【回复“小呀小顽童”的帖子】



病毒/木马的加载项:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><235780M.BMP> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{9C0CFA58-3A6F-51ba-9EFE-5320F4F62FB1}><D:\WINDOWS\system32\bdscheca100.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<csrss><; D:\WINDOWS\csrss.exe> [N/A]
<System><; D:\Program Files\Common Files\System\Updaterun.exe> [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Windows installer><; C:\winstall.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<{202718E6-0957-2052-1008-030207290056}><; "D:\Program Files\Common Files\{202718E6-0957-2052-1008-030207290056}\Update.exe" te-110-12-0000175> [N/A]
<{202718E6-0958-2052-1008-030207290056}><; "D:\Program Files\Common Files\{202718E6-0958-2052-1008-030207290056}\Update.exe" te-110-12-0000175> [N/A]
木马服务:
[Windows DHCP Service / WinDHCPsvc][Stopped/Auto Start]
<D:\WINDOWS\system32\rundll32.exe windhcp.ocx,start><Microsoft Corporation>
病毒/木马驱动:
[MicroSoft Media Services / MediaDrver][Stopped/Manual Start]
<\??\D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\YpOCalLH.sys><N/A>
[Netgroup Packet Filter / NPF][Stopped/Manual Start]
<system32\DRIVERS\npf.sys><CACE Technologies>
[SVKP / SVKP][Running/Auto Start]
<\??\D:\WINDOWS\system32\SVKP.sys><AntiCracking>
被病毒/木马插入的进程:
[PID: 488][\??\D:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 540][D:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 552][D:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 748][D:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 796][D:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 916][D:\Program Files\Rising\Rav1\CCenter.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 3]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 980][D:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 1080][D:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 1120][D:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 1344][D:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 1380][D:\WINDOWS\system32\msdtc.exe] [Microsoft Corporation, 2001.12.4720.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 1492][D:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[PID: 1568][D:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[PID: 1912][D:\WINDOWS\system32\Dfssvc.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\bdscheca100.dll] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[PID: 2044][D:\tem\VRV2005\VRV2005\vrv2005\vrvmon.exe] [vrv, 1, 0, 0, 1]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[PID: 216][D:\Program Files\Rising\Rav1\RavTask.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[D:\WINDOWS\system32\bdscheca100.dll] [N/A, N/A]
[PID: 340][D:\Program Files\Rising\Rav1\Ravmon.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[D:\WINDOWS\system32\bdscheca100.dll] [N/A, N/A]
[PID: 1044][D:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[D:\WINDOWS\system32\bdscheca100.dll] [N/A, N/A]
[PID: 1616][D:\WINDOWS\system32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.2.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[PID: 804][D:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[D:\WINDOWS\system32\bdscheca100.dll] [N/A, N/A]
[PID: 2772][D:\WINDOWS\system\conime.exe] [N/A, N/A]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[D:\WINDOWS\system32\bdscheca100.dll] [N/A, N/A]
[PID: 3912][D:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[D:\WINDOWS\system32\bdscheca100.dll] [N/A, N/A]
[PID: 1316][D:\Program Files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.3790.0 (srv03_rtm.030324-2048)]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[D:\WINDOWS\system32\bdscheca100.dll] [N/A, N/A]
[PID: 2172][D:\RAV\SRENG\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[D:\WINDOWS\235780M.BMP] [N/A, N/A]
[D:\WINDOWS\system32\windhcp.ocx] [N/A, N/A]
[D:\WINDOWS\system32\bdscheca100.dll] [N/A, N/A]
被篡改的文件关联:
.TXT Error. [notepad.exe %1]
.REG Error. [regedit.exe %1]
.CHM Error. [D:\WINDOWS\hh.exe %1]
.HLP Error. [D:\WINDOWS\winhlp32.exe %1]
.INI Error. [notepad.exe %1]
.INF Error. [D:\WINDOWS\NOTEPAD.EXE %1]