[+] Windows Firewall开放的端口
[+] Windows劫持
数值名称: DisableSR
数值数据: 1
注册表项: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore
数值名称: SFCDisable
数值数据: 0
注册表项: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
数值名称: FirstRunDisabled
数值数据: 1
注册表项: HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center
数值名称: AntiVirusDisableNotify
数值数据: 0
注册表项: HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center
数值名称: FirewallDisableNotify
数值数据: 0
注册表项: HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center
数值名称: UpdatesDisableNotify
数值数据: 0
注册表项: HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center
数值名称: AntiVirusOverride
数值数据: 0
注册表项: HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center
数值名称: FirewallOverride
数值数据: 0
注册表项: HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center
数值名称: EnableDCOM
数值数据: Y
注册表项: HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
数值名称: Start
数值数据: 2
注册表项: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry
数值名称: EnableSecurityFilters
数值数据: 0
注册表项: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
数值名称: Wallpaper
数值数据: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
注册表项: HKEY_CURRENT_USER\Control Panel\Desktop
数值名称: OriginalWallpaper
数值数据: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
注册表项: HKEY_CURRENT_USER\Control Panel\Desktop
数值名称: ConvertedWallpaper
数值数据: E:\cc\壁纸\20070608_3a69bb46c81bd21738727JYlhXzKhIUX.jpg
注册表项: HKEY_CURRENT_USER\Control Panel\Desktop
[+] 临时文件夹中的可执行程序
[+] 可疑文件夹中的可执行程序
C:\Program Files\windows nt\hypertrm.exe (28160 bytes) (Hilgraeve, Inc.) (e71ddbd9bedbcd46995044f2bdf6e6ad)
[+] Internet Explorer文件夹中的可执行程序
C:\Program Files\Internet Explorer\ExtExport.exe (144384 bytes) (Microsoft Corporation) (44d37a87f00d8684ad907dae295f67fb)
C:\Program Files\Internet Explorer\iedvtool.dll (742912 bytes) (Microsoft Corporation) (bd3c4101b9340e697c9eb0c9c7c9fedf)
C:\Program Files\Internet Explorer\iexplore.exe.mui (12288 bytes) (Microsoft Corporation) (4eaf0ddc2158ca4aae6c18e98a246e45)
C:\Program Files\Internet Explorer\jsdbgui.dll (521216 bytes) (Microsoft Corporation) (33db6e706fd3a2271033c5d29b3d6f76)
C:\Program Files\Internet Explorer\jsdebuggeride.dll (121344 bytes) (Microsoft Corporation) (3494af094cfb1d1b9a3c1ce255492b6c)
C:\Program Files\Internet Explorer\JSProfilerCore.dll (118272 bytes) (Microsoft Corporation) (d68cc4e775420716b6abc4d188d5d316)
C:\Program Files\Internet Explorer\jsprofilerui.dll (233984 bytes) (Microsoft Corporation) (0f6a0675181d3ae76755986f3bf9e598)
C:\Program Files\Internet Explorer\pdm.dll (355832 bytes) (Microsoft Corporation) (3ca2dfd1ee857cde7dccf4235f52d142)
C:\Program Files\Internet Explorer\sqmapi.dll (134144 bytes) (Microsoft Corporation) (5eb87ba0b93ca7e894fc8002e3ce4c2a)
C:\Program Files\Internet Explorer\xpshims.dll (12800 bytes) (Microsoft Corporation) (91aa17d860c4903fa8d0d8c009a449f5)
C:\Program Files\Internet Explorer\ieproxy.dll (247808 bytes) (Microsoft Corporation) (5696576e4e717efc67fcb62953800064)
C:\Program Files\Internet Explorer\iecompat.dll (64000 bytes) (Microsoft Corporation) (c49bcadd185a78e548a7b87434dd5c26)
[+] 自定义文件列表
C:\WINDOWS\setdebug.exe (46352 bytes) (Microsoft Corporation) (afab870a40df457165c83896e546fe92)
C:\WINDOWS\stsystra.exe (282624 bytes) (SigmaTel, Inc.) (289bdc9e5681bd1be0fb871c460bd254)
C:\WINDOWS\system32\keystone.exe (425984 bytes) (Unknown) (94eb51915cf36b7f094501d40655b2a9)
C:\WINDOWS\system32\setver.exe (12141 bytes) (Unknown) (db3bd5aab4a9f3b9c4b772bdac84cdfb)
C:\WINDOWS\system32\taskman.exe (15360 bytes) (Microsoft Corporation) (005ab22c5d9123cc4840eb54ae521a51)
C:\WINDOWS\system32\migpwd.exe (51712 bytes) (Microsoft Corporation) (d6165edbaa5f3b26375a7eb511b12b70)
C:\WINDOWS\system32\ieudinit.exe (36864 bytes) (Microsoft Corporation) (06a0d051b6937cda3e38702494bbfc2a)
C:\WINDOWS\system32\nvappbar.exe (442368 bytes) (Unknown) (fbf363882470999ac2d47f25feacd559)
C:\WINDOWS\system32\nvcolor.exe (147456 bytes) (NVIDIA Corporation) (c3bce4508661cddba9f8ab9d9ca0341f)
C:\WINDOWS\system32\nvdspsch.exe (1339392 bytes) (Unknown) (eb7fe7d15c13240d46818a6dbe435a90)
C:\WINDOWS\system32\nwiz.exe (1617920 bytes) (Unknown) (bf40c88ceebd9ea8f5d1ec858d9cc92e)
C:\WINDOWS\system32\spupdsvc.exe (26144 bytes) (Microsoft Corporation) (3a61a08f543bde5b16d1c5dfcc04cc5b)
C:\WINDOWS\system32\cliconfg.exe (20480 bytes) (Microsoft Corporation) (0b2db679a23e6c3521e47ff808eeda92)
C:\WINDOWS\system32\tzchange.exe (46080 bytes) (Microsoft Corporation) (2273a67d52af485e87fd6aac2e8d6807)
C:\WINDOWS\system32\uwdf.exe (47104 bytes) (Microsoft Corporation) (31776e2f4809b2369ed901a45cda5b8a)
C:\WINDOWS\system32\wdfmgr.exe (38912 bytes) (Microsoft Corporation) (ab0a7ca90d9e3d6a193905dc1715ded0)
C:\WINDOWS\system32\NVUNINST.EXE (208896 bytes) (NVIDIA Corporation) (6cf47aca6a081d2bd3c4490f41533248)
C:\WINDOWS\system32\nvsvc32.exe (155715 bytes) (NVIDIA Corporation) (986d6666e076afd2b60acafd5b01a00f)
C:\WINDOWS\system32\nvudisp.exe (208896 bytes) (NVIDIA Corporation) (6cf47aca6a081d2bd3c4490f41533248)
C:\WINDOWS\system32\Hdaudpropshortcut.exe (61952 bytes) (Windows (R) Server 2003 DDK provider) (bdb806c747c5257b9919e1a64b2db67b)
C:\WINDOWS\system32\WISPTIS.EXE (189952 bytes) (Microsoft Corporation) (99783fa6bfeb23a5f97b4a8db36c8a39)
C:\WINDOWS\system32\msfeedssync.exe (13312 bytes) (Microsoft Corporation) (fee2ba1ad38f457f418e82ea30724053)
C:\WINDOWS\system32\MRT.exe (31971272 bytes) (Microsoft Corporation) (5b2ad4b9219f5f7bd3229f4c5a7cf013)
C:\WINDOWS\system32\clspack.exe (49424 bytes) (Microsoft Corporation) (1c702f5c05b8282895a4d191cadabc14)
C:\WINDOWS\system32\jdbgmgr.exe (15120 bytes) (Microsoft Corporation) (a091ee93b655989161335d033350b048)
C:\WINDOWS\system32\jview.exe (172304 bytes) (Microsoft Corporation) (9e8b8cab625584ec29320c644d5a959f)
C:\WINDOWS\system32\wjview.exe (171792 bytes) (Microsoft Corporation) (f4cdc83fcef266f203812c324b0441b6)
C:\WINDOWS\system32\kknative.exe (15776 bytes) (Beijing Rising Information Technology Co., Ltd.) (9a1fd816774015c88487cad5347c8601)
C:\WINDOWS\system32\bsmain.exe (237680 bytes) (Beijing Rising Information Technology Co., Ltd.) (7556055c51585b20814bd612b4fd04e3)
C:\WINDOWS\system32\icardagt.exe (622080 bytes) (Microsoft Corporation) (f7889fc13a627f8cfa92420a211b9d33)
C:\WINDOWS\system32\verclsid.exe (28672 bytes) (Microsoft Corporation) (32a71f37940de5997fbb8f7bf76bd246)
C:\WINDOWS\system32\TsWpfWrp.exe (26112 bytes) (Microsoft Corporation) (b534ac76bf7623f48a7200aa0bddae7d)
C:\WINDOWS\system32\WinFXDocObj.exe (208384 bytes) (Microsoft Corporation) (cb61f20255c666e59f076247203d8496)
C:\WINDOWS\system32\PresentationHost.exe (326160 bytes) (Microsoft Corporation) (d256d79648c57ad83fa203555c8acf05)
[+] Files created 30 days ago
C:\WINDOWS\system32\drivers\rsassist.sys (12056 bytes) (Beijing Rising Information Technology Co., Ltd.) (2010-4-9 下午 04:10:16) (----) (05dd1cd69a464f0c406d37f61aecb88c)
C:\WINDOWS\system32\drivers\RsNTGdi.sys (11320 bytes) (Beijing Rising Information Technology Co., Ltd.) (2010-4-26 下午 02:58:00) (----) (3b9cd45cb4f79635d4249bed6e111e34)
C:\WINDOWS\system32\drivers\HookHelp.sys (37912 bytes) (Beijing Rising Information Technology Co., Ltd.) (2010-4-9 下午 04:10:16) (----) (52217bc74e68476f9973d5b835c19c30)
C:\WINDOWS\system32\drivers\HookSys.sys (168472 bytes) (Beijing Rising Information Technology Co., Ltd.) (2010-4-9 下午 04:10:16) (----) (5637b354f4bc3cac78aff51e0378c1f7)
C:\WINDOWS\system32\drivers\HookCont.sys (15512 bytes) (Beijing Rising Information Technology Co., Ltd.) (2010-4-9 下午 04:10:18) (----) (fc3d73394f83eaa6bcd66559397bcc19)
C:\WINDOWS\system32\drivers\rfwbase.sys (19184 bytes) (Beijing Rising Information Technology Co., Ltd.) (2010-4-9 下午 05:32:32) (--A-) (0fec959ecbe25bea9fc83ffd5b9bb5f3)
C:\WINDOWS\system32\drivers\rfwarp.sys (27632 bytes) (Beijing Rising Information Technology Co., Ltd.) (2010-4-9 下午 05:32:32) (--A-) (275074f14f462a54c644005d9f41e8d5)
C:\WINDOWS\system32\drivers\BC.sys (24984 bytes) (Kingsoft Corporation) (2010-4-19 下午 10:51:18) (--A-) (8964a8f677a76a68609c67320dda6bc9)
C:\Program Files\Common Files\Real\Codecs\atrc.dll (122880 bytes) (Unknown) (2010-5-1 上午 03:07:24) (--A-) (e55574dca2b3434338185ce75616da7e)
C:\Program Files\Common Files\Real\Codecs\cook.dll (106496 bytes) (Unknown) (2010-5-1 上午 03:07:24) (--A-) (9244704334e6ca449953d646b67d6b75)
C:\Program Files\Common Files\Real\Codecs\raac.dll (589824 bytes) (Unknown) (2010-5-1 上午 03:07:24) (--A-) (0882b83b4012c59f3c6da9ade4834e6a)
C:\Program Files\Common Files\Real\Codecs\sipr.dll (167936 bytes) (Unknown) (2010-5-1 上午 03:07:24) (--A-) (413acd92b9c8e972c088e8ba5366ae36)
C:\Program Files\Common Files\Real\Codecs\drv1.dll (106496 bytes) (RealNetworks, Inc.) (2010-5-1 上午 03:07:26) (--A-) (97b508444be9fd71048e0c46be188938)
C:\Program Files\Common Files\Real\Codecs\drv2.dll (180224 bytes) (Unknown) (2010-5-1 上午 03:07:26) (--A-) (95fb40daaf727f6375532cb59093b16b)
C:\Program Files\Common Files\Real\Codecs\drvc.dll (286720 bytes) (Unknown) (2010-5-1 上午 03:07:26) (--A-) (972fca42ed1c70a42d4b97b2ea9288ab)
C:\Program Files\Common Files\Real\Codecs\rv10.dll (86016 bytes) (RealNetworks, Inc.) (2010-5-1 上午 03:07:26) (--A-) (6202f3631bd610757bc8dd04b0484a62)
C:\Program Files\Common Files\Real\Codecs\rv20.dll (86016 bytes) (Unknown) (2010-5-1 上午 03:07:26) (--A-) (1661fffb928b550a9dc758444cc70964)
C:\Program Files\Common Files\Real\Codecs\rv30.dll (86016 bytes) (Unknown) (2010-5-1 上午 03:07:26) (--A-) (d5ec079b8e3464bb4a8cc531406bb5c1)
C:\Program Files\Common Files\Real\Codecs\rv40.dll (86016 bytes) (Unknown) (2010-5-1 上午 03:07:26) (--A-) (7d454263e8fbbcf74de82e99f897c244)
C:\Program Files\Common Files\Real\Codecs\evrc.dll (86016 bytes) (Unknown) (2010-5-1 上午 03:07:28) (--A-) (e8a5d2a13e5ca2a480448a685dbc373e)
C:\Program Files\Common Files\Real\Codecs\ralf.dll (155648 bytes) (Unknown) (2010-5-1 上午 03:07:28) (--A-) (4346cea6f5702f5b01b6f6326a99e86a)
C:\Program Files\Common Files\Real\Codecs\mp4v.dll (86016 bytes) (Unknown) (2010-5-1 上午 03:07:36) (--A-) (21fe931533c8d886c427c5418f01a682)
C:\Program Files\Common Files\Real\Codecs\dmp4.dll (212992 bytes) (Unknown) (2010-5-1 上午 03:07:36) (--A-) (a1faaf727683d4e07c4a36318e7b370a)
C:\Program Files\Common Files\Real\Codecs\avcq.dll (45056 bytes) (Unknown) (2010-5-1 上午 03:07:36) (--A-) (5f0e07c8a51ea99a2f80bca3101ab175)
C:\Program Files\Common Files\Real\Codecs\amrn.dll (204800 bytes) (Unknown) (2010-5-1 上午 03:07:36) (--A-) (12681120804ef3d67ea8a7812d5c609f)
C:\Program Files\Common Files\Real\Codecs\amrw.dll (110592 bytes) (Unknown) (2010-5-1 上午 03:07:36) (--A-) (3a50ee4bcea50edf4bad85e27214d0f9)
C:\Program Files\Common Files\Real\Codecs\qclp.dll (118784 bytes) (Unknown) (2010-5-1 上午 03:07:36) (--A-) (2c7b1e488ed674b3695eaeea80a7e1be)
C:\Program Files\Common Files\Real\Codecs\colorcvt.dll (548919 bytes) (Unknown) (2010-5-1 上午 03:08:12) (--A-) (dd19636e2650eaff14c54ea2d4de1789)
C:\Program Files\Common Files\Real\Plugins\authmgr.dll (45056 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (1cf55ba8575094f72347bc861f36a231)
C:\Program Files\Common Files\Real\Plugins\cdda3260.dll (17408 bytes) (RealNetworks, Inc.) (2010-5-1 上午 03:04:46) (--A-) (61187bfa13a999b3a1a70bace0125f2a)
C:\Program Files\Common Files\Real\Plugins\clbascauth.dll (25088 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (90ac0a6f1514c87027f7aa03ab1404a7)
C:\Program Files\Common Files\Real\Plugins\httpfsys.dll (204800 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (3a1efaa6209d6fc742d8fde651685eae)
C:\Program Files\Common Files\Real\Plugins\hxsdp.dll (49152 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (a5c084f4dd3437605f83279f0ca4a130)
C:\Program Files\Common Files\Real\Plugins\memfsys.dll (86016 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (2c7697c68d67bd576175506bd921820d)
C:\Program Files\Common Files\Real\Plugins\ntlmauth.dll (29184 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (787bc31510365556300bfc47b880d9ea)
C:\Program Files\Common Files\Real\Plugins\pacplin.dll (364544 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (dc546e249d4b21cdc1af041011f1e488)
C:\Program Files\Common Files\Real\Plugins\plusplin.dll (73728 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (53d1f560688dadc577d0791e6b3d9613)
C:\Program Files\Common Files\Real\Plugins\pxcb3210.dll (24064 bytes) (RealNetworks, Inc.) (2010-5-1 上午 03:04:46) (--A-) (1295175517ebba8154430f176a8c7a85)
C:\Program Files\Common Files\Real\Plugins\ramfformat.dll (32256 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (77ac64b9bc84879ff7fc600693829208)
C:\Program Files\Common Files\Real\Plugins\ramrender.dll (77824 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (4625f20eb846c55ced2bd0c99d7ff23f)
C:\Program Files\Common Files\Real\Plugins\rmfformat.dll (184320 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (56b5c86242188c196bcaa2166a005087)
C:\Program Files\Common Files\Real\Plugins\rn5auth.dll (53248 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (97db57121dab0cb077470132422fccf1)
C:\Program Files\Common Files\Real\Plugins\smlfformat.dll (61440 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (ee003fe0eaca9def495cc9ede15e1963)
C:\Program Files\Common Files\Real\Plugins\smlrender.dll (520192 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (7c36c3243272a7c233932f31eff4850f)
C:\Program Files\Common Files\Real\Plugins\smmrender.dll (61440 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (757939875f2803f2d6fd07960e0b6616)
C:\Program Files\Common Files\Real\Plugins\vidsite.dll (380928 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (f34334e4ad03a9729b428c95d811fe00)
C:\Program Files\Common Files\Real\Plugins\smplfsys.dll (86016 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (796b0623bf94db5b0f41d7770af3739e)
C:\Program Files\Common Files\Real\Plugins\zipf3260.dll (167936 bytes) (RealNetworks, Inc.) (2010-5-1 上午 03:04:46) (--A-) (0b913156eea6f6a47049971064218326)
C:\Program Files\Common Files\Real\Plugins\clntxres.dll (44032 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (535d3ad0633630fedfbe0bde7b971f26)
C:\Program Files\Common Files\Real\Plugins\vsrcplin.dll (131072 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (8c56d768e32120399c2c7a835f7e47ef)
C:\Program Files\Common Files\Real\Plugins\vsrlocal.dll (122880 bytes) (Unknown) (2010-5-1 上午 03:04:46) (--A-) (c829899759440a3c74bd71f585b36efe)
C:\Program Files\Common Files\Real\Plugins\rarender.dll (159744 bytes) (Unknown) (2010-5-1 上午 03:07:24) (--A-) (6ca29e844f3021d4aaffb8cdab2e5e9d)
C:\Program Files\Common Files\Real\Plugins\rvrender.dll (159744 bytes) (Unknown) (2010-5-1 上午 03:07:26) (--A-) (282aeda0ce0161e6bb5b692bc44955d6)
C:\Program Files\Common Files\Real\Plugins\imaprender.dll (53248 bytes) (Unknown) (2010-5-1 上午 03:07:26) (--A-) (cf1631fbaaf3c9796c5476a6edc8b645)
C:\Program Files\Common Files\Real\Plugins\swfformat.dll (114688 bytes) (Unknown) (2010-5-1 上午 03:07:26) (--A-) (6b64e75998e7bc01521b9ffe872c0b2a)
C:\Program Files\Common Files\Real\Plugins\swfrender.dll (630784 bytes) (Unknown) (2010-5-1 上午 03:07:26) (--A-) (a8b0d0ff668f848955d0d6af3ec8bb52)
C:\Program Files\Common Files\Real\Plugins\rtfformat.dll (114688 bytes) (Unknown) (2010-5-1 上午 03:07:28) (--A-) (fdd7d620845cc478494dbfbcbbb4db0e)