[spoil]Mẫu báo cáo tình trạng máy tính hiện tại.
Thực hiện bởi chương trình: Perfect Antivirus 2009.
Thời gian: 9:54:28 PM - 10/13/2010
- Thông tin máy tính:
+ Hệ điều hành: Microsoft Windows XP Professional 5.1.2600
+ Tên người sử dụng: ANHCHUANPC
+ Tên máy tính: ANHCHUAN
+ Dung lượng bộ nhớ RAM: 1917.105 MB
===============================================================================
[1] - Các chương trình đang chạy trong bộ nhớ:
C:\WINDOWS\System32\smss.exe : 668
C:\WINDOWS\system32\winlogon.exe : 756
C:\WINDOWS\system32\services.exe : 800
C:\WINDOWS\system32\lsass.exe : 812
C:\WINDOWS\system32\nvsvc32.exe : 980
C:\WINDOWS\system32\svchost.exe : 1016
C:\WINDOWS\System32\svchost.exe : 1208
C:\WINDOWS\system32\svchost.exe : 1252
C:\WINDOWS\system32\spoolsv.exe : 1724
C:\WINDOWS\Explorer.EXE : 328
C:\WINDOWS\RTHDCPL.EXE : 1412
C:\WINDOWS\system32\PnkBstrA.exe : 1600
C:\WINDOWS\system32\PnkBstrB.exe : 1640
C:\WINDOWS\system32\svchost.exe : 1788
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe : 1852
D:\ZikZakBoy\Soft\BKAV 2009\Bkav2006\Bkav2006.exe : 252
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe : 1864
D:\ZikZakBoy\Soft\Cyber phim\PowerDVD10\PDVD10Serv.exe : 1872
C:\Program Files\Cyberlink\Shared files\brs.exe : 1916
D:\ZikZakBoy\Game\Game offine\Zing Movie\Zing Chat\Plugin\Com.Tencent.ZingGet\bin\zingdownload.exe : 1696
D:\ZikZakBoy\Soft\Unikey\UniKey4.0\UniKey.exe : 3036
C:\WINDOWS\System32\svchost.exe : 3284
C:\WINDOWS\system32\ctfmon.exe : 1908
C:\Program Files\InternetDownloadManager\IDMan.exe : 4056
C:\Program Files\InternetDownloadManager\IEMonitor.exe : 3732
E:\ZikZakBoy\Game Offine\War of warcraf 3\War 3\Warcraft III\WarCraft III HP View Helper\WarCraft III HP View Helper.exe : 3580
C:\Program Files\Internet Explorer\iexplore.exe : 2032
C:\Program Files\Internet Explorer\iexplore.exe : 3116
D:\ZikZakBoy\Soft\Messenger\ymsgr_tray.exe : 2408
C:\Program Files\Internet Explorer\iexplore.exe : 3000
C:\Program Files\Internet Explorer\iexplore.exe : 2856
E:\ZikZakBoy\Soft\Kiem tram ay tinh\_PSR.exe : 1184
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[2] - Các chương trình được nạp lúc khởi động:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
[+] ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
[+] swg = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
[+] IDMan = C:\Program Files\InternetDownloadManager\IDMan.exe /onboot
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[+] RTHDCPL = RTHDCPL.EXE
[+] nwiz = C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
[+] NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[+] NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[+] BkavFw = D:\ZikZakBoy\Soft\BKAV 2009\Bkav2006\Bkav2006.exe TASKBAR
[+] Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[+] YSearchProtection = "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
[+] RemoteControl10 = "D:\ZikZakBoy\Soft\Cyber phim\PowerDVD10\PDVD10Serv.exe"
[+] BDRegion = C:\Program Files\Cyberlink\Shared files\brs.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
[+] desktop.ini
[C:\Documents and Settings\ANHCHUANPC\Start Menu\Programs\Startup]
[+] desktop.ini
[+] zingdownload.lnk
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[3] - Giá trị của các Key quan trọng trong khóa Winlogon:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[+] AutoRestartShell = 0001
[+] DefaultDomainName = ANHCHUAN
[+] DefaultUserName = Administrator
[+] LegalNoticeCaption =
[+] LegalNoticeText =
[+] PowerdownAfterShutdown = 0
[+] ReportBootOk = 1
[+] Shell = Explorer.exe
[+] ShutdownWithoutLogon = 0
[+] System =
[+] Userinit = Userinit.exe
[+] VmApplet = rundll32 shell32,Control_RunDLL "sysdm.cpl"
[+] SfcQuota = FFFFFFFF
[+] allocatecdroms = 0
[+] allocatedasd = 0
[+] allocatefloppies = 0
[+] cachedlogonscount = 10
[+] forceunlocklogon = 0000
[+] passwordexpirywarning = 000E
[+] scremoveoption = 0
[+] AllowMultipleTSSessions = 0001
[+] UIHost = logonui.exe
[+] LogonType = 0000
[+] Background = 0 0 0
[+] DebugServerCommand = no
[+] SFCDisable = 0000
[+] WinStationsDisabled = 0
[+] HibernationPreviouslyEnabled = 0001
[+] ShowLogonOptions = 0000
[+] AltDefaultUserName = ANHCHUANPC
[+] AltDefaultDomainName = ANHCHUAN
[+] ChangePasswordUseKerberos = 0001
[+] AutoAdminLogon = 1
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[4] - Nội dung tập tin Hosts:
-------------------------------------------------------------------
# Copyright (c) 1993-2009 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
# 127.0.0.1 localhost
# ::1 localhost
27.0.14.77 gunz.vn
27.0.14.77 gunzvn.2it.in
27.0.14.77 gunz.2it.in
27.0.14.77 forums.gunz.vn
27.0.14.77 gunz4r.2it.in
27.0.14.77 gamedl.2it.in
27.0.14.77 gamedl2.2it.in
27.0.14.77 mu.2it.in
27.0.14.77 murs.2it.in
27.0.14.77 aion.2it.in
27.0.14.77 gamerzplanet.net
27.0.14.77 gunz.rap.vn
27.0.14.77 gunz.ijji.com
27.0.14.77 darkgunz.com
27.0.14.77 euro-gunz.eu
27.0.14.77 eurogunz.net
27.0.14.77 gamerzneeds.net
27.0.14.77 forum.ragezone.com
27.0.14.77 ragezone.com
27.0.14.77 mocrogunz.net
27.0.14.77
www.gunz.vn
27.0.14.77
www.gunzvn.2it.in
27.0.14.77
www.gunz.2it.in
27.0.14.77
www.forums.gunz.vn
27.0.14.77
www.gunz4r.2it.in
27.0.14.77
www.gamedl.2it.in
27.0.14.77
www.gamedl2.2it.in
27.0.14.77
www.mu.2it.in
27.0.14.77
www.murs.2it.in
27.0.14.77
www.aion.2it.in
27.0.14.77
www.gamerzplanet.net
27.0.14.77
www.gunz.rap.vn
27.0.14.77
www.gunz.ijji.com
27.0.14.77
www.darkgunz.com
27.0.14.77
www.euro-gunz.eu
27.0.14.77
www.eurogunz.net
27.0.14.77
www.gamerzneeds.net
27.0.14.77
www.forum.ragezone.com
27.0.14.77
www.ragezone.com
27.0.14.77
http://www.mocrogunz.net------------...--------------
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[5] - Các thông số cài đặt của Internet Explorer:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[+] NoUpdateCheck = 0001
[+] NoJITSetup = 0001
[+] Disable Script Debugger = yes
[+] Show_ChannelBand = No
[+] Anchor Underline = yes
[+] Cache_Update_Frequency = Once_Per_Session
[+] Display Inline Images = yes
[+] Do404Search = 01 00 00 00
[+] Local Page = C:\WINDOWS\system32\blank.htm
[+] Save_Session_History_On_Exit = no
[+] Show_FullURL = no
[+] Show_StatusBar = yes
[+] Show_ToolBar = yes
[+] Show_URLinStatusBar = yes
[+] Show_URLToolBar = yes
[+] Start Page =
http://www.zing.vn/news/
[+] Use_DlgBox_Colors = yes
[+] Window_Placement = 2C 00 00 00 02 00 00 00 03 00 00 00 00 83 FF FF 00 83 FF FF FF FF FF FF FF FF FF FF 05 01 00 00 3A 00 00 00 19 04 00 00 46 02 00 00
[+] FullScreen = no
[+] NotifyDownloadComplete = no
[+] Use FormSuggest = yes
[+] Use Custom Search URL = 0001
[+] AutoSearch = 0004
[+] ShowedCheckBrowser = Yes
[+] Check_Associations = No
[+] AddToFavoritesExpanded = 0000
[+] Search Page =
http://www.microsoft.com/isapi/redir...ie&ar=iesearch
[+] Error Dlg Displayed On Every Error = no
[+] XMLHTTP = 0001
[+] UseClearType = yes
[+] Enable Browser Extensions = yes
[+] Play_Background_Sounds = yes
[+] Play_Animations = yes
[+] CompatibilityFlags = 0000
[+] IE8RunOnceLastShown = 0001
[+] IE8RunOnceLastShown_TIMESTAMP = D2 85 F2 87 CB 67 CB 01
[+] IE8RunOncePerInstallCompleted = 0001
[+] IE8RunOnceCompletionTime = 98 9E DE A8 CB 67 CB 01
[+] IE8TourShown = 0001
[+] IE8TourShownTime = 54 33 2F B3 A0 AB CA 01
[+] FormSuggest PW Ask = no
[+] Use Search Asst = no
[+] Search Bar =
http://www.crawler.com/search/dispat...=%s&tbid=66016
[+] StatusBarWeb = 0001
[+] AlwaysShowMenus = 0001
[+] Expand Alt Text = no
[+] Move System Caret = no
[+] NscSingleExpand = 0000
[+] DisableScriptDebuggerIE = yes
[+] Page_Transitions = 0001
[+] UseThemes = 0001
[+] EnableSearchPane = 0000
[+] Force Offscreen Composition = 0000
[+] AllowWindowReuse = 0001
[+] Friendly http errors = yes
[+] SmoothScroll = 0001
[+] Enable AutoImageResize = yes
[+] Show image placeholders = 0000
[+] Print_Background = no
[+] DOMStorage = 0001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
[+] Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
[+] Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
[+] Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
[+] Enable_Disk_Cache = yes
[+] Cache_Percent_of_Disk = 0A 00 00 00
[+] Delete_Temp_Files_On_Exit = yes
[+] Local Page = C:\WINDOWS\system32\blank.htm
[+] Anchor_Visitation_Horizon = 01 00 00 00
[+] Use_Async_DNS = yes
[+] Placeholder_Width = 1A 00 00 00
[+] Placeholder_Height = 1A 00 00 00
[+] Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
[+] CompanyName = Microsoft Corporation
[+] Custom_Key = MICROSO
[+] Wizard_Version = 6.0.2600.0000
[+] FullScreen = no
[+] Default_Secondary_Page_URL =
[+] Extensions Off Page = about:NoAdd-ons
[+] Security Risk Page = about:SecurityRisk
[+] Check_Associations = yes
[+] IEWatsonEnabled = 0000
[+] SearchAssistant =
http://www.crawler.com/search/ie.aspx?tb_id=66016
[+] CustomizeSearch =
http://dnl.crawler.com/support/sa_cu...spx?TbId=66016
[+] DEPOff = 0000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
[+] SearchAssistant =
http://www.crawler.com/search/ie.aspx?tb_id=66016
[+] CustomizeSearch =
http://dnl.crawler.com/support/sa_cu...spx?TbId=66016
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[6] - Khóa đăng ký của các tập tin thực thi:
[HKEY_CLASSES_ROOT\exefile\shell\open\command]
(Default) = "%1" %*
[HKEY_CLASSES_ROOT\comfile\shell\open\command]
(Default) = "%1" %*
[HKEY_CLASSES_ROOT\batfile\shell\open\command]
(Default) = "%1" %*
[HKEY_CLASSES_ROOT\piffile\shell\open\command]
(Default) = "%1" %*
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[7] - Tình trạng Khóa/Mở các chức năng của Windows
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
[+] NoDriveTypeAutoRun = 000DF
[+] NoDriveAutoRun = FC 0F 00 00
[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[8] - Các tập tin Autorun.inf trong ổ đĩa:
[C:\] - Không phát hiện Autorun.
ZIKZAKBOY [D:\] - Không phát hiện Autorun.
DATA [E:\] - Không phát hiện Autorun.
[K:\] - Phát hiện Autorun!
-------------------------------------
[AutoRun]
Open=SysAnti.exe
Shell\Open=´ò¿ª(&O)
Shell\Open\Command=SysAnti.exe
Shell\Open\Default=1
Shell\Explore=×ÊÔ´¹ÜÀíÆ÷(&X)
Shell\Explore\Command=SysAnti.exe
-------------------------------------
==============================================================================
Hoàn tất báo cáo.
--------------------------------------- End --------------------------------------
Copyright © Perfect Antivirus 2009[/spoil]
file log của máy 1 bệnh nhân bên bệnh viện pc truongton.
để ý thấy có bkav, khóa registry của userinit bị thay đổi, và virus autorun trong ổ K. Lần trước đã lập 1 topic ở ngoài nhưng ko thấy support trả lời thỏa đáng, chỉ đòi cái scan log, ko có rồi im cho chìm xuồng.
mấy con virus autorun lây qua usb rất thông dụng, ko thể diệt thì cũng phải phòng tránh được chứ, cái proactive defense của bkav đâu rồi ?