谢天使之剑,报告如下:
——————————————
L2MFIX find log 1.04a
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Shell Extensions]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINNT\\system32\\h62olgf3162.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
**********************************************************************************
useragent:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{AAECDE91-21A9-1DAA-AEDC-7FD436232186}"=""
**********************************************************************************
Shell Extension key:
**********************************************************************************
HKEY ROOT CLASSIDS:
**********************************************************************************
Files Found are not all bad files:
Invalid keyboard code specified
C:\WINNT\SYSTEM32\
wghext.dll Wed 2005-10-26 16:36:22 ..S.R 234,272 228.78 K
nvtman.dll Mon 2005-10-31 15:57:18 ..S.R 234,033 228.55 K
tvpi32.dll Mon 2005-10-31 12:18:28 ..S.R 237,008 231.45 K
glgiftga.dll Tue 2005-08-23 17:15:14 A.... 32,768 32.00 K
gljpg.dll Tue 2005-08-23 17:15:14 A.... 94,208 92.00 K
glpng.dll Tue 2005-08-23 17:15:14 A.... 94,208 92.00 K
czrsrv.dll Wed 2005-10-26 14:56:04 ..S.R 234,272 228.78 K
dhcompos.dll Thu 2005-10-27 9:02:30 ..S.R 235,569 230.05 K
drsrslvr.dll Wed 2005-11-02 9:01:24 ..... 235,585 230.06 K
enn8l1~1.dll Wed 2005-10-26 16:20:44 ..S.R 234,458 228.96 K
wvspdmod.dll Wed 2005-10-26 16:44:02 ..S.R 234,272 228.78 K
oaethk32.dll Mon 2005-10-31 11:02:14 ..S.R 235,283 229.77 K
wvpasf.dll Mon 2005-10-31 14:28:42 ..S.R 234,033 228.55 K
atmtd.dll Tue 2005-10-25 9:40:56 A.... 687,592 671.48 K
nydskcc.dll Wed 2005-10-26 16:00:06 ..S.R 234,458 228.96 K
lv4s09~1.dll Tue 2005-11-01 14:02:50 ..S.R 234,259 228.77 K
glzip.dll Tue 2005-08-23 17:15:12 A.... 69,632 68.00 K
glcards.dll Tue 2005-08-23 17:15:12 A.... 807,424 788.50 K
glmpdll.dll Tue 2005-08-23 17:15:12 A.... 94,208 92.00 K
glsocks.dll Tue 2005-08-23 17:15:12 A.... 10,240 10.00 K
glmpeg.dll Tue 2005-08-23 17:15:14 A.... 57,344 56.00 K
gliedo~1.dll Tue 2005-08-23 17:15:14 A.... 106,496 104.00 K
glcomp~1.dll Tue 2005-08-23 17:15:12 A.... 57,344 56.00 K
ywriin~1.dll Wed 2005-10-26 16:18:44 ..S.R 234,458 228.96 K
kt66l7~1.dll Fri 2005-10-28 16:33:32 ..S.R 235,483 229.96 K
epfpix~1.dll Mon 2005-10-31 12:38:34 ..S.R 234,033 228.55 K
h62olg~1.dll Tue 2005-11-01 11:03:48 ..S.R 235,585 230.06 K
27 items found: 27 files (15 H/S), 0 directories.
Total of file sizes: 5,868,525 bytes 5.59 M
Locate .tmp files:
C:\WINNT\SYSTEM32\
guard.tmp Wed 2005-11-02 9:03:24 ..S.R 235,585 230.06 K
1 item found: 1 file (1 H/S), 0 directories.
Total of file sizes: 235,585 bytes 230.06 K
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is 0D25-160A
Directory of C:\WINNT\System32
2005-11-02 09:03 235,585 guard.tmp
2005-11-01 14:02 234,259 lv4s09h7e.dll
2005-11-01 11:03 235,585 h62olgf3162.dll
2005-10-31 15:57 234,033 nvtman.dll
2005-10-31 14:41 165,624 lmllm.ini
2005-10-31 14:28 234,033 wvpasf.dll
2005-10-31 12:38 234,033 epfpixpsets.dll
2005-10-31 12:18 237,008 TVPI32.DLL
2005-10-31 11:02 162,974 lmllm.bak2
2005-10-31 11:02 235,283 oaethk32.dll
2005-10-28 16:33 235,483 kt66l7js1.dll
2005-10-28 11:56 162,351 lmllm.bak1
2005-10-27 09:02 235,569 dhcompos.dll
2005-10-26 16:44 234,272 wvspdmod.dll
2005-10-26 16:36 234,272 wghext.dll
2005-10-26 16:20 234,458 enn8l15u1.dll
2005-10-26 16:18 234,458 ywriinsert.dll
2005-10-26 16:00 234,458 nydskcc.dll
2005-10-26 14:56 234,272 CZRSRV.DLL
2004-04-13 15:17 <DIR> dllcache
19 File(s) 4,248,010 bytes
1 Dir(s) 6,210,830,336 bytes free
————————————————