杀掉后,发现没用,每次开机就又发现。
另外 每次开机注册表 run 项目下增加 启动项HKLM\\Run: [ATICardInit] VideoAti0.exe
于是用RootkitRevealer扫描,报告如下
HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\VideoAti0 2006-6-9 22:19 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\VideoAti0 2006-6-9 22:19 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_VIDEOATI0 2006-6-9 22:19 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\d347prt\Cfg\0Jf40 2006-9-12 7:16 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\VideoAti0 2006-9-14 7:12 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_VIDEOATI0 2006-6-9 22:19 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\VideoAti0 2007-2-1 1:27 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Control\SafeBoot\Minimal\VideoAti0 2006-6-9 22:19 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Control\SafeBoot\Network\VideoAti0 2006-6-9 22:19 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_VIDEOATI0 2006-6-9 22:19 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Services\VideoAti0 2006-9-14 7:12 0 bytes Hidden from Windows API.
C:\WINDOWS\SYSTEM32\DRIVERS\VideoAti0.sys 2006-6-17 20:46 19.68 KB Hidden from Windows API.
C:\WINDOWS\SYSTEM32\VideoAti0.dll 2006-6-17 20:46 144.00 KB Hidden from Windows API.
C:\WINDOWS\SYSTEM32\VideoAti0.exe 2006-6-17 20:46 56.00 KB Hidden from Windows API.
Originally posted by flo at 2006-10-21 22:01:
stdie.dll不晓得...
后面那个应该是某个Rootkit,请进到安全模式去吧,然后再看,再安全模式下这类隐藏技巧应该都是没有用的。或者,如果这个Rootkit是靠涂改SSDT隐藏的话,请下载一个SSDT Recover([url]http:/ ...