启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)]
==================================
服务
[360安全卫士查杀模块 / 360安全卫士查杀模块.exe][Stopped/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k 360安全卫士查杀模块.exe-->%SystemRoot%\System32\jlmsbj.dll><N/A>
[Microsoft Device Manager / Ias][Stopped/Auto Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\system32\Winsvr.dll><N/A>
==================================
正在运行的进程
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 868 / SYSTEM][RsHide] [N/A, ]
[PID: 952 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-
2158)]
[PID: 1048 / SYSTEM][RsHide] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 1776 / Administrator][RsHide] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 2016 / Administrator][RsHide] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[PID: 312 / Administrator][RsHide] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsv24.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\PROGRA~1\OCINS\ieaux.dll] [中国互联网络信息中心(CNNIC), 2, 6, 0, 9]
[C:\PROGRA~1\OCINS\idnsvr.dll] [中国互联网信息中心(CNNIC), 2, 6, 0, 4]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rsvB.tmp] [Beijing Rising Tech. Co., Ltd., 1, 3, 0, 0]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.CHM Error. ["hh.exe" %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 1692, C:\WINDOWS\EXPLORER.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1692, C:\WINDOWS\EXPLORER.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1776, C:\WINDOWS\RSHIDE]
特殊特权被允许: SeDebugPrivilege [PID = 2016, C:\WINDOWS\RSHIDE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2016, C:\WINDOWS\RSHIDE]
特殊特权被允许: SeDebugPrivilege [PID = 312, C:\WINDOWS\RSHIDE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 312, C:\WINDOWS\RSHIDE]
==================================
隐藏进程
N/A
==================================
补充