回复:【求助】十万火急,好厉害的变种木马
HOSTS 文件
127.0.0.1 localhost
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1940, C:\PROGRAM FILES\QVODPLAYER\QVODTERMINAL.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 316, C:\WINDOWS\USBLOGON.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 900, C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1168, C:\PROGRAM FILES\RISING\ANTISPYWARE\RUNIEP.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2944, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
==================================
API HOOK
入口点错误:NtCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003D4305)
入口点错误:NtWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003D43A5)
入口点错误:ZwCreateFile (危险等级: 高, 被下面模块所HOOK: 0x003D4305)
入口点错误:ZwWriteFile (危险等级: 高, 被下面模块所HOOK: 0x003D43A5)
==================================
隐藏进程
N/A
==================================
[/CODE]