大概就看到这么多,连350safe.exe都出来了,汗……
=================================
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<internetnet><C:\WINDOWS\system32\spoolsv.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [](系统文件被替换了)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.EXE]
<IFEO[360rpt.EXE]><C:\WINDOWS\system32\dllcache\spoolsv.exe> []
…………………………(省略一堆IFEO项)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WOPTILITIES.EXE]
<IFEO[WOPTILITIES.EXE]><C:\WINDOWS\system32\dllcache\spoolsv.exe> []
==================================
服务(可能该系统服务映像文件和注册表项已被病毒替换掉)
[Print Spooler / Spooler][Stopped/Auto Start]
<C:\WINDOWS\system32\spoolsv.exe><Microsoft Corporation>
==================================
驱动程序
[acpidisk / acpidisk][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\acpidisk.sys><N/A>
[MyDog / MyDog][Running/Disabled]
<\??\C:\WINDOWS\system32\Drivers\Atieccx.sys><N/A>
==================================
浏览器加载项
[CAdLogic Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\PushWare\cpush.dll, >
[Info cache]
{285AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\WINDOWS\Wisb\pbhealth.dll, Polls>
[CAdLogic Object]
{11F09AFD-75AD-4E51-AB43-E09E9351CE16} <C:\Program Files\Common Files\PushWare\cpush.dll, >
[Info cache]
{285AB8C6-FB22-4D17-8834-064E2BA0A6F0} <C:\WINDOWS\Wisb\pbhealth.dll, Polls>
==================================
正在运行的进程
[C:\WINDOWS\system32\winlib .dll] [N/A, ]
[PID: 1488 / Administrator][C:\WINDOWS\system32\350safe.exe] [N/A, ]
[PID: 876 / Administrator][C:\WINDOWS\Fonts\svchost.exe] [N/A, ]
==================================
Autorun.inf
[C:\]
[AutoRun] shell\open=打开(&O) shell\open\Command=HGZP.PIF shell\open\Default=1 shell\explore=资源管理器(&X) shell\explore\command=HGZP.PIF
[D:\]
[AutoRun] shell\open=打开(&O) shell\open\Command=HGZP.PIF shell\open\Default=1 shell\explore=资源管理器(&X) shell\explore\command=HGZP.PIF
[E:\]
[AutoRun] shell\open=打开(&O) shell\open\Command=HGZP.PIF shell\open\Default=1 shell\explore=资源管理器(&X) shell\explore\command=HGZP.PIF
==================================
进程特权扫描
特殊特权被允许: SeDebugPrivilege [PID = 1944, C:\WINDOWS\SYSTEM32\SPOOLSV.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1944, C:\WINDOWS\SYSTEM32\SPOOLSV.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1488, C:\WINDOWS\SYSTEM32\350SAFE.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1488, C:\WINDOWS\SYSTEM32\350SAFE.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 876, C:\WINDOWS\FONTS\SVCHOST.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 876, C:\WINDOWS\FONTS\SVCHOST.EXE]
特殊特权被允许: SeDebugPrivilege [PID = 1860, C:\WINDOWS\DOWNLOADED PROGRAM FILES\SVCHOST.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 1860, C:\WINDOWS\DOWNLOADED PROGRAM FILES\SVCHOST.EXE]
==================================