注册表
<EXPLORER><C:\Program Files\Common Files\System\wab32res.exe> []
<ryirgs><C:\DOCUME~1\liu\LOCALS~1\Temp\iexpl0re.exe> []
<kv93rkd2><C:\DOCUME~1\liu\LOCALS~1\Temp\crasos.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<fy><C:\WINDOWS\Sysfy3\svchost.exe> []
<wm><C:\WINDOWS\Syswm7\svchost.exe> []
<wl><C:\WINDOWS\Syswl3\svchost.exe> []
<sun><C:\WINDOWS\SysSun2\svchost.exe> []
<JT><C:\WINDOWS\SysJT3\svchost.exe> []
服务
[TCP/IP Check / Hello Download][Stopped/Auto Start]
<C:\Program Files\Common Files\System\wab32res.exe><N/A>
[Windows Accounts Driver / WindowsConnections][Running/Auto Start]
<C:\WINDOWS\system32\server.exe><N/A>
运行程序
注入桌面
[PID: 1444][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Exprer.dll] [N/A, ]
[C:\WINDOWS\Sysfy3\Ghook.dll] [N/A, ]
[C:\WINDOWS\Syswm7\Ghook.dll] [N/A, ]
[C:\WINDOWS\SysJT3\Ghook.dll] [N/A, ]
[C:\WINDOWS\SysSun2\Ghook.dll] [N/A, ]
[C:\WINDOWS\Syswl3\Ghook.dll] [N/A, ]
[C:\WINDOWS\HKNTDLL.dll] [N/A, ]
[C:\DOCUME~1\liu\LOCALS~1\Temp\LgSy0.dll] [N/A, ]
[C:\DOCUME~1\liu\LOCALS~1\Temp\Msxo1.dll] [N/A, ]
[C:\DOCUME~1\liu\LOCALS~1\Temp\Kavs1.dll] [N/A, ]
注入VTtrayp.exe,SOUNDMAN.EXE等,几乎每个都注入
[C:\WINDOWS\SysJT3\Ghook.dll] [N/A, ]
[C:\WINDOWS\SysSun2\Ghook.dll] [N/A, ]
[C:\WINDOWS\Syswl3\Ghook.dll] [N/A, ]
[C:\WINDOWS\Syswm7\Ghook.dll] [N/A, ]
[C:\WINDOWS\Sysfy3\Ghook.dll] [N/A, ]
调用svchost.exe
[PID: 1904][C:\WINDOWS\Sysfy3\svchost.exe] [N/A, ]
[C:\WINDOWS\Sysfy3\Ghook.dll] [N/A, ]
[PID: 1916][C:\WINDOWS\Syswm7\svchost.exe] [N/A, ]
[C:\WINDOWS\Syswm7\Ghook.dll] [N/A, ]
[PID: 1952][C:\WINDOWS\Syswl3\svchost.exe] [N/A, ]
[C:\WINDOWS\Syswl3\Ghook.dll] [N/A, ]
[PID: 120][C:\WINDOWS\SysSun2\svchost.exe] [N/A, ]
[C:\WINDOWS\SysSun2\Ghook.dll] [N/A, ]
[PID: 144][C:\WINDOWS\SysJT3\svchost.exe] [N/A, ]
[C:\WINDOWS\SysJT3\Ghook.dll] [N/A, ]
修改的HOSTS 文件倒是挺有意思,似乎屏蔽的都是黄色网站
非常霸道的一个木马,恐怖哦!!
先建议你把上面的文件设法删除,不要重启,再扫描日志,发上来
如果对系统不是狠熟悉,还是建议你重新安装系统吧,