致:“孤独更可靠”——新“随机7”没什么新意
释放的文件见附图。
SRENG 2.5日志异常项如下:
启动项目
注册表
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<tckflml><C:\windows\system32\hehfdvi.exe> []
<nahpwiq><C:\windows\system32\gdaxqhm.exe> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe]
<IFEO[360rpt.exe]><C:\windows\system32\gdaxqhm.exe> []
..............N项(与老版相同)
==================================
正在运行的进程
[PID: 3244][C:\windows\system32\hehfdvi.exe] [N/A, ]
[PID: 2304][C:\windows\system32\gdaxqhm.exe] [N/A, ]
==================================
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 3244, C:\WINDOWS\SYSTEM32\HEHFDVI.EXE]
特殊特权被允许: SeLoadDriverPrivilege [PID = 2304, C:\WINDOWS\SYSTEM32\GDAXQHM.EXE]