本帖最后由 liulangzhecgr 于 2010.9.17 04:36 编辑
2010-09-17 00:40:20 创建文件 操作:使用任务隔离区操作
进程路径:F:\virus\virus\virus.exe
文件 ...
hddu 发表于 2010.9.17 00:39 
这是啥病毒?!
wscript.exe调用两个c:\windows\system\svchost.exe
此两个文件都过数字签名却后者是隐藏的!
Installation Report: virus
Generated by InCtrl5, version 1.0.0.0
Install program: E:\downloads\virus\virus.exe
9-16-2010 2:40 PM
------------------------------------------------------------
Registry
********
Keys ignored: 0
---------------
* (none)
Keys added: 4
-------------
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings
HKEY_CLASSES_ROOT\.mke
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_8086&DEV_2445&SUBSYS_4730414C&REV_05#3&13C0B0C5&0&FD#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\n
Keys deleted: 4
---------------
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_8086&DEV_2445&SUBSYS_4730414C&REV_05#3&13C0B0C5&0&FD#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\F
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Lsa\SspiCache\o
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Lsa\SspiCache\o
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Lsa\SspiCache\o
Values added: 3
---------------
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache "E:\downloads\virus\virus.exe"
Type: REG_SZ
Data: virus
HKEY_CLASSES_ROOT\.mke "(Default)"
Type: REG_SZ
Data: JSEFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings "Enabled"
Type: REG_DWORD
Data: 01, 00, 00, 00
Values changed: 5
-----------------
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden"
Old type: REG_DWORD
New type: REG_DWORD
Old data: 01, 00, 00, 00
New data: 02, 00, 00, 00
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden"
Old type: REG_DWORD
New type: REG_DWORD
Old data: 01, 00, 00, 00
New data: 00, 00, 00, 00
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "SuperHidden"
Old type: REG_DWORD
New type: REG_DWORD
Old data: 01, 00, 00, 00
New data: 00, 00, 00, 00
HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft\Kingsoft AntiVirus Technology Preview "FileCount"
Old type: REG_DWORD
New type: REG_DWORD
Old data: 69, 1B, 00, 00
New data: F6, 1B, 00, 00
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG "Seed"
Old type: REG_BINARY
New type: REG_BINARY
Old data: A3, 92, A7, FF, 79, B4, 01, 34, 11, 48, DA, BE, 24, 1F, AC, F7, 40, EF, 25, 20, C8, 91, BF, CD, AD, 23, 09, 18, E3, 3F, 52, F1, C7, 13, F6, FA, 8F, 01, 3A, E2, 8C, DD, 4F, 5A, 2F, BD, B2, B3, F5, 37, 5A, 28, 5D, 43, E2, 64, 2C, 20, 3A, F0, 40, 49, 30, F5, BE, 0C, C0, 61, B5, 95, 41, D3, 7D, C1, EB, 9F, 54, 4D, 3D, 0F
New data: D0, F9, 16, EF, 0F, D5, F1, 1C, F0, 8D, 47, B2, DF, 84, DD, EF, 63, F1, 1E, BD, 8A, C4, C5, 97, 74, CE, C7, 2C, 05, D0, 76, 39, 87, 9B, 84, 77, 61, 4F, B8, 06, 92, D2, E9, 6A, 24, C4, 01, B2, 30, 56, BF, 57, 31, 42, 48, 92, 58, 6E, F3, 1A, D5, CA, 6E, EE, F1, 09, E3, 45, 7D, F0, 9A, B9, CA, 57, 08, 37, 50, 10, F0, CB
------------------------------------------------------------
Disk contents
*************
Drives tracked: 3
-----------------
* c:\
* d:\
* e:\
Folders added: 1
----------------
c:\Program Files\Messenger
Files added: 7
--------------
c:\tmp.tmp
Date: 9-16-2010 2:40 PM
Size: 0 bytes
c:\Program Files\Messenger\Messenger.mke
Date: 9-14-2010 8:11 PM
Size: 10,796 bytes
c:\WINDOWS\Prefetch\SVCHOST.EXE-0445652B.pf
Date: 9-16-2010 2:40 PM
Size: 32,986 bytes
c:\WINDOWS\Prefetch\VIRUS.EXE-0223345C.pf
Date: 9-16-2010 2:39 PM
Size: 20,224 bytes
c:\WINDOWS\Prefetch\WSCRIPT.EXE-32960AB9.pf
Date: 9-16-2010 2:39 PM
Size: 32,212 bytes
c:\WINDOWS\system\SVCHOST.EXE
Date: 12-15-2005 8:00 AM
Size: 114,688 bytes
c:\WINDOWS\system32\taoY.ico
Date: 6-8-2005 6:10 PM
Size: 12,862 bytes
Files deleted: 3
----------------
c:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\搜狗高速浏览器.lnk
Date: 9-15-2010 8:20 PM
Size: 760 bytes
c:\Documents and Settings\All Users\「开始」菜单\搜狗高速浏览器.lnk
Date: 9-15-2010 8:20 PM
Size: 742 bytes
c:\Documents and Settings\All Users\桌面\搜狗高速浏览器.lnk
Date: 9-15-2010 8:20 PM
Size: 742 bytes
Files changed: 14
-----------------
c:\Documents and Settings\Administrator\ntuser.dat.LOG
Old date: 9-16-2010 2:38 PM
New date: 9-16-2010 2:40 PM
Old size: 1,024 bytes
New size: 1,024 bytes
c:\Program Files\Kingsoft\Kingsoft AntiVirus Technology Preview\kse_wfsdata\tmpa0.dat
Old date: 9-16-2010 2:38 PM
New date: 9-16-2010 2:40 PM
Old size: 0 bytes
New size: 0 bytes
c:\Program Files\Kingsoft\webshield\kse\kse_wfsdata\KSWebShield_tmpa0.dat
Old date: 9-16-2010 2:38 PM
New date: 9-16-2010 2:40 PM
Old size: 0 bytes
New size: 0 bytes
c:\Program Files\Kingsoft\webshield\webui\icon\btbg.gif
Old date: 9-16-2010 2:38 PM
New date: 9-16-2010 2:40 PM
Old size: 1,050 bytes
New size: 1,050 bytes
c:\WINDOWS\explorer.exe
Old date: 12-15-2005 8:00 AM
New date: 9-16-2010 2:39 PM
Old size: 976,896 bytes
New size: 976,896 bytes
c:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf
Old date: 9-16-2010 2:05 PM
New date: 9-16-2010 2:39 PM
Old size: 29,308 bytes
New size: 28,276 bytes
c:\WINDOWS\system32\smss.exe
Old date: 12-15-2005 8:00 AM
New date: 9-16-2010 2:39 PM
Old size: 50,688 bytes
New size: 50,688 bytes
c:\WINDOWS\system32\CatRoot2\edb.chk
Old date: 9-16-2010 1:31 PM
New date: 9-16-2010 2:39 PM
Old size: 8,192 bytes
New size: 8,192 bytes
c:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
Old date: 9-16-2010 1:31 PM
New date: 9-16-2010 2:39 PM
Old size: 3,153,920 bytes
New size: 3,153,920 bytes
c:\WINDOWS\system32\config\default.LOG
Old date: 9-16-2010 12:56 PM
New date: 9-16-2010 2:40 PM
Old size: 1,024 bytes
New size: 1,024 bytes
c:\WINDOWS\system32\config\software
Old date: 9-16-2010 12:41 PM
New date: 9-16-2010 2:39 PM
Old size: 9,961,472 bytes
New size: 9,961,472 bytes
c:\WINDOWS\system32\config\software.LOG
Old date: 9-16-2010 2:37 PM
New date: 9-16-2010 2:40 PM
Old size: 1,024 bytes
New size: 20,480 bytes
c:\WINDOWS\system32\dllcache\explorer.exe
Old date: 12-15-2005 8:00 AM
New date: 9-16-2010 2:39 PM
Old size: 976,896 bytes
New size: 976,896 bytes
c:\WINDOWS\system32\dllcache\smss.exe
Old date: 12-15-2005 8:00 AM
New date: 9-16-2010 2:39 PM
Old size: 50,688 bytes
New size: 50,688 bytes
------------------------------------------------------------
INI file
********
Ini files tracked: 4
--------------------
* C:\boot.ini
* c:\windows\control.ini
* c:\windows\system.ini
* c:\windows\win.ini
------------------------------------------------------------
Text file
*********
Text files tracked: 2
---------------------
* c:\windows\system32\autoexec.nt
* c:\windows\system32\config.nt
------------------------------------------------------------
InCtrl5, Copyright ?2000 by Ziff Davis Media, Inc.
Written by Neil J. Rubenking
First published in PC Magazine, December 5, 2000.
|