key: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
data: userinit.exe,c:\program files (x86)\microsoft\desktoplayer.exe
file: c:\program files (x86)\common files\microsoft shared\equation\eqnedt32.exe
file: c:\program files (x86)\7-zip\7zfm.exe
file: c:\program files (x86)\7-zip\7zg.exe
Blacklist: fget-career.com
行为分析
执行的命令
- C:\Users\test\AppData\Local\Temp\BaoPoSrv.exe
- C:\Program Files (x86)\Microsoft\DesktopLayer.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
创建的服务
无信息
启动的服务
无信息
进程
BaoPo.exe PID: 2480, 上一级进程 PID: 2336
BaoPoSrv.exe PID: 2556, 上一级进程 PID: 2480
DesktopLayer.exe PID: 2632, 上一级进程 PID: 2556
chrome.exe PID: 2708, 上一级进程 PID: 2632
删除的文件
- C:\Program Files (x86)\Microsoft\px3B98.tmp
注册表键
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
- HKEY_CLASSES_ROOT\http\shell\open\command
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\http\shell\open\command\(Default)
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
- HKEY_LOCAL_MACHINE\Software\WASAntidot
读取的注册表键
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\http\shell\open\command\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
修改的注册表键
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
删除的注册表键
无信息