N/A, ]
[G:\WINDOWS\system32\xxctrc82.dll] [Microsoft Corporation, 1, 1, 1, 1030]
[G:\PROGRA~1\mkbd\sxrt.dll] [, 1, 0, 0, 6]
[G:\PROGRA~1\mkbd\ecwv.dll] [ , 1, 0, 0, 6]
[G:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[G:\WINDOWS\system32\kybava05.dll] [, 1, 1, 1, 1002]
[G:\WINDOWS\system32\zcmcha48.dll] [, 1, 1, 1, 1002(第5行可能不是)
PID: 888][G:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[G:\program files\internet explorer\use18.dll] [N/A, ]
[G:\PROGRA~1\mkbd\sxrt.dll] [, 1, 0, 0, 6]
[G:\PROGRA~1\mkbd\ecwv.dll] [ , 1, 0, 0, 6]
后两个病毒模块插入了几乎所有(包挂瑞星)的进程。