瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 怀疑svchost其中有个是灰鸽子(附日志)

12   2  /  2  页   跳转

怀疑svchost其中有个是灰鸽子(附日志)

==================================
正在运行的进程
[PID: 824][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 892][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 916][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\klogon.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 960][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 972][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1128][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1192][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1360][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
[PID: 1444][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1588][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1784][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  [Windows (R) 2000 DDK provider, 5.00.2195.1620]
[PID: 2040][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe]  [Microsoft Corporation, 7.10.3077]
[PID: 248][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.10.9133]
[PID: 276][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1396][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2196][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 3180][C:\Program Files\LClock\lclock.exe]  [N/A, 1, 0, 0, 1]
    [C:\Program Files\LClock\LC.dll]  [N/A, N/A]
    [C:\Program Files\LClock\Calendar.dll]  [N/A, N/A]
[PID: 3480][C:\Program Files\ChinaNet\VnetClient.exe]  [, 2005, 10, 8, 1]
    [C:\Program Files\ChinaNet\Communicate.dll]  [0, 2005, 3, 3, 1]
    [C:\Program Files\ChinaNet\DialModule.dll]  [, 2005, 3, 22, 1]
    [E:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\PROGRA~1\ChinaNet\CLIENT~1.DLL]  [, 2004, 2, 28, 1]
    [C:\PROGRA~1\ChinaNet\PLUGIN~1.OCX]  [, 2005, 7, 27, 1]
    [C:\PROGRA~1\ChinaNet\sign.dll]  [0, 2004, 12, 1, 1]
    [C:\PROGRA~1\ChinaNet\WEBPLU~1.DLL]  [, 2005, 8, 18, 1]
    [C:\PROGRA~1\ChinaNet\PostPlug.dll]  [, 2004, 12, 16, 2]
    [C:\PROGRA~1\ChinaNet\ADVERT~1.OCX]  [, 2005, 10, 13, 1]
    [C:\PROGRA~1\ChinaNet\VnetBs.ocx]  [, 2004, 11, 18, 1]
    [C:\PROGRA~1\ChinaNet\ACCOUN~3.DLL]  [, 2005, 8, 11, 1]
    [C:\PROGRA~1\ChinaNet\AccountMgr.dll]  [, 2005, 8, 16, 1]
    [C:\PROGRA~1\ChinaNet\VnetSkin.ocx]  [GDDC, 1, 0, 0, 1]
    [C:\PROGRA~1\ChinaNet\DialogStyle.dll]  [, 1, 0, 0, 1]
    [C:\PROGRA~1\ChinaNet\Timer.ocx]  [, 2005, 10, 9, 14]
    [C:\PROGRA~1\ChinaNet\PLUGIN~2.OCX]  [, 2005, 2, 24, 1]
    [C:\PROGRA~1\ChinaNet\NEWMES~1.DLL]  [, 2005, 8, 26, 1]
    [C:\PROGRA~1\ChinaNet\PassCtrl.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\wpcap.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\WINDOWS\system32\pthreadVC.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\packet.dll]  [Politecnico di Torino, 3, 0, 0, 18]
    [C:\PROGRA~1\ChinaNet\PlugPush.dll]  [, 2004, 12, 21, 1]
    [C:\PROGRA~1\ChinaNet\ALLINT~1.DLL]  [, 2004, 11, 23, 1]
    [C:\PROGRA~1\ChinaNet\VNetLog.ocx]  [, 2005, 10, 9, 1]
    [C:\PROGRA~1\ChinaNet\StatNum.dll]  [, 2004, 11, 18, 1]
    [C:\PROGRA~1\ChinaNet\VNETON~1.OCX]  [, 2005, 3, 2, 1]
    [C:\PROGRA~1\ChinaNet\ALLFUN~1.DLL]  [GDCN, 2005, 10, 9, 1]
    [C:\PROGRA~1\ChinaNet\VnetOptLog.dll]  [, 2005, 9, 13, 9]
    [E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scr_ch_pg.dll]  [Kaspersky Lab, 1.0.6.299]
    [E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\klscav.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\pr_remote.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\prloader.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\prkernel.ppl]  [Kaspersky Lab, 6.0.0.304]
gototop
 

[e:\program files\kaspersky lab\kaspersky internet security 6.0\params.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\program files\kaspersky lab\kaspersky internet security 6.0\pxstub.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\program files\kaspersky lab\kaspersky internet security 6.0\tempfile.ppl]  [Kaspersky Lab, 6.0.0.299]
    [C:\PROGRA~1\ChinaNet\DlgSkin.ocx]  [, 1, 0, 0, 1]
    [e:\program files\kaspersky lab\kaspersky internet security 6.0\nfio.ppl]  [Kaspersky Lab, 6.0.0.299]
    [e:\program files\kaspersky lab\kaspersky internet security 6.0\fsdrvplgn.ppl]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
[PID: 2708][E:\Program Files\Tencent\qq\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [E:\Program Files\Tencent\qq\CoralAssist.DLL]  [Coral Team, 4.5.0 build 20060515]
    [E:\Program Files\Tencent\qq\CoralQQ.DLL]  [Coral Team, 4.5.4 Build 20061001]
    [E:\Program Files\Tencent\qq\ipsearcher.dll]  [N/A, 1.0.0.4]
    [E:\Program Files\Tencent\qq\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [E:\Program Files\Tencent\qq\QQAPI.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [E:\Program Files\Tencent\qq\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [E:\Program Files\Tencent\qq\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [E:\Program Files\Tencent\qq\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\QQMainFrame.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\CQQApplication.dll]  [N/A, N/A]
    [E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\Program Files\Tencent\qq\NewSkin.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\HostingMgr.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\CameraDll.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\MailSummary.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\QQSpace.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\QQAllInOne.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\GroupLive.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [E:\Program Files\Tencent\qq\QQPlugin.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\QQCustomFace.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\ShareFiles.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\QQZip.dll]  [tencent, 0, 3, 2, 4]
    [E:\Program Files\Tencent\qq\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [E:\Program Files\Tencent\qq\QQAvatar.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\QRingMng.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\GroupConnection.dll]  [Tencent, 0, 3, 3, 5]
    [E:\Program Files\Tencent\qq\QQPet.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [E:\Program Files\Tencent\qq\VPortal.dll]  [, 1, 0, 0, 4]
    [E:\Program Files\Tencent\qq\BQQApplication.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [E:\Program Files\Tencent\qq\QQSysMsgMng.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\CommercesMng.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
    [E:\Program Files\Tencent\qq\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 0, 1, 10]
    [E:\Program Files\Tencent\qq\QQSceneMng.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
    [E:\Program Files\Tencent\qq\QQSettingCtrl.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\ImageOle.dll]  [TODO: <Company name>, 1.0.0.1]
    [E:\Program Files\Tencent\qq\QQFileTransfer.dll]  [Tencent, 0, 3, 3, 5]
[PID: 964][E:\Program Files\Tencent\qq\TIMPlatform.exe]  [tencent, 0, 3, 1, 8]
    [E:\Program Files\Tencent\qq\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
[PID: 2900][C:\WINDOWS\explorer.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\AcSignIcon.dll]  [Autodesk, 17.0.54.0]
    [E:\Program Files\IconPackager\shellext.dll]  [Stardock.net, Inc, 3.10.00]
    [C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll]  [Autodesk, 17.0.54.110]
    [E:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 7.0.0.0]
    [C:\Program Files\LClock\LC.dll]  [N/A, N/A]
    [E:\Program Files\BitComet\tools\BitCometBHO.dll]  [BitComet, 20061116]
    [E:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
    [E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\shellex.dll]  [Kaspersky Lab, 6.0.0.299]
    [C:\WINDOWS\system32\contmenu.dll]  [N/A, N/A]
    [C:\WINDOWS\system32\PYJJ4.IME]  [加加工作组, 4, 1, 0, 42]
[PID: 1640][C:\WINDOWS\system32\taskmgr.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 228][E:\Program Files\Tencent\qq\QQ.exe]  [TENCENT, 0, 0, 0, 0]
    [E:\Program Files\Tencent\qq\CoralAssist.DLL]  [Coral Team, 4.5.0 build 20060515]
    [E:\Program Files\Tencent\qq\CoralQQ.DLL]  [Coral Team, 4.5.4 Build 20061001]
    [E:\Program Files\Tencent\qq\ipsearcher.dll]  [N/A, 1.0.0.4]
    [E:\Program Files\Tencent\qq\QQBaseClassInDll.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\QQHelperDll.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\BasicCtrlDll.dll]  [Tencent, 5, 0, 200, 370]
    [E:\Program Files\Tencent\qq\QQAPI.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\TIMProxy.dll]  [tencent, 0, 3, 2, 4]
    [E:\Program Files\Tencent\qq\LoginCtrl.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\npkcntc.dll]  [INCA Internet Co., Ltd., 2006, 6, 27, 1]
    [E:\Program Files\Tencent\qq\npkpdb.dll]  [INCA Internet Co., Ltd., 2003, 10, 1, 1]
    [E:\Program Files\Tencent\qq\QQRes.dll]  [tencent, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\QQMainFrame.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\CQQApplication.dll]  [N/A, N/A]
    [E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\adialhk.dll]  [Kaspersky Lab, 6.0.0.299]
    [E:\Program Files\Tencent\qq\NewSkin.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\HostingMgr.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\CameraDll.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\MailSummary.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\QQSpace.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\QQGroupMng.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\GroupLive.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\UserDefinedHead.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\QQPlugin.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\QQConfigPlugin.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\FlashAvatarDll.dll]  [, 1, 4, 0, 1]
    [E:\Program Files\Tencent\qq\QQAvatar.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\LongConnection.dll]  [tencent, 5, 0, 200, 160]
    [E:\Program Files\Tencent\qq\QQSettingCtrl.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\QRingMng.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\PhoneAPI.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\DialerAllinOne.dll]  [tencent, 1, 4, 0, 0]
    [E:\Program Files\Tencent\qq\VPortal.dll]  [, 1, 0, 0, 4]
    [E:\Program Files\Tencent\qq\QQPet.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\QQSysMsgMng.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\BQQApplication.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\PersonalDesktop.dll]  [深圳市腾讯计算机系统公司QQ工作小组, 1, 0, 0, 2]
    [E:\Program Files\Tencent\qq\CommercesMng.dll]  [, 1, 0, 0, 1]
    [E:\Program Files\Tencent\qq\QQAddr.dll]  [深圳市腾讯计算机系统有限公司, 5, 0, 101, 240]
    [E:\Program Files\Tencent\qq\QQSceneMng.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\QQMsgFriendMng.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\QQZip.dll]  [tencent, 0, 3, 2, 4]
    [E:\Program Files\Tencent\qq\QQCustomFace.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\QQPhoneHelper.dll]  [腾讯科技(深圳)有限公司, 2, 0, 1, 10]
    [E:\Program Files\Tencent\qq\QQAllInOne.dll]  [N/A, N/A]
    [E:\Program Files\Tencent\qq\SCCore.dll]  [TENCENT, 2, 0, 0, 1]
[PID: 2852][E:\Program Files\Tencent\qq\QZone\QZone.exe]  [腾讯公司, 1, 3, 102, 22]
[PID: 3272][C:\Program Files\TTPlayer\TTPlayer.exe]  [Alen Soft, 4, 6, 9, 0]
    [C:\Program Files\TTPlayer\ttpcomm.dll]  [N/A, N/A]
    [C:\Program Files\TTPlayer\ttpres.dll]  [Alen Soft, 4, 6, 9, 0]
[PID: 2392][E:\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者
N/A

==================================
Autorun.inf
N/A

==================================
HOSTS 文件
127.0.0.1localhost

==================================
API HOOK
警告!System Repair Engineer 提醒
你下面的函数内容与预期值不符,他
们可能被一些恶意的软件所修改:
RVA  错误: LoadLibraryA
RVA  错误: LoadLibraryExA
RVA  错误: LoadLibraryExW
RVA  错误: LoadLibraryW


==================================


[/CODE]
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT