O2 - BHO CFunPlayer Object - {66DF3805-4078-4095-BA13-09DBC92F3E87}
= C:\WINDOWS\system32\393r.dll | 2010-2-6 17:51:22
| IE Media Object
| 1.0.0.1
| IE Media Object
| Beijing Angels Technology ltd. All rights reserved.
| 1.0.0.1 | Beijing Angels Technology ltd.| ?
| BHO.dll
| b.dll
文件说明符 : C:\WINDOWS\system32\393r.dll
属性 : ----
数字签名:Beijing BoDong Wanjie Network Technology Co.Ltd
PE文件:是
语言 : 中文(中国)
文件版本 : 1.0.0.1
说明 : IE Media Object
版权 : Beijing Angels Technology ltd. All rights reserved.
产品版本 : 1.0.0.1
产品名称 : IE Media Object
公司名称 : Beijing Angels Technology ltd.
内部名称 : BHO.dll
源文件名 : b.dll
创建时间 : 2010-1-30 21:8:29
修改时间 : 2010-2-6 17:51:22
大小 : 156328 字节 152.680 KB
MD5 : cef404bb4d617cc5c7ee83ef7e54cf4c
SHA1: 4515A901689910D07F0A18E7B1D4A34D9455CA82
CRC32: 0618c254
| 反病毒引擎 | 版本 | 最后更新 | 扫描结果 |
| a-squared | 4.5.0.50 | 2010.03.24 | Trojan-Downloader.Win32.Adload!IK |
| AhnLab-V3 | 5.0.0.2 | 2010.03.24 | - |
| AntiVir | 8.2.1.196 | 2010.03.24 | TR/BHO.adld |
| Antiy-AVL | 2.0.3.7 | 2010.03.24 | AdWare/Win32.BHO.gen |
| Authentium | 5.2.0.5 | 2010.03.24 | - |
| Avast | 4.8.1351.0 | 2010.03.24 | Win32:Adload-LR |
| Avast5 | 5.0.332.0 | 2010.03.24 | Win32:Adload-LR |
| AVG | 9.0.0.787 | 2010.03.24 | - |
| BitDefender | 7.2 | 2010.03.24 | Application.Generic.285893 |
| CAT-QuickHeal | 10.00 | 2010.03.24 | Trojan.Agent.ATV |
| ClamAV | 0.96.0.0-git | 2010.03.24 | - |
| Comodo | 4368 | 2010.03.24 | ApplicUnwnt.Win32.Adware.DM.B |
| DrWeb | 5.0.1.12222 | 2010.03.24 | MULDROP.Trojan |
| eSafe | 7.0.17.0 | 2010.03.24 | Win32.TRBHO.Adld |
| eTrust-Vet | 35.2.7386 | 2010.03.24 | - |
| F-Prot | 4.5.1.85 | 2010.03.23 | - |
| F-Secure | 9.0.15370.0 | 2010.03.24 | Application.Generic.285893 |
| Fortinet | 4.0.14.0 | 2010.03.24 | Adware/BHO |
| GData | 19 | 2010.03.24 | Application.Generic.285893 |
| Ikarus | T3.1.1.80.0 | 2010.03.24 | Trojan-Downloader.Win32.Adload |
| Jiangmin | 13.0.900 | 2010.03.24 | - |
| K7AntiVirus | 7.10.1004 | 2010.03.22 | Trojan.Win32.Malware.4 |
| Kaspersky | 7.0.0.125 | 2010.03.24 | not-a-virus:AdWare.Win32.BHO.lct |
| McAfee | 5929 | 2010.03.23 | potentially unwanted program Adware-BHO |
| McAfee+Artemis | 5929 | 2010.03.23 | potentially unwanted program Adware-BHO |
| McAfee-GW-Edition | 6.8.5 | 2010.03.24 | Trojan.BHO.adld |
| Microsoft | 1.5605 | 2010.03.24 | TrojanDownloader:Win32/Adload.L |
| NOD32 | 4971 | 2010.03.24 | Win32/Adware.WSearch.AD |
| Norman | 6.04.10 | 2010.03.24 | - |
| nProtect | 2009.1.8.0 | 2010.03.24 | Trojan-Clicker/W32.BHO.156328 |
| Panda | 10.0.2.2 | 2010.03.23 | Suspicious file |
| PCTools | 7.0.3.5 | 2010.03.24 | Adware.Ruango |
| Prevx | 3.0 | 2010.03.24 | High Risk Spyware |
| Rising | 22.40.02.03 | 2010.03.24 | - |
| Sophos | 4.51.0 | 2010.03.24 | Mal/Generic-A |
| Sunbelt | 6031 | 2010.03.22 | Trojan.Win32.Generic!BT |
| Symantec | 20091.2.0.41 | 2010.03.24 | Adware.ADH |
| TheHacker | 6.5.2.0.242 | 2010.03.24 | - |
| TrendMicro | 9.120.0.1004 | 2010.03.24 | - |
| VBA32 | 3.12.12.2 | 2010.03.24 | - |
| ViRobot | 2010.3.24.2242 | 2010.03.24 | - |
| VirusBuster | 5.0.27.0 | 2010.03.24 | Trojan.BHO.ADSA |
O2 - BHO BHO Class - {AFA9FF66-862A-4b0c-8D6B-3FB026ECEB0A}
= C:\WINDOWS\system32\n9elo8.dll | 2010-2-14 16:50:54
| Flacdker Product
| 1, 0, 2, 8
| Transactin_Module
| Copyright 2006
| 1, 0, 2, 8
| RealNetworks Corporation
| | Browser Services
| Browser Services
文件说明符 : C:\WINDOWS\system32\n9elo8.dll
属性 : A---
数字签名:否
PE文件:是
语言 : 英语(美国)
文件版本 : 1, 0, 2, 8
说明 : Transactin_Module
版权 : Copyright 2006
备注 : RealNetworks Corporation
产品版本 : 1, 0, 2, 8
产品名称 : Flacdker Product
公司名称 : RealNetworks Corporation
内部名称 : Browser Services
源文件名 : Browser Services
创建时间 : 2010-2-14 16:50:52
修改时间 : 2010-2-14 16:50:54
大小 : 49152 字节 48.0 KB
MD5 : b0dbc62ab50f176d1740b17ae269ef8e
SHA1: EF84013329758D7FEB6DCA2024F22865BC89C31A
CRC32: 20b3a0d1
文件 n9elo8.dll 接收于 2010.03.24 13:40:59 (UTC)
| 反病毒引擎 | 版本 | 最后更新 | 扫描结果 |
| a-squared | 4.5.0.50 | 2010.03.24 | Riskware.AdWare.Win32.BHO!IK |
| AhnLab-V3 | 5.0.0.2 | 2010.03.24 | - |
| AntiVir | 8.2.1.196 | 2010.03.24 | ADSPY/Bho.lft |
| Antiy-AVL | 2.0.3.7 | 2010.03.24 | AdWare/Win32.BHO.gen |
| Authentium | 5.2.0.5 | 2010.03.24 | - |
| Avast | 4.8.1351.0 | 2010.03.24 | Win32:Malware-gen |
| Avast5 | 5.0.332.0 | 2010.03.24 | Win32:Malware-gen |
| AVG | 9.0.0.787 | 2010.03.24 | - |
| BitDefender | 7.2 | 2010.03.24 | - |
| CAT-QuickHeal | 10.00 | 2010.03.24 | - |
| ClamAV | 0.96.0.0-git | 2010.03.24 | - |
| Comodo | 4368 | 2010.03.24 | UnclassifiedMalware |
| DrWeb | 5.0.1.12222 | 2010.03.24 | - |
| eSafe | 7.0.17.0 | 2010.03.24 | - |
| eTrust-Vet | 35.2.7386 | 2010.03.24 | Win32/SillyBHO.HD |
| F-Prot | 4.5.1.85 | 2010.03.23 | - |
| F-Secure | 9.0.15370.0 | 2010.03.24 | - |
| Fortinet | 4.0.14.0 | 2010.03.24 | Adware/BHO |
| GData | 19 | 2010.03.24 | Win32:Malware-gen |
| Ikarus | T3.1.1.80.0 | 2010.03.24 | not-a-virus:AdWare.Win32.BHO |
| Jiangmin | 13.0.900 | 2010.03.24 | Adware/Boolans.gd |
| K7AntiVirus | 7.10.1004 | 2010.03.22 | - |
| Kaspersky | 7.0.0.125 | 2010.03.24 | not-a-virus:AdWare.Win32.BHO.lft |
| McAfee | 5929 | 2010.03.23 | Generic PWS!hv.ah |
| McAfee+Artemis | 5929 | 2010.03.23 | Artemis!B0DBC62AB50F |
| McAfee-GW-Edition | 6.8.5 | 2010.03.24 | Ad-Spyware.Bho.lft |
| Microsoft | 1.5605 | 2010.03.24 | - |
| NOD32 | 4971 | 2010.03.24 | - |
| Norman | 6.04.10 | 2010.03.24 | - |
| nProtect | 2009.1.8.0 | 2010.03.24 | - |
| Panda | 10.0.2.2 | 2010.03.23 | - |
| PCTools | 7.0.3.5 | 2010.03.24 | Adware.WSearch.O |
| Prevx | 3.0 | 2010.03.24 | Medium Risk Malware |
| Rising | 22.40.02.03 | 2010.03.24 | - |
| Sophos | 4.51.0 | 2010.03.24 | - |
| Sunbelt | 6031 | 2010.03.22 | - |
| Symantec | 20091.2.0.41 | 2010.03.24 | Adware.Gen |
| TheHacker | 6.5.2.0.242 | 2010.03.24 | - |
| TrendMicro | 9.120.0.1004 | 2010.03.24 | TROJ_DESUROU.SMB |
| VBA32 | 3.12.12.2 | 2010.03.24 | AdWare.Win32.BHO.lft |
| ViRobot | 2010.3.24.2242 | 2010.03.24 | - |
| VirusBuster | 5.0.27.0 | 2010.03.24 | - |
O23 - 服务: MediaIECom (MediaIECom) -
C:\WINDOWS\system32\733d.exe | 2010-2-6 17:51:24(自动)
文件说明符 : C:\WINDOWS\system32\733d.exe
属性 : ---R
数字签名:Beijing BoDong Wanjie Network Technology Co.Ltd
PE文件:是
获取文件版本信息大小失败!
创建时间 : 2010-1-30 21:8:29
修改时间 : 2010-2-6 17:51:24
大小 : 115368 字节 112.680 KB
MD5 : 2d6440d451236ec8a330bf3f54b548e7
SHA1: 7267854CC6594B0D01DCF8BBE7F38D176464B79D
CRC32: b13beaaf
文件 733d.exe 接收于 2010.03.24 13:36:37 (UTC)
| 反病毒引擎 | 版本 | 最后更新 | 扫描结果 |
| a-squared | 4.5.0.50 | 2010.03.24 | Trojan-Downloader.Win32.Adload!IK |
| AhnLab-V3 | 5.0.0.2 | 2010.03.24 | Win-Trojan/Adload.115368 |
| AntiVir | 8.2.1.196 | 2010.03.24 | ADSPY/Bho.kzb |
| Antiy-AVL | 2.0.3.7 | 2010.03.24 | Trojan/Win32.Adload.gen |
| Authentium | 5.2.0.5 | 2010.03.24 | W32/Rugu.D.gen!Eldorado |
| Avast | 4.8.1351.0 | 2010.03.24 | Win32:Adload-LR |
| Avast5 | 5.0.332.0 | 2010.03.24 | Win32:Adload-LR |
| AVG | 9.0.0.787 | 2010.03.24 | Generic16.BKIH |
| BitDefender | 7.2 | 2010.03.24 | Application.Generic.284939 |
| CAT-QuickHeal | 10.00 | 2010.03.24 | TrojanDownloader.Adload.obl |
| ClamAV | 0.96.0.0-git | 2010.03.24 | - |
| Comodo | 4368 | 2010.03.24 | - |
| DrWeb | 5.0.1.12222 | 2010.03.24 | Trojan.DownLoad1.36946 |
| eSafe | 7.0.17.0 | 2010.03.24 | - |
| eTrust-Vet | 35.2.7386 | 2010.03.24 | - |
| F-Prot | 4.5.1.85 | 2010.03.23 | W32/Rugu.D.gen!Eldorado |
| F-Secure | 9.0.15370.0 | 2010.03.24 | Application.Generic.284939 |
| Fortinet | 4.0.14.0 | 2010.03.24 | W32/Adload.OBL!tr.dldr |
| GData | 19 | 2010.03.24 | Application.Generic.284939 |
| Ikarus | T3.1.1.80.0 | 2010.03.24 | Trojan-Downloader.Win32.Adload |
| Jiangmin | 13.0.900 | 2010.03.24 | TrojanDownloader.Adload.ipm |
| K7AntiVirus | 7.10.1004 | 2010.03.22 | Trojan-Downloader.Win32.Adload.obl |
| Kaspersky | 7.0.0.125 | 2010.03.24 | Trojan-Downloader.Win32.Adload.obl |
| McAfee | 5929 | 2010.03.23 | Generic Downloader.x!dap |
| McAfee+Artemis | 5929 | 2010.03.23 | Generic Downloader.x!dap |
| McAfee-GW-Edition | 6.8.5 | 2010.03.24 | Ad-Spyware.Bho.kzb |
| Microsoft | 1.5605 | 2010.03.24 | - |
| NOD32 | 4971 | 2010.03.24 | Win32/Adware.WSearch |
| Norman | 6.04.10 | 2010.03.24 | - |
| nProtect | 2009.1.8.0 | 2010.03.24 | Trojan-Clicker/W32.BHO.115368 |
| Panda | 10.0.2.2 | 2010.03.23 | Suspicious file |
| PCTools | 7.0.3.5 | 2010.03.24 | Trojan-Downloader.Adload |
| Prevx | 3.0 | 2010.03.24 | - |
| Rising | 22.40.02.03 | 2010.03.24 | - |
| Sophos | 4.51.0 | 2010.03.24 | Mal/Generic-A |
| Sunbelt | 6031 | 2010.03.22 | Trojan.Win32.Generic!BT |
| Symantec | 20091.2.0.41 | 2010.03.24 | SecurityRisk.ADH |
| TheHacker | 6.5.2.0.242 | 2010.03.24 | - |
| TrendMicro | 9.120.0.1004 | 2010.03.24 | - |
| VBA32 | 3.12.12.2 | 2010.03.24 | AdWare.Win32.BHO.kzb |
| ViRobot | 2010.3.24.2242 | 2010.03.24 | - |
| VirusBuster | 5.0.27.0 | 2010.03.24 | Adware.Bho.ACXE |
O23 - 服务: OSEvent (OSEvent) -
C:\WINDOWS\system32\s.exe | 2010-1-20 13:31:22
| Microsoft(R) Windows(R) Operating System
| 3.1.2600.2160
| COM Surrogate
| Microsoft Corporation
| 3.1.2600.2160 (xpsp_sp2_rtm.040803-2158)
| Microsoft Corporation
| ?
| COM| ?(自动)
文件说明符 : C:\WINDOWS\system32\s.exe
属性 : A--R
数字签名:Beijing BoDong Wanjie Network Technology Co.Ltd
PE文件:是
语言 : 中文(中国)
文件版本 : 3.1.2600.2160 (xpsp_sp2_rtm.040803-2158)
说明 : COM Surrogate
版权 : Microsoft Corporation
产品版本 : 3.1.2600.2160
产品名称 : Microsoft(R) Windows(R) Operating System
公司名称 : Microsoft Corporation
内部名称 : COM
创建时间 : 2009-12-30 17:29:57
修改时间 : 2010-1-20 13:31:22
大小 : 85456 字节 83.464 KB
MD5 : fff63a64b440ca1b4e2071e5ac4e3a29
SHA1: FCD1C863D92785349F461E899EBE1C3FEEED892B
CRC32: b5cf10e6
文件 s.exe 接收于 2010.03.24 13:43:46 (UTC)
| 反病毒引擎 | 版本 | 最后更新 | 扫描结果 |
| a-squared | 4.5.0.50 | 2010.03.24 | Riskware.AdWare.Win32.Zhongsou!IK |
| AhnLab-V3 | 5.0.0.2 | 2010.03.24 | - |
| AntiVir | 8.2.1.196 | 2010.03.24 | - |
| Antiy-AVL | 2.0.3.7 | 2010.03.24 | - |
| Authentium | 5.2.0.5 | 2010.03.24 | - |
| Avast | 4.8.1351.0 | 2010.03.24 | - |
| Avast5 | 5.0.332.0 | 2010.03.24 | - |
| AVG | 9.0.0.787 | 2010.03.24 | - |
| BitDefender | 7.2 | 2010.03.24 | - |
| CAT-QuickHeal | 10.00 | 2010.03.24 | - |
| ClamAV | 0.96.0.0-git | 2010.03.24 | - |
| Comodo | 4368 | 2010.03.24 | UnclassifiedMalware |
| DrWeb | 5.0.1.12222 | 2010.03.24 | Trojan.AdLoad.8 |
| eSafe | 7.0.17.0 | 2010.03.24 | Win32.Agent.Qoc |
| eTrust-Vet | 35.2.7386 | 2010.03.24 | - |
| F-Prot | 4.5.1.85 | 2010.03.23 | - |
| F-Secure | 9.0.15370.0 | 2010.03.24 | - |
| Fortinet | 4.0.14.0 | 2010.03.24 | - |
| GData | 19 | 2010.03.24 | - |
| Ikarus | T3.1.1.80.0 | 2010.03.24 | not-a-virus:AdWare.Win32.Zhongsou |
| Jiangmin | 13.0.900 | 2010.03.24 | - |
| K7AntiVirus | 7.10.1004 | 2010.03.22 | - |
| Kaspersky | 7.0.0.125 | 2010.03.24 | - |
| McAfee | 5929 | 2010.03.23 | - |
| McAfee+Artemis | 5929 | 2010.03.23 | Artemis!FFF63A64B440 |
| McAfee-GW-Edition | 6.8.5 | 2010.03.24 | - |
| Microsoft | 1.5605 | 2010.03.24 | - |
| NOD32 | 4971 | 2010.03.24 | a variant of Win32/Agent.QOC |
| Norman | 6.04.10 | 2010.03.24 | - |
| nProtect | 2009.1.8.0 | 2010.03.24 | - |
| Panda | 10.0.2.2 | 2010.03.23 | - |
| PCTools | 7.0.3.5 | 2010.03.24 | - |
| Prevx | 3.0 | 2010.03.24 | - |
| Rising | 22.40.02.03 | 2010.03.24 | - |
| Sophos | 4.51.0 | 2010.03.24 | - |
| Sunbelt | 6031 | 2010.03.22 | - |
| Symantec | 20091.2.0.41 | 2010.03.24 | Suspicious.Insight |
| TheHacker | 6.5.2.0.242 | 2010.03.24 | Trojan/Agent.qoc |
| TrendMicro | 9.120.0.1004 | 2010.03.24 | - |
| VBA32 | 3.12.12.2 | 2010.03.24 | - |
| ViRobot | 2010.3.24.2242 | 2010.03.24 | - |
| VirusBuster | 5.0.27.0 | 2010.03.24 | - |
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; QQDownload 1.7; Maxthon)附件:
4f.rar