[ Changes to registry ]
* Modifies value "NukeOnDelete=00000001" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\BitBucket
old value empty
* Modifies value "Common Desktop=C:\Documents and Settings\All Users\Lhb?" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Shell Folders
old value "Common Desktop=C:\Documents and Settings\All Users\桌面"
* Creates value "Kris=C:\7h,g106\upx\1\dumped_1.exe" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run
* Creates Registry key HKEY_LOCAL_MACHINE\system\CurrentControlSet\Control\MediaResources\msvideo
* Creates value "SymbolicLinkValue=5C00520045004700490053005400520059005C0055005300450052005C00530061006E00640062006F0078005F00410064006D0069006E006900730074007200610074006F0072005F00440065006600610075006C00740042006F0078005C0075007300650072005C00630075007200720065006E0074005F0063006C0061007300730065007300" in key HKEY_CURRENT_USER\software\classes
* Modifies value "Desktop=C:\Documents and Settings\Administrator\Lhb?" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
old value "Desktop=C:\Documents and Settings\Administrator\桌面"
* Creates value "FolderType=Documents" in key HKEY_CURRENT_USER\software\Microsoft\Windows\ShellNoRoam\Bags\45\Shell
[ Network services ]
* Connects to "221.130.179.36" on port 1379.
[ Process/window information ]
* Creates an event named "SBIE_BOXED_ServiceInitComplete_RpcSs".
* Creates a mutex "ZonesCounterMutex".
* Creates a mutex "ZonesCacheCounterMutex".
* Creates a mutex "ZonesLockedCacheCounterMutex".
* Creates a mutex "aa0533.3322.org".
* Creates process "(null),c:\Windows\svchest000.exe,(null)".
呵呵,看到了吧,这里记录了样本对文件系统,注册表,网络及系统环境的影响。清楚直观,一目了然,想不说是个木马都不容易。