1   1  /  1  页   跳转

可疑文件

可疑文件

NameValue
Size501248
MD5baf0d50d5bad678ba1ce84afd8731b71
SHA1c9fd5f4da7a8f8fc60c8d7c3deb3452051250f3b
SHA256d7e0bdb952fe943ee3d12d5fa2558bfe101b6a435f020e2df888ee2e09ed62f5
ProcessActive

• Keys Created• Keys Changed• Keys Deleted• Values Created• Values Changed• Values Deleted• Directories Created• Directories Changed• Directories Deleted• Files Created
NameSizeLast Write TimeCreation TimeLast Access TimeAttr
C:\Documents and Settings\User\Local Settings\Temp\~DFBD61.tmp983042009.01.12 14:47:58.3122009.01.12 14:47:58.2182009.01.12 14:47:58.2180x20

• Files Changed• Files Deleted• Directories Hidden• Files Hidden• Drivers Loaded• Drivers Unloaded• Processes Created• Processes Terminated• Threads Created
PIdProcess NameTIdStartStart MemWin32 StartWin32 Start Mem
0x4System0x36c0xf8dacb32MEM_FREE0x0MEM_FREE
0x4System0x3700xf8dacb32MEM_FREE0x0MEM_FREE
0x344svchost.exe0x1700x7c810856MEM_IMAGE0x7c910760MEM_IMAGE
0x404svchost.exe0x3740x7c810856MEM_IMAGE0x7509b647MEM_IMAGE

• Modules Loaded
PIdProcess NameBaseSizeFlagsImage Name
0x404svchost.exe0x71c800000x70000x800c4006C:\WINDOWS\System32\NETRAP.dll
0x404svchost.exe0x720800000x190000x800c4004C:\WINDOWS\System32\xactsrv.dll

 附件: 您所在的用户组无法下载或查看附件

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; CNCDialer; .NET CLR 2.0.50727; MAXTHON 2.0)
分享到:
gototop
 

回复:可疑文件

建议把样本发给瑞星,地址为:http://mailcenter.rising.com.cn/FileCheck/

提交后,可自行查询处理进度。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT