瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » IE被79300.com及tm286.com劫持有SREngLOG报告
AMYCHEN - 2006-12-12 12:12:00
[PID: 488][C:\WINDOWS\System32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
[PID: 3924][E:\Program Files\Rav\RsAgent.exe]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
    [E:\Program Files\Rav\RsCommX.dll]  [rising, 18, 0, 0, 1]
[PID: 3940][C:\WINDOWS\msagent\AgentSvr.exe]  [Microsoft Corporation, 2.00.0.3422]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
[PID: 3920][C:\Program Files\Microsoft Office\Office\WINWORD.EXE]  [Microsoft Corporation, 9.0.2823]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
    [E:\Program Files\Rav\RsPlugIn.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CAP3UIK.DLL]  [Canon Inc., 1.00.0.007]
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CAP3K.DLL]  [Canon Inc., 0.3.0.0]
    [E:\Program Files 在 Win 上\wnwb2005\WNMKEY.DLL]  [深圳世强软件开发部 www.wnwb.com , 2005, 7, 5, 1]
    [C:\WINDOWS\System32\WNWBIO.IME]  [深圳世强软件开发部 www.wnwb.com , 2005, 1, 31, 1]
    [C:\WINDOWS\System32\icm32.dll]  [Microsoft Corporation, 5.00]
[PID: 2428][E:\Program Files 在 Win 上\wnwb2005\wnwb.exe]  [深圳世强软件开发部 www.wnwb.com , 2005, 11, 19, 1]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
    [E:\Program Files 在 Win 上\wnwb2005\WNMKEY.DLL]  [深圳世强软件开发部 www.wnwb.com , 2005, 7, 5, 1]
[PID: 2628][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
    [C:\WINDOWS\downlo~1\Apyj.dll]  [Tencent, 4, 3, 8, 80]
    [C:\PROGRA~1\baidu\bar\baidubar.dll]  [Baidu.com, Inc., 2, 0, 2, 121]
    [C:\Program Files\Adobe\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 7.0.7.2006011200]
    [C:\WINDOWS\DOWNLO~1\vivimin.dll]  [北京新浪信息技术有限公司, 1, 0, 1, 1]
    [C:\WINDOWS\System32\ssup.dll]  [TENCENT, 4, 3, 8, 80]
    [C:\PROGRA~1\KuGoo2\KUGOO3~1.OCX]  [N/A, N/A]
    [C:\PROGRA~1\COMMON~1\Wnwb\wnwbio.dll]  [深圳世强软件开发部, 2005, 8, 30, 1]
    [C:\PROGRA~1\INTERN~1\CONNEC~1\iccon.dll]  [Microsoft Corporation, 5.00.2195.6946]
    [E:\Program Files\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [E:\Program Files 在 Win 上\wnwb2005\WNMKEY.DLL]  [深圳世强软件开发部 www.wnwb.com , 2005, 7, 5, 1]
    [C:\WINDOWS\System32\WNWBIO.IME]  [深圳世强软件开发部 www.wnwb.com , 2005, 1, 31, 1]
[PID: 2764][C:\Program Files\Microsoft Office\Office\EXCEL.EXE]  [Microsoft Corporation, 9.0.2823]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
    [E:\Program Files\Rav\RsPlugIn.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 14]
[PID: 2072][E:\QQ\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [E:\QQ\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [E:\QQ\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [E:\QQ\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
    [E:\QQ\QQAPI.dll]  [, 1, 0, 0, 1]
    [E:\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [E:\QQ\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [E:\QQ\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [E:\QQ\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [E:\Program Files 在 Win 上\wnwb2005\WNMKEY.DLL]  [深圳世强软件开发部 www.wnwb.com , 2005, 7, 5, 1]
    [E:\QQ\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [E:\QQ\WizardCtrl.dll]  [, 1, 0, 0, 1]
    [E:\QQ\QQMainFrame.dll]  [N/A, N/A]
    [C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
    [E:\QQ\CQQApplication.dll]  [N/A, N/A]
    [E:\QQ\NewSkin.dll]  [, 1, 0, 0, 1]
    [E:\QQ\HostingMgr.dll]  [, 1, 0, 0, 1]
    [E:\QQ\CameraDll.dll]  [, 1, 0, 0, 1]
    [E:\QQ\MailSummary.dll]  [, 1, 0, 0, 1]
    [E:\QQ\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\System32\msdmo.dll]  [N/A, N/A]
    [E:\QQ\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [E:\QQ\GroupLive.dll]  [N/A, N/A]
    [E:\QQ\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [E:\QQ\QQPlugin.dll]  [N/A, N/A]
    [E:\QQ\ShareFiles.dll]  [N/A, N/A]
    [E:\QQ\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [E:\QQ\QQAllInOne.dll]  [N/A, N/A]
    [E:\QQ\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [E:\QQ\QQCustomFace.dll]  [N/A, N/A]
    [E:\QQ\QQPet.dll]  [, 1, 0, 0, 1]
    [E:\QQ\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [E:\QQ\QRingMng.dll]  [N/A, N/A]
    [E:\QQ\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [E:\QQ\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [E:\QQ\VPortal.dll]  [, 1, 0, 0, 4]
    [E:\QQ\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [E:\QQ\QQMagicFace.dll]  [, 1, 0, 0, 1]
    [E:\QQ\QQAvatar.dll]  [N/A, N/A]
    [E:\QQ\QQSceneMng.dll]  [N/A, N/A]
    [E:\QQ\QQSysMsgMng.dll]  [N/A, N/A]
    [E:\QQ\BQQApplication.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
    [E:\QQ\CommercesMng.dll]  [, 1, 0, 0, 1]
    [E:\QQ\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [E:\QQ\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
    [E:\QQ\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 1, 1, 11]
[PID: 468][E:\QQ\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
    [E:\QQ\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 3020][C:\Program Files\WinRAR\WinRAR.exe]  [N/A, N/A]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
[PID: 1280][C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX05.750\SREng\SREng.exe]  [Smallfrogs Studio, 2.2.6.605]
    [C:\WINDOWS\downlo~1\Txmhjc.dll]  [Tencent, 4, 3, 8, 80]
    [C:\WINDOWS\System32\ePSCSto1.dll]  [http://www.ftsafe.com, 3, 1, 3, 1027]
    [C:\WINDOWS\System32\ep1pk111.dll]  [http://www.ftsafe.com, 3, 0, 3, 1027]
    [C:\WINDOWS\System32\EP1kDL20.dll]  [, 3, 2, 3, 1027]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1      localhost

==================================
1
查看完整版本: IE被79300.com及tm286.com劫持有SREngLOG报告