C:\WINDOWS\system32\dllcache\wuauclt.exe、C:\WINDOWS\system32\wuauclt.exe这两个系统文件被病毒替换了,需要优先用正常文件替换。
以下是日志显示的问题项目:
===========================================================================
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<internetnet><C:\WINDOWS\system32\wuauclt.exe> [(Verified)]
<20040927-1148><.vbe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.EXE]
<IFEO[360rpt.EXE]><C:\WINDOWS\system32\dllcache\wuauclt.exe> []
……………………………………(此处省略无数个病毒添加的IFEO项)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WOPTILITIES.EXE]
<IFEO[WOPTILITIES.EXE]><C:\WINDOWS\system32\dllcache\wuauclt.exe> []
驱动程序
[acpidisk / acpidisk][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[sys_hkt / sys_hkt][Others/Disabled]
<\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~65.tmp><N/A>
浏览器加载项
[CAdLogic Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\PushWare\cpush1.dll, >
[Info cache]
{285AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\WINDOWS\Aseo\pbhealth.dll, AMD Thulo-Kenny George's incredible size is his >
[网站排名工具条BHO]
{489873CE-F3E1-44A3-8E89-04BE26BE4446} <C:\Program Files\zzToolBar\Toolbar_bho.dll, (Signed) http://www.chinarank.org.cn>
[网站排名工具条]
{0A1230F1-EB52-4CA3-9D34-DE2ABC2EED35} <C:\Program Files\zzToolBar\ToolBand.dll, (Signed) http://www.chinarank.org.cn>
[CAdLogic Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\PushWare\cpush1.dll, >
[Info cache]
{285AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\WINDOWS\Aseo\pbhealth.dll, AMD Thulo-Kenny George's incredible size is his >
[网站排名工具条BHO]
{489873CE-F3E1-44A3-8E89-04BE26BE4446} <C:\Program Files\zzToolBar\Toolbar_bho.dll, (Signed) http://www.chinarank.org.cn>
正在运行的进程(仅指插入系统核心进程的病毒DLL文件)
[PID: 588 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\winlib .dll] [N/A, ]
Autorun.inf
[C:\]
[AutoRun]
shell\open=打开(&O)
shell\open\Command=GSR.PIF shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\command=GSR.PIF
[D:\]
[AutoRun]
shell\open=打开(&O)
shell\open\Command=GSR.PIF
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\command=GSR.PIF
[E:\]
[AutoRun]
shell\open=打开(&O)
shell\open\Command=GSR.PIF
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\command=GSR.PIF
[H:\]
[AutoRun]
shell\open=打开(&O)
shell\open\Command=GSR.PIF
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\command=GSR.PIF
[I:\]
[AutoRun]
shell\open=打开(&O)
shell\open\Command=GSR.PIF
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\command=GSR.PIF
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 1860, C:\WINDOWS\SYSTEM32\WUAUCLT.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1860, C:\WINDOWS\SYSTEM32\WUAUCLT.EXE]
===========================================================================