本帖最后由 ELOHIM 于 2019-10-27 22:22 编辑
刚刚检测又发现一个这个:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eizboang]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000000
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,\
64,00,6f,00,77,00,73,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,64,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,65,00,69,00,7a,00,\
62,00,6f,00,61,00,6e,00,67,00,2e,00,73,00,79,00,73,00,00,00
"Group"="Boot Bus Extender"
"Args"="C:\\Windows\\system32\\drivers\\eizboang.sys:changelist"
服务已安装在系统中。
服务名称: DBUtil_2_3
服务文件名: C:\Users\Human\AppData\Local\Temp\DBUtil_2_3.Sys
服务类型: 内核模式驱动程序
服务启动类型: 按需启动
|