注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<HBService32><System.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [Microsoft Corporation]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><HBmhly.dll,HBDNF.dll,HBTL.dll,HBASKTAO.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{D7C79813-9233-4AE0-832C-99B2E8019673}><D7C79813.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe]
<IFEO[360rpt.exe]><ntsd -d> [N/A]
……………………(一堆IFEO,就不一一列出了)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zxsweep.exe]
<IFEO[zxsweep.exe]><ntsd -d> [N/A]
==================================
驱动程序
[HBKernel32 Driver / HBKernel32][Stopped/Boot Start]
<\SystemRoot\system32\drivers\HBKernel32.sys><N/A>
[f35ee9e / f35ee9e][Running/Manual Start]
<\??\C:\WINDOWS\system32\f35ee9e.sys><N/A>
==================================
正在运行的进程
[PID: 1596][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\D7C79813.dll] [N/A, ]
[PID: 2024][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\WINDOWS\system32\HBmhly.dll] [N/A, ]
[C:\WINDOWS\system32\HBDNF.dll] [N/A, ]
[C:\WINDOWS\system32\D7C79813.dll] [N/A, ]
[C:\WINDOWS\system32\HBTL.dll] [N/A, ]
[C:\WINDOWS\system32\HBASKTAO.dll] [N/A, ]
[C:\WINDOWS\system32\HBXMJ.dll] [N/A, ]
[PID: 236][C:\WINDOWS\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.1.0.8]
[C:\WINDOWS\system32\D7C79813.dll] [N/A, ]
[PID: 364][C:\WINDOWS\system32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\D7C79813.dll] [N/A, ]
[PID: 380][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\D7C79813.dll] [N/A, ]
[C:\WINDOWS\system32\HBASKTAO.dll] [N/A, ]
[C:\WINDOWS\system32\HBTL.dll] [N/A, ]
[C:\WINDOWS\system32\HBDNF.dll] [N/A, ]
[C:\WINDOWS\system32\HBmhly.dll] [N/A, ]
[PID: 556][C:\Program Files\Tencent\QQ\QQ.exe] [TENCENT, 8,0,775,1803]
[C:\WINDOWS\system32\HBDNF.dll] [N/A, ]
[C:\WINDOWS\system32\HBmhly.dll] [N/A, ]
[C:\WINDOWS\system32\HBTL.dll] [N/A, ]
[C:\WINDOWS\system32\D7C79813.dll] [N/A, ]
[C:\WINDOWS\system32\HBASKTAO.dll] [N/A, ]
[C:\WINDOWS\system32\HBXMJ.dll] [N/A, ]
[PID: 900][C:\Program Files\WinRAR\WinRAR.exe] [N/A, ]
[C:\WINDOWS\system32\D7C79813.dll] [N/A, ]
[PID: 1144][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.235\SRE7a4f2056.EXE] [Smallfrogs Studio, 2.7.0.1210]
[C:\WINDOWS\system32\HBmhly.dll] [N/A, ]
[C:\WINDOWS\system32\HBDNF.dll] [N/A, ]
[C:\WINDOWS\system32\D7C79813.dll] [N/A, ]
[C:\WINDOWS\system32\HBASKTAO.dll] [N/A, ]
[C:\WINDOWS\system32\HBTL.dll] [N/A, ]
[C:\WINDOWS\system32\HBXMJ.dll] [N/A, ]
[PID: 2012][G:\绿化.bat] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\D7C79813.dll] [N/A, ]
[PID: 1708][C:\WINDOWS\system32\System.exe] [N/A, ]
[C:\WINDOWS\system32\HBmhly.dll] [N/A, ]
[C:\WINDOWS\system32\HBDNF.dll] [N/A, ]
[C:\WINDOWS\system32\HBTL.dll] [N/A, ]
[C:\WINDOWS\system32\D7C79813.dll] [N/A, ]
[C:\WINDOWS\system32\HBASKTAO.dll] [N/A, ]
[C:\WINDOWS\system32\HBXMJ.dll] [N/A, ]
==================================
Autorun.inf
[C:\]
[AutoRun]
open=.\绿化.bat
shell\open=打开(&O)
shell\open\Command=.\绿化.bat
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=.\绿化.bat
[E:\]
[AutoRun]
open=.\绿化.bat
shell\open=打开(&O)
shell\open\Command=.\绿化.bat
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=.\绿化.bat
[F:\]
[AutoRun]
open=.\绿化.bat
shell\open=打开(&O)
shell\open\Command=.\绿化.bat
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=.\绿化.bat
[G:\]
[AutoRun]
open=.\绿化.bat
shell\open=打开(&O)
shell\open\Command=.\绿化.bat
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=.\绿化.bat==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 2012, G:\绿化.BAT]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2012, G:\绿化.BAT]
特殊特权被允许: SeDebugPrivilege [PID = 1708, C:\WINDOWS\SYSTEM32\SYSTEM.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1708, C:\WINDOWS\SYSTEM32\SYSTEM.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 412, C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMP\SVCHOST.EXE]