杀病毒RavMon.exe/SVCHOST.EXE/MDM.EXE

启动项目
注册表
[HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/CurrentVersion/Run]
    <SVCHOST><C:/WINDOWS/MDM.EXE>  []
Autorun.inf
[C:/]
[AutoRun]
open=RavMon.exe
shell/open=打开(&O)
shell/open/Command=RavMon.exe
shell/explore=资源管理器(&X)
shell/explore/Command="RavMon.exe -e"
进程特权扫描
特殊特权被允许: SeLoadDriverPrivilege [PID = 1772, C:/WINDOWS/SVCHOST.EXE]

你可能感兴趣的:(杀病毒RavMon.exe/SVCHOST.EXE/MDM.EXE)