|
初生襁褓狮
|
发表于:
2007-03-31 19:40
|
显示全部
短消息
资料
| 引用: | ================================== 正在运行的进程 [PID: 420][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 476][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 500][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 544][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 556][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 720][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 784][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 856][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 932][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1016][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1260][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [PID: 1280][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [D:\工具\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LgSy0.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, N/A] [C:\WINDOWS\system32\cmdbcs.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Msxo0.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rav20.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LgSy1.dll] [N/A, N/A] [D:\工具\xl\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4] [PID: 1460][D:\工具\360safe\safemon\360tray.exe] [奇虎网, 3, 2, 1, 1001] [D:\工具\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001] [D:\工具\360safe\safemon\SafeKrnl.dll] [奇虎网, 3, 2, 0, 1001] [D:\工具\360safe\AntiAdwa.dll] [360Safe.com, 3, 2, 0, 1001] [D:\工具\360safe\live.dll] [360safe.COM, 1, 0, 0, 1011] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Msxo0.dll] [N/A, N/A] [C:\WINDOWS\system32\cmdbcs.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LgSy0.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rav20.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LgSy1.dll] [N/A, N/A] [PID: 1032][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1992][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [D:\工具\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001] [PID: 852][D:\工具\xl\Program\Thunder5.exe] [Thunder Networking Technologies,LTD, 5, 5, 6, 274] [D:\工具\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001] [D:\工具\xl\Program\TaskManager.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 14] [D:\工具\xl\Program\download_interface.dll] [Thunder Networking Technologies,LTD, 2, 12, 2, 56] [D:\工具\xl\Program\asyn_dns.dll] [Thunder Networking Technologies,LTD, 2, 12, 2, 56] [D:\工具\xl\Program\iTargetAD.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 16] [D:\工具\xl\Program\BHOStub.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 8] [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0] [D:\工具\xl\Components\DiagnoseHelper\DiagnoseHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 10] [D:\工具\xl\Components\PortVerify\PortVerify.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1] [D:\工具\xl\Components\ExplorerHelper\ExplorerHelper.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1] [D:\工具\xl\Components\DTAG\DTAG.dll] [Thunder Networking Technologies,LTD, 1, 1, 0, 2] [D:\工具\xl\Components\DTAG\ExtractMediaTag.dll] [Thunder Networking Technologies,LTD, 1, 0, 0, 1] [D:\工具\xl\Program\LiveUpdate.dll] [, 1, 0, 1, 17] [D:\工具\xl\Components\InMedia\iEmbedShell.dll] [ , 1, 0, 0, 15] [D:\工具\xl\Components\InMedia\iEmbed08.dll] [ , 3, 2, 0, 63] [D:\工具\xl\Components\Community\XLCommunity.dll] [Thunder Networking Technologies,LTD, 1, 0, 4, 15] [D:\工具\xl\Program\RegisterDll.dll] [Thunder Networking Technologies,LTD, 2, 2, 1, 43] [D:\工具\xl\Components\Search\XLSearch.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 7] [D:\工具\xl\Components\P4PClient\P4PClient.dll] [Thunder Networking Technologies,LTD, 1, 0, 2, 14] [PID: 1972][C:\program files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [D:\工具\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001] [D:\工具\xl\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4] [D:\工具\QQ\QQIEHelper.dll] [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5] [PID: 1640][C:\WINDOWS\system32\notepad.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [D:\工具\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001] [PID: 2060][C:\program files\Internet Explorer\IEXPLORE.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [D:\工具\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001] [D:\工具\xl\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4] [D:\工具\QQ\QQIEHelper.dll] [深圳市腾讯计算机系统有限公司, 1, 1, 0, 5] [PID: 3288][D:\工具\360safe\360safe.exe] [奇虎网, 3, 2, 1, 1001] [D:\工具\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001] [D:\工具\360safe\AntiAdwa.dll] [360Safe.com, 3, 2, 0, 1001] [D:\工具\360safe\AntiEng.dll] [360Safe.com, 3, 0, 2, 2000] [D:\工具\360safe\Antispy.dll] [奇虎网, 1, 0, 0, 1002] [D:\工具\360safe\CleanHis.dll] [奇虎网, 3, 0, 2, 1000] [D:\工具\360safe\AntiActi.dll] [360Safe.com, 2, 0, 0, 3000] [D:\工具\360safe\live.dll] [360safe.COM, 1, 0, 0, 1011] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LgSy1.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rav20.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Msxo0.dll] [N/A, N/A] [C:\WINDOWS\system32\cmdbcs.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LgSy0.dll] [N/A, N/A] [PID: 3348][D:\工具\QQ\TT\TTraveler.exe] [腾讯公司, 3.1.0.261] [D:\工具\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001] [D:\工具\QQ\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll] [腾讯公司, 1, 1, 0, 5] [D:\工具\QQ\TT\Plugins\TWeather\TWeather.dll] [, 1, 0, 0, 3] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LgSy1.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rav20.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Msxo0.dll] [N/A, N/A] [C:\WINDOWS\system32\cmdbcs.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LgSy0.dll] [N/A, N/A] [D:\工具\QQ\TT\PersonalDesktop.dll] [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 4] [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0] [PID: 2996][D:\工具\sreng2\SREng.EXE] [Smallfrogs Studio, 2.3.13.690] [D:\工具\360safe\safemon\safemon.dll] [, 3, 2, 0, 1001] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LgSy1.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rav20.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Gjzo0.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Msxo0.dll] [N/A, N/A] [C:\WINDOWS\system32\cmdbcs.dll] [N/A, N/A] [C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LgSy0.dll] [N/A, N/A]
================================== 文件关联 .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}]
================================== Winsock 提供者 N/A
================================== Autorun.inf N/A
================================== HOSTS 文件 127.0.0.1 localhost 127.0.0.1 mmm.caifu18.net 127.0.0.1 www.18dmm.com 127.0.0.1 d.qbbd.com 127.0.0.1 www.5117music.com 127.0.0.1 www.union123.com 127.0.0.1 www.wu7x.cn 127.0.0.1 www.54699.com 127.0.0.1 60.169.0.66 127.0.0.1 60.169.1.29 127.0.0.1 www.97725.com 127.0.0.1 down.97725.com 127.0.0.1 ip.315hack.com 127.0.0.1 ip.54liumang.com 127.0.0.1 www.41ip.com 127.0.0.1 xulao.com 127.0.0.1 www.heixiou.com 127.0.0.1 www.9cyy.com 127.0.0.1 www.hunll.com 127.0.0.1 www.down.hunll.com 127.0.0.1 do.77276.com 127.0.0.1 www.baidulink.com 127.0.0.1 adnx.yygou.cn 127.0.0.1 222.73.220.45 127.0.0.1 www.f5game.com 127.0.0.1 www.guazhan.cn 127.0.0.1 wm,103715.com 127.0.0.1 www.my6688.cn 127.0.0.1 i.96981.com 127.0.0.1 d.77276.com 127.0.0.1 www1.cw988.cn 127.0.0.1 cool.47555.com 127.0.0.1 www.asdwc.com 127.0.0.1 55880.cn 127.0.0.1 61.152.169.234 127.0.0.1 cc.wzxqy.com 127.0.0.1 www.54699.com
================================== API HOOK 警告!System Repair Engineer 提醒 你下面的函数内容与预期值不符,他 们可能被一些恶意的软件所修改: 入口点错误:CreateProcessA 入口点错误:CreateProcessW
================================== |
|