样本分析:
用清理专家检查到异常的XX就被关了,
进程
secuers32.exe和server.exe区别开使用这个工具清除下:http://devbuilds.kaspersky-labs.com/devbuilds/AVPTool/以下是找到的异常文件,可以参考:[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\Userinit.exe,C:\Program Files\Common Files\System\
secuers32.exe,C:\WINDOWS\svchost.exe>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<通讯簿 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.NT> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing]
特殊特权被允许: SeDebugPrivilege [PID = 240, C:\PROGRAM FILES\COMMON FILES\SYSTEM\SECUERS32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 240, C:\PROGRAM FILES\COMMON FILES\SYSTEM\SECUERS32.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 564, C:\PROGRAM FILES\COMMON FILES\SYSTEM\SERVER32.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 564, C:\PROGRAM FILES\COMMON FILES\SYSTEM\SERVER32.EXE]
服务的英语不这么写SERVER