第二部主机报告:
Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS.0\System32\ctfmon.exe> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RfwMain><C:\Program Files\Rising\Rfw\rfwmain.exe> []
<CnsMin><Rundll32.exe C:\WINDOWS.0\downlo~1\CnsMin.dll,Rundll32> [北京三七二一科技有限公司]
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<xBarUpdate><C:\Program Files\xBar\xBarUpdate.exe> []
<C-Media Mixer><Mixer.exe /startup> [C-Media Electronic Inc. (www.cmedia.com.tw)]
<StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> []
<SoundMan><SOUNDMAN.EXE> [Realtek Semiconductor Corp.]
<SonudMan><C:\WINDOWS.0\System32\vidcap32.exe> []
<PHIME2002ASync><C:\WINDOWS.0\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><C:\WINDOWS.0\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<nwiz><nwiz.exe /install> [NVIDIA Corporation]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS.0\System32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<IMJPMIG8.1><"C:\WINDOWS.0\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<helper.dll><C:\WINDOWS.0\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32> []
<worknote1><C:\WINDOWS.0\System32\SYSNOTE.EXE> []--------------U盘病毒
<Desktop><C:\WINDOWS.0\System32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll> []
<TProgram><C:\WINDOWS.0\smss.exe> [iSw78fh2kl3A]---------------------落雪
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
<alsmt.exe><C:\WINDOWS.0\System32\alsmt.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<CheckFaultKernel><C:\WINDOWS.0\System32\mswdm.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><explorer.exe 1> []-------------------- 修改注册表
<Userinit><C:\WINDOWS.0\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><KB399952M.LOG> []-----------------感染内存的病毒
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS.0\downlo~1\CnsHook.dll> [北京三七二一科技有限公司]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad]
<SysTime><C:\PROGRA~1\WinKld\WinKld.dll> [www.88dog.com]----------------------
<webwork><C:\WINDOWS.0\webwork\webwork.dll> [MSWebwork Cop.]
<DLMon><C:\WINDOWS.0\System32\DLMain.dll> []------------------------------
==================================
启动文件夹
[startup]
<C:\Documents and Settings\All Users\「开始」菜单\程序\启动\startup.bat><N>-------------------------
==================================
服务
[JMediaService / JMediaService]
<C:\WINDOWS.0\System32\rundll32.exe C:\PROGRA~1\MMSASS~1\MMSSVER.DLL,Service><N/A>---------------------------
[NVIDIA Driver Helper Service / NVSvc]
<C:\WINDOWS.0\System32\nvsvc32.exe><NVIDIA Corporation>
[Rising Personal Firewall Service / RfwService]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Corporation Limited>
[Window Services Pack Install / Spullepdsvc]------------------------------------------------------清除成功。
<C:\Program Files\Common Files\ktxp.exe><N/A>
[StdService / StdService]
<C:\WINDOWS.0\System32\rundll32.exe C:\WINDOWS.0\System32\STDSVER.DLL,Service><N/A>---------------------------------------
[Svchost Service For Windows / svchost]--------------------------------
<C:\WINDOWS.0\svchost.exe><N/A>
[WinkldUP / WinkldUP]--------------------------------------------------
<C:\DOCUME~1\zzw\LOCALS~1\Temp\wz\wz.exe -R><N/A>------------------------------
[WintUPp / WintUPp]
<C:\DOCUME~1\zzw\LOCALS~1\Temp\wt\wt.exe -R><N/A>----------------------------------------------
[WinWrCup / WinWrCup]
<C:\WINDOWS.0\wincup\wincup.exe -R><MsWinCup>------------------------------------