病毒修改注册表键值:
项:HKLM\SYSTEM\CurrentControlSet\Services\Privilege\
键值:DisplayName
指向数据:Performance Logs and Ale
项:HKLM\SYSTEM\CurrentControlSet\Services\Privilege\
键值:ImagePath
指向文件:%systemroot%\system32\Security.exe
项:HKLM\SYSTEM\CurrentControlSet\Services\Privilege\
键值:Description
指向数据:Intel Registry Service
项:HKLM\SYSTEM\CurrentControlSet\Services\Privilege\
键值:Start
指向数据:02 |
|