[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(
Infected) Microsoft Corporation]
C:\WINDOWS\system32\userinit.exe被感染
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{59DABD72-6A3F-47C0-90E6-23022B72D463}><C:\Documents and Settings\NetworkService\Application Data\Dk.sys> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KAV><C:\WINDOWS\system32\kav.exe> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
有N多劫
(防止屏蔽)持
(防止屏蔽)项
根据进程判断为感染了木(防止屏蔽)马(防止屏蔽)下(防止屏蔽)载(防止屏蔽)者、木(防止屏蔽)马(防止屏蔽)群请用金
(防止屏蔽)山
(防止屏蔽)急
(防止屏蔽)救
(防止屏蔽)箱或者3
(防止屏蔽)6
(防止屏蔽)0
(防止屏蔽)急
(防止屏蔽)救
(防止屏蔽)箱处理下再上个日志
c:\documents and settings\networkservice\application data\dk.sys
c:\program files\common files\tenparty.dat
c:\windows\system32\dbr00006.iem
c:\windows\system32\dbr00006.mdd
c:\windows\system32\dbr01005.iem
c:\windows\system32\dbr01005.mdd
c:\windows\system32\dbr02006.iem
c:\windows\system32\dbr03004.iem
c:\windows\system32\dbr03004.mdd
c:\windows\system32\dbr04004.iem
c:\windows\system32\dbr04004.mdd
c:\windows\system32\dbr05005.iem
c:\windows\system32\dbr05005.mdd
c:\windows\system32\dbr06004.iem
c:\windows\system32\dbr07005.iem
c:\windows\system32\dbr08006.iem
c:\windows\system32\dbr08006.mdd
c:\windows\system32\dbr09004.iem
c:\windows\system32\dbr09004.mdd
c:\windows\system32\dbr10003.iem
c:\windows\system32\dbr10003.mdd
c:\windows\system32\dbr11004.iem
c:\windows\system32\dbr12004.iem
c:\windows\system32\dbr12004.mdd
c:\windows\system32\dbr13004.iem
c:\windows\system32\dbr13004.mdd
c:\windows\system32\dbr14005.iem
c:\windows\system32\dbr14005.mdd
c:\windows\system32\dbr15005.iem
c:\windows\system32\dbr17002.iem
c:\windows\system32\dbr17002.mdd
c:\windows\system32\msctfime.iem
c:\windows\system32\msimg32.dll
c:\windows\system32\userinit.exe,c:\windows\system32\kav.exe
c:\windows\system32\mrinet.exe
驱动
[12AF57B1 / 12AF57B1] <>
[12AF57B1 / 12AF57B1] <>
服务
Microsoft .NET Framework v4.2.58373_x86 / MnetFream] <C:\WINDOWS\system32\mrinet.exe>