| 引用: |
| 【baohe的贴子】vspool.exe感染系统详细记录 Create file :C:\windows\system32\vspool.exe Starting process :C:\WINDOWS\system32\vspool.exe Create registry key :HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal Set registry key value :HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\Vspool\\ Create registry key :HKLM\System\CurrentControlSet\Control\SafeBoot\Network Set registry key value :HKLM\System\CurrentControlSet\Control\SafeBoot\Network\Vspool\\ Set registry key value :HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\\Cache Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\\Directory Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\\Paths Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\\CachePath Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\\CachePath Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3\\CachePath Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\\CachePath Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\\CacheLimit Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\\CacheLimit Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\\CacheLimit Set registry key value :HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\\Cookies Set registry key value :HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\\History Set registry key value :HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProxyBypass Set registry key value :HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\IntranetName Set registry key value :HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\UNCAsIntranet Create file :C:\Documents and Settings\用户名\Local Settings\Temp\terminate.bat Time:2005-8-11 15:51:48 ........................... |
| 引用: |
| 【茶香蜜糖的贴子】斑竹,有问题想问,我已经把补丁都打全了,瑞星也每天杀毒。危险端口也封上了,为什么还是老中木马阿,我应该还防范点什么啊?我最近这个礼拜一直在中木马,每天都在中,一天一个新木马。 ........................... |
| 引用: |
| 【baohe的贴子】vspool.exe感染系统详细记录 Create file :C:\windows\system32\vspool.exe Starting process :C:\WINDOWS\system32\vspool.exe Create registry key :HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal Set registry key value :HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\Vspool\\ Create registry key :HKLM\System\CurrentControlSet\Control\SafeBoot\Network Set registry key value :HKLM\System\CurrentControlSet\Control\SafeBoot\Network\Vspool\\ Set registry key value :HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\\Cache Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\\Directory Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\\Paths Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\\CachePath Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\\CachePath Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3\\CachePath Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\\CachePath Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\\CacheLimit Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\\CacheLimit Set registry key value :HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\\CacheLimit Set registry key value :HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\\Cookies Set registry key value :HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\\History Set registry key value :HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProxyBypass Set registry key value :HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\IntranetName Set registry key value :HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\UNCAsIntranet Create file :C:\Documents and Settings\用户名\Local Settings\Temp\terminate.bat Time:2005-8-11 15:51:48 ........................... |
| 引用: |
| 【命运里の金色的贴子】这个日志从TPF哪里出来的,随便问下在IDS&IPS里的Rules有条backdoor.rules有必要选上吗? ........................... |