个人认为日志中的异常项目如下,几个伪微软签名的病毒文件是其根源,估计能通过远程计算机在本地建立计划任务,造成屡杀不死的现象:
========================
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<e26b><rundll32 "C:\Windows\Downlo~1\e26b.dll",Run> [Microsoft Corporation]
服务
[Gebley / Gebley][Stopped/Auto Start]
<C:\Windows\system32\1r7b.exe><(File is missing)>
[OSEvent / OSEvent][Stopped/Auto Start]
<C:\Windows\system32\t.exe><Microsoft Corporation>
驱动程序
[xflirgh / xflirgh][Running/Boot Start]
<\SystemRoot\system32\drivers\nswmj.sys><N/A>
浏览器加载项
[Invoke Class]
{C44A4F21-CD5E-44fd-BB98-E27579F275B5} <C:\Windows\system32\2cp5.dll, N/A>
[Invoke Class]
{C44A4F21-CD5E-44FD-BB98-E27579F275B5} <C:\Windows\system32\2cp5.dll, N/A>
正在运行的进程(仅指插入进程的DLL模块,红色的就是)
[PID: 324 / hp][C:\Windows\Explorer.EXE] [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\Downlo~1\e26b.dll] [Microsoft Corporation, 5, 3, 2600, 2180][PID: 3516 / hp][C:\Windows\system32\rundll32.EXE] [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[C:\Windows\Downlo~1\e26ac.dll] [Microsoft Corporation, 8, 90, 1101, 0]
计划任务
[已启用] \\e26ac
rundll32 C:\Windows\Downlo~1\e26ac.dll,Always
[已启用] \\e26b
rundll32 C:\Windows\Downlo~1\e26b.dll,Run
============================