瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » IE被79300.com及tm286.com劫持有SREngLOG报告
AMYCHEN - 2006-12-12 12:11:00
[PID: 1356][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
    [C:\PROGRA~1\baidu\bar\baidubar.dll]  [Baidu.com, Inc., 2, 0, 2, 121]
    [C:\WINDOWS\downlo~1\Apyj.dll]  [Tencent, 4, 3, 8, 80]
    [C:\Program Files\Adobe\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.7.2006011200]
    [C:\WINDOWS\DOWNLO~1\vivimin.dll]  [北京新浪信息技术有限公司, 1, 0, 1, 1]
    [C:\WINDOWS\System32\ssup.dll]  [TENCENT, 4, 3, 8, 80]
    [C:\PROGRA~1\KuGoo2\KUGOO3~1.OCX]  [N/A, N/A]
    [C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\igfxpph.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxres.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxsrvc.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxdev.dll]  [Intel Corporation, 3,0,0,2104]
    [E:\Program Files\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [E:\Program Files\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 1588][E:\Program Files\Rav\RavStub.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 4]
    [E:\Program Files\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [E:\Program Files\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 1720][C:\WINDOWS\System32\igfxtray.exe]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxdev.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxsrvc.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxres.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxress.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
[PID: 1748][C:\WINDOWS\System32\hkcmd.exe]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\hccutils.DLL]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxdev.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxsrvc.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxhk.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\System32\igfxres.dll]  [Intel Corporation, 3,0,0,2104]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
[PID: 1756][C:\WINDOWS\SOUNDMAN.EXE]  [Realtek Semiconductor Corp., 5.1.0.22]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
[PID: 1816][C:\WINDOWS\System32\SCardSvr.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1976][C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe]  [InstallShield Software Corporation, 3, 10, 100, 1146]
[PID: 1988][C:\WINDOWS\System32\EPSMON.EXE]  [, 1, 0, 3, 1027]
    [C:\WINDOWS\System32\epserr.dll]  [, 1, 0, 2001, 1228]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
[PID: 2020][E:\Program Files\Rav\RavTask.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [E:\Program Files\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [E:\Program Files\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [E:\Program Files\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [E:\Program Files\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
[PID: 2040][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 152][E:\Program Files\Rav\Ravmon.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 36]
    [E:\Program Files\Rav\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
    [E:\Program Files\Rav\BWList.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
    [E:\Program Files\Rav\RSAPPMGR.DLL]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
    [E:\Program Files\Rav\CfgDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
    [E:\Program Files\Rav\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
    [E:\Program Files\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
    [E:\Program Files\Rav\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
    [E:\Program Files\Rav\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
[PID: 352][C:\Program Files\MSN Messenger\msnmsgr.exe]  [Microsoft Corporation, 7.5.0324]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
    [C:\WINDOWS\System32\ePSCSto1.dll]  [http://www.ftsafe.com, 3, 1, 3, 1027]
    [C:\WINDOWS\System32\ep1pk111.dll]  [http://www.ftsafe.com, 3, 0, 3, 1027]
    [C:\WINDOWS\System32\EP1kDL20.dll]  [, 3, 2, 3, 1027]
    [C:\WINDOWS\System32\msdmo.dll]  [N/A, N/A]
1
查看完整版本: IE被79300.com及tm286.com劫持有SREngLOG报告