回复:7月21日 日志分析 练习3
第一;host文件要修复
第二:
文件关联 修复一下
第三:计划任务
第四进程:
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.3.3.345]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2497]
[C:\Program Files\Micropoint\mp110031.dll] [Micropoint Corporation, 1.3.3.345]
程序驱动:
[npkcrypt / npkcrypt][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\npkcrypt.sys><N/A>
[npkycryp / npkycryp][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\npkycryp.sys><N/A>
[winachsf / winachsf][Running/Manual Start]
<system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
注册表:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing]
<thxpl><C:\WINDOWS\system32\ocskg.dll> [File is missing]
<stup.exe><; Rundll32.exe C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll,Rundll32 R> [File is missing]
对对答案啊