==================================
正在运行的进程
[PID: 436][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 496][\??\C:\WINDOWS2\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1480][C:\WINDOWS2\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS2\system32\AF849484.DLL] [Microsoft Corporation, ]
[C:\WINDOWS2\G_Server.DLL] [N/A, ]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [Yahoo! China, 3, 0, 8, 1026]
[C:\WINDOWS2\system32\mppds.dll] [N/A, ]
[C:\WINDOWS2\system32\winform.dll] [N/A, ]
[C:\Syswm1i\Ghook.dll] [N/A, ]
[C:\WINDOWS2\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS2\system32\cmdbc.dll] [N/A, ]
[C:\DOCUME~1\CHUNQI~1.607\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS2\system32\msccrt.dll] [N/A, ]
[E:\7260PC套件\安装文件\Nokia PC Suite 6\PhoneBrowser.dll] [Nokia, 6, 82, 63, 9]
[E:\7260PC套件\安装文件\Nokia PC Suite 6\PCSCM.dll] [Nokia, 6, 82, 77, 0]
[C:\Program Files\PC Connectivity Solution\ConnAPI.DLL] [Nokia., 6, 82, 72, 2]
[C:\WINDOWS2\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS2\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[E:\7260PC套件\安装文件\Nokia PC Suite 6\Lang\PhoneBrowser_chi-sc.nlr] [Nokia, 6, 82, 36, 1]
[E:\7260PC套件\安装文件\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr] [Nokia, 6, 82, 14, 0]
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] [yahoo! china, 3, 6, 7, 1122]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] [Yahoo! China, 3, 0, 2, 1011]
[D:\迅雷\安装文件\ComDlls\XunLeiBHO_007.dll] [Thunder Networking Technologies,LTD, 5, 0, 1, 4]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll] [Yahoo! China, 3, 0, 8, 1010]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL] [yahoo! china, 3, 0, 4, 1006]
[C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yassist.dll] [Yahoo! China, 3, 1, 7, 1022]
[PID: 1656][C:\WINDOWS2\system32\3925249E.exe] [N/A, ]
[C:\WINDOWS2\system32\vb6chs.dll] [Microsoft Corporation, 6.00.8988]
[C:\WINDOWS2\G_Server.DLL] [N/A, ]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [Yahoo! China, 3, 0, 8, 1026]
[C:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 544][C:\Syswm1i\svchost.exe] [N/A, ]
[C:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 752][C:\WINDOWS2\SVCHOST.EXE] [N/A, ]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [Yahoo! China, 3, 0, 8, 1026]
[C:\WINDOWS2\G_Server.DLL] [N/A, ]
[C:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 908][C:\WINDOWS2\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [Yahoo! China, 3, 0, 8, 1026]
[C:\WINDOWS2\G_Server.DLL] [N/A, ]
[C:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 1080][C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe] [Google Inc., 1, 2, 1128, 5462]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [Yahoo! China, 3, 0, 8, 1026]
[C:\WINDOWS2\G_Server.DLL] [N/A, ]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\res_zh-CN.dll] [Google Inc., 1, 2, 1128, 5462]
[C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\swg.dll] [Google Inc., 1, 2, 1128, 5462]
[C:\Syswm1i\Ghook.dll] [N/A, ]
[PID: 1008][C:\WINDOWS2\system32\cmd.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1444][C:\WINDOWS2\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1388][C:\WINDOWS2\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1344][C:\WINDOWS2\system32\runonce.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1128][C:\WINDOWS2\nortonp.exe] [N/A, ]
[C:\WINDOWS2\system32\nortonp.dll] [N/A, ]
[PID: 2664][C:\Documents and Settings\chunqiu.607E7E68691B4D0\My Documents\00\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] [Yahoo! China, 3, 0, 8, 1026]
[C:\WINDOWS2\G_Server.DLL] [N/A, ]
[C:\Syswm1i\Ghook.dll] [N/A, ]
[C:\WINDOWS2\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS2\system32\cmdbc.dll] [N/A, ]
[C:\WINDOWS2\system32\winform.dll] [N/A, ]
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS2\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MSAFD Tcpip [TCP/IP]
C:\WINDOWS2\system32\md6media.dll(, N/A)
MSAFD Tcpip [RAW/IP]
C:\WINDOWS2\system32\md6media.dll(, N/A)
==================================
Autorun.inf
[C:\]
[AutoRun]
open=RavMon.exe
shell\open=打开(&O)
shell\open\Command=RavMon.exe
shell\explore=资源管理器(&X)
shell\explore\Command="RavMon.exe -e"
[D:\]
[AutoRun]
open=RavMon.exe
shell\open=打开(&O)
shell\open\Command=RavMon.exe
shell\explore=资源管理器(&X)
shell\explore\Command="RavMon.exe -e"
[E:\]
[AutoRun]
open=RavMon.exe
shell\open=打开(&O)
shell\open\Command=RavMon.exe
shell\explore=资源管理器(&X)
shell\explore\Command="RavMon.exe -e"
[F:\]
[AutoRun]
open=RavMon.exe
shell\open=打开(&O)
shell\open\Command=RavMon.exe
shell\explore=资源管理器(&X)
shell\explore\Command="RavMon.exe -e"
[G:\]
[AutoRun]
open=RavMon.exe
shell\open=打开(&O)
shell\open\Command=RavMon.exe
shell\explore=资源管理器(&X)
shell\explore\Command="RavMon.exe -e"
[H:\]
[AutoRun]
open=RavMon.exe
shell\open=打开(&O)
shell\open\Command=RavMon.exe
shell\explore=资源管理器(&X)
shell\explore\Command="RavMon.exe -e"
==================================
HOSTS 文件
127.0.0.1 localhost
61.188.38.107 www.9605899.com
61.188.38.107 hyap98.com
61.188.38.107 www.hyap98.com
61.188.38.107 82087871.com
61.188.38.107 www.82087871.com
61.188.38.107 47555.cn
61.188.38.107 nc.47555.cn
61.188.38.107 cn.47555.cn
61.188.38.107 crsky.47555.cn
61.188.38.107 www.47555.cn
==================================
API HOOK
入口点错误:NtQuerySystemInformation (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS2\G_Server.DLL)
入口点错误:NtTerminateProcess (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS2\G_Server.DLL)
入口点错误:ZwTerminateProcess (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS2\G_Server.DLL)
入口点错误:EnumServicesStatusA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS2\G_Server.DLL)
入口点错误:EnumServicesStatusW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS2\G_Server.DLL)
入口点错误:FindNextFileA (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS2\G_Server.DLL)
入口点错误:FindNextFileW (危险等级: 高, 被下面模块所HOOK: C:\WINDOWS2\G_Server.DLL)
==================================
隐藏进程
[1116] C:\DOCUME~1\CHUNQI~1.607\LOCALS~1\Temp\ie777.exe
[1580] C:\WINDOWS2\G_Server.exe
==================================
[/CODE]