回复:7月21日 日志分析 练习6
1:文件关联修复
2:注册表:
<LeyuBoxData><E:\应用软件\Leyu\LeyuBox.exe p2p> [File is missing]
<360tray><C:\WINDOWS\dyloty\spoolsv.vbs> []
<nwiz><nwiz.exe /installquiet> []
<36tray><C:\WINDOWS\kkty\555.vbs> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logondll]
<WinlogonNotify: logondll><fly4715.dll> []
3进程:[PID: 576 / SYSTEM][C:\WINDOWS\System32\WLTRYSVC.EXE] [N/A, ]
[C:\WINDOWS\system32\nvshell.dll] [, ]
[E:\应用软件\Leyu\vod.dll] [N/A, ]