vspool.exe感染系统详细记录
Create file
Object:C:\windows\system32\vspool.exe
Starting process
Object:C:\WINDOWS\system32\vspool.exe
Create registry key
Object:HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal
Set registry key value
Object:HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\Vspool\\
Create registry key
Object:HKLM\System\CurrentControlSet\Control\SafeBoot\Network
Set registry key value
Object:HKLM\System\CurrentControlSet\Control\SafeBoot\Network\Vspool\\
Set registry key value
Object:HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\\Cache
Set registry key value
Object:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\\Directory
Set registry key value
Object:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\\Paths
Set registry key value
Object:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\\CachePath
Set registry key value
Object:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\\CachePath
Set registry key value
Object:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3\\CachePath
Set registry key value
Object:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\\CachePath
Set registry key value
Object:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\\CacheLimit
Set registry key value
Object:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\\CacheLimit
Set registry key value
Object:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\\CacheLimit
Set registry key value
Object:HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\\Cookies
Set registry key value
Object:HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\\History
Set registry key value
Object:HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProxyBypass
Set registry key value
Object:HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\IntranetName
Set registry key value
Object:HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\UNCAsIntranet
Create file
Object:C:\Documents and Settings\用户名\Local Settings\Temp\terminate.bat
Time:2005-8-11 15:51:48