回复: 受到攻击(附日志)
t同意2楼意见,病毒倒是其次,要命的是系统关键服务被禁用,一些系统关键进程被替换或丢失,处理起来相当麻烦:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)]
<Userinit><C:\WINDOWS\system32\UserInit.exe,> [(Verified)]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<explorer><C:\WINDOWS\system32\wuauclt.exe> [(Verified)]
[Application Layer Gateway Service / ALG][Stopped/Disabled]
<C:\WINDOWS\System32\alg.exe><(File is missing)>
[Indexing Service / CiSvc][Stopped/Auto Start]
<C:\WINDOWS\system32\cisvc.exe><(File is missing)>
[ClipBook / ClipSrv][Stopped/Disabled]
<C:\WINDOWS\system32\clipsrv.exe><(File is missing)>
如果是病毒干的,这病毒也够黑的了。不过把下面这个服务和映像文件弄掉,不知道想演哪出戏……
[Application Layer Gateway Service / ALG][Stopped/Disabled]
<C:\WINDOWS\System32\alg.exe><(File is missing)>