以下是第二次植入木马后的SRENG日志及释放/下载的木马文件:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<upxdhnd><C:\DOCUME~1\baohelin\LOCALS~1\Temp\upxdhnd.exe> [N/A]
<kernel32><C:\windows\Kernel32.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{4DEC9B29-F08F-4cbc-B179-592B9283FAB0}><c:\program files\internet download manager\pqiwgkiw.dll> [N/A]
<{E464D6D7-935B-4203-9E74-8A6C60906B37}><c:\program files\internet download manager\wcxpjetr.dll> [N/A]
<{C883F785-102E-2427-7ADD-5B002D13D077}><C:\windows\system32\gj.dll> [N/A]
正在运行的进程
[PID: 584][\??\C:\windows\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\program files\internet download manager\pqiwgkiw.dll] [N/A, N/A]
[c:\program files\internet download manager\wcxpjetr.dll] [N/A, N/A]
[PID: 1608][C:\windows\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\upxdhnd.dll] [N/A, N/A]
[c:\program files\internet download manager\pqiwgkiw.dll] [N/A, N/A]
[c:\program files\internet download manager\wcxpjetr.dll] [N/A, N/A]
[C:\windows\system32\gj.dll] [N/A, N/A]
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\~TmD.tmp.rom] [N/A, N/A]
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\~TmE.tmp..rom] [N/A, N/A]
[PID: 2008][C:\windows\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\~TmD.tmp.rom] [N/A, N/A]
[PID: 2020][C:\Program Files\Tiny Firewall Pro\amon.exe] [Computer Associates International, Inc., 6.5.3.2]
[C:\windows\system32\gj.dll] [N/A, N/A]
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\~TmD.tmp.rom] [N/A, N/A]
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\~TmE.tmp..rom] [N/A, N/A]
[PID: 1156][C:\Program Files\Internet Download Manager\IDMan.exe] [Internet Download Manager Corp., Tonec Inc. , 5, 0, 2, 5]
[C:\windows\system32\gj.dll] [N/A, N/A]
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\~TmD.tmp.rom] [N/A, N/A]
[PID: 2640][C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe] [TechSmith Corporation, 7.1.2.0]
[C:\windows\system32\gj.dll] [N/A, N/A]
[PID: 384][C:\windows\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system32\gj.dll] [N/A, N/A]
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\~TmD.tmp.rom] [N/A, N/A]
[PID: 3216][C:\windows\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\windows\system32\gj.dll] [N/A, N/A]
[PID: 4036][C:\Program Files\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605]
[C:\windows\system32\gj.dll] [N/A, N/A]
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\~TmD.tmp.rom] [N/A, N/A]
[C:\DOCUME~1\baohelin\LOCALS~1\Temp\~TmE.tmp..rom] [N/A, N/A]