XywCloud 发表于 2012-4-3 23:30 
就这么多么?
看这记录像是除了弹广告,就没别的恶意行为了...
汗,那只是重要的记录,用来清理病毒的用。。。。
完整记录如下:
Executing: c:\windows\syswow64\mshta.exe
GetModuleHandle(lz32.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(lz32.dll) [c:\windows\syswow64\mshta.exe]
CreateEvent(SBIE_BOXED_ServiceInitComplete_RpcSs) [c:\windows\syswow64\mshta.exe]
GetModuleHandle(Kernel32.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(mshtml.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(psapi.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(ole32.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(urlmon.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(oleaut32.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(shlwapi.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(iertutil.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(wininet.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(normaliz.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(version.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(secur32.dll) [c:\windows\syswow64\mshta.exe]
CreateMutex(Local\!PrivacIE!SharedMemory!Mutex) [c:\windows\syswow64\mshta.exe]
LoadLibrary(ntmarta.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(wldap32.dll) [c:\windows\syswow64\mshta.exe]
GetModuleHandle(shell32.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(shell32.dll) [c:\windows\syswow64\mshta.exe]
OpenProcessToken(C:\Windows\SysWOW64\mshta.exe) [c:\windows\syswow64\mshta.exe]
GetModuleHandle(ole32.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(c:\windows\system32\uxtheme.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(uxtheme.dll) [c:\windows\syswow64\mshta.exe]
IsDebuggerPresent() [c:\windows\syswow64\mshta.exe]
GetModuleHandle(user32.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(dwmapi.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(propsys.dll) [c:\windows\syswow64\mshta.exe]
GetModuleHandle(advapi32.dll) [c:\windows\syswow64\mshta.exe]
FindWindow(Shell_TrayWnd,(null)) [c:\windows\syswow64\mshta.exe]
GetModuleHandle(shlwapi.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(clbcatq.dll) [c:\windows\syswow64\mshta.exe]
GetModuleHandle(kernel32) [c:\windows\syswow64\mshta.exe]
GetModuleHandle(LPK) [c:\windows\syswow64\mshta.exe]
LoadLibrary(comctl32.dll) [c:\windows\syswow64\mshta.exe]
GetModuleHandle(EXPLORER.EXE) [c:\windows\syswow64\mshta.exe]
GetModuleHandle(IEXPLORE.EXE) [c:\windows\syswow64\mshta.exe]
LoadLibrary(mlang.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(msimtf.dll) [c:\windows\syswow64\mshta.exe]
GetKeyState() [c:\windows\syswow64\mshta.exe]
GetModuleHandle(USER32) [c:\windows\syswow64\mshta.exe]
BitBlt() [c:\windows\syswow64\mshta.exe]
GetModuleHandle(C:\Windows\system32\Msimtf.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(jscript9.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(api-ms-win-core-localregistry-l1-1-0.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(powrprof.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(setupapi.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(cfgmgr32.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(devobj.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(d2d1.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(dwrite.dll) [c:\windows\syswow64\mshta.exe]
OpenService(FontCache) [c:\windows\syswow64\mshta.exe]
StartService() [c:\windows\syswow64\mshta.exe]
LoadLibrary(dxgi.dll) [c:\windows\syswow64\mshta.exe]
CreateDC(\\.\DISPLAY1,\\.\DISPLAY1,(null)) [c:\windows\syswow64\mshta.exe]
LoadLibrary(wintrust.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(crypt32.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(msasn1.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(d3d10_1.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(d3d10_1core.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(d3d10warp.dll) [c:\windows\syswow64\mshta.exe]
CreateMutex(Local\IESQMMUTEX_0_274) [c:\windows\syswow64\mshta.exe]
LoadLibrary(nvd3dum.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(msls31.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(oleaccrc.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(ieframe.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(oleacc.dll) [c:\windows\syswow64\mshta.exe]
GetUserName() [c:\windows\syswow64\mshta.exe]
LoadLibrary(profapi.dll) [c:\windows\syswow64\mshta.exe]
CreateFile(C:\Users\Shamrock\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat) [c:\windows\syswow64\mshta.exe]
CreateFile(C:\Users\Shamrock\AppData\Roaming\Microsoft\Windows\Cookies\index.dat) [c:\windows\syswow64\mshta.exe]
CreateFile(C:\Users\Shamrock\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat) [c:\windows\syswow64\mshta.exe]
LoadLibrary(d3d10.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(d3d10core.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(windowscodecs.dll) [c:\windows\syswow64\mshta.exe]
CreateDC(DISPLAY,(null),(null)) [c:\windows\syswow64\mshta.exe]
LoadLibrary(scrrun.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(sxs.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(wshom.ocx) [c:\windows\syswow64\mshta.exe]
LoadLibrary(mpr.dll) [c:\windows\syswow64\mshta.exe]
CreateFile(C:\ProgramData\csdat\X5A59XVV.h) [c:\windows\syswow64\mshta.exe]
LoadLibrary(apphelp.dll) [c:\windows\syswow64\mshta.exe]
CreateProcess(C:\Windows\System32\mshta.exe,"C:\Windows\System32\mshta.exe" "C:\ProgramData\csdat\X5A59XVV.h",C:\Users\Shamrock\Desktop) [c:\windows\syswow64\mshta.exe]
GetModuleHandle(OLEAUT32) [c:\windows\syswow64\mshta.exe]
LoadLibrary(msxml3.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(c:\windows\system32\msxml3r.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(cryptsp.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(rsaenh.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(rpcrtremote.dll) [c:\windows\syswow64\mshta.exe]
GetModuleHandle(svchost.exe) [c:\windows\syswow64\mshta.exe]
GetModuleHandle(taskhost.exe) [c:\windows\syswow64\mshta.exe]
LoadLibrary(ws2_32.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(nsi.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(dnsapi.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(iphlpapi.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(winnsi.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(rasapi32.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(rasman.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(rtutils.dll) [c:\windows\syswow64\mshta.exe]
RasEnumEntries() [c:\windows\syswow64\mshta.exe]
OpenService(rasman) [c:\windows\syswow64\mshta.exe]
OpenService(Sens) [c:\windows\syswow64\mshta.exe]
LoadLibrary(sensapi.dll) [c:\windows\syswow64\mshta.exe]
InternetGetConnectedState() [c:\windows\syswow64\mshta.exe]
InternetOpen() [c:\windows\syswow64\mshta.exe]
LoadLibrary(mswsock.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(wshtcpip.dll) [c:\windows\syswow64\mshta.exe]
GetModuleHandle(ws2_32.dll) [c:\windows\syswow64\mshta.exe]
bind(port=0) [c:\windows\syswow64\mshta.exe]
connect( 127.0.0.1:56507 ) [c:\windows\syswow64\mshta.exe]
InternetConnect(ann-d.com) [c:\windows\syswow64\mshta.exe]
HttpOpenRequest(/user/h_info_ajax.php?checkuser=X5A59XVV) [c:\windows\syswow64\mshta.exe]
LoadLibrary(nlaapi.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(rasadhlp.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(wship6.dll) [c:\windows\syswow64\mshta.exe]
LoadLibrary(fwpuclnt.dll) [c:\windows\syswow64\mshta.exe]
connect( 50.23.111.254:80 ) [c:\windows\syswow64\mshta.exe]
CreateFile(C:\ProgramData\csdat\d.bat) [c:\windows\syswow64\mshta.exe]
CreateProcess((null),"C:\ProgramData\csdat\d.bat" ,C:\Users\Shamrock\Desktop) [c:\windows\syswow64\mshta.exe]
LoadLibrary(c:\sandbox\shamrock\defaultbox\user\all\csdat\d.bat) [c:\windows\syswow64\mshta.exe]
Executing: c:\windows\syswow64\cmd.exe
LoadLibrary(winbrand.dll) [c:\windows\syswow64\cmd.exe]
GetModuleHandle(lz32.dll) [c:\windows\syswow64\cmd.exe]
LoadLibrary(lz32.dll) [c:\windows\syswow64\cmd.exe]
GetModuleHandle(user32.dll) [c:\windows\syswow64\cmd.exe]
LoadLibrary(c:\windows\system32\uxtheme.dll) [c:\windows\syswow64\cmd.exe]
LoadLibrary(uxtheme.dll) [c:\windows\syswow64\cmd.exe]
IsDebuggerPresent() [c:\windows\syswow64\cmd.exe]
LoadLibrary(dwmapi.dll) [c:\windows\syswow64\cmd.exe]
GetModuleHandle(shell32.dll) [c:\windows\syswow64\cmd.exe]
CreateEvent(SBIE_BOXED_ServiceInitComplete_RpcSs) [c:\windows\syswow64\cmd.exe]
LoadLibrary(shell32.dll) [c:\windows\syswow64\cmd.exe]
LoadLibrary(shlwapi.dll) [c:\windows\syswow64\cmd.exe]
GetModuleHandle(KERNEL32.DLL) [c:\windows\syswow64\cmd.exe]
OpenProcessToken(C:\Windows\SysWOW64\cmd.exe) [c:\windows\syswow64\cmd.exe]
GetVolumeInformation(C:\) [c:\windows\syswow64\cmd.exe]
LoadLibrary(ole32.dll) [c:\windows\syswow64\cmd.exe]
GetModuleHandle(ole32.dll) [c:\windows\syswow64\cmd.exe]
CreateFile(NUL) [c:\windows\syswow64\cmd.exe]
LoadLibrary(propsys.dll) [c:\windows\syswow64\cmd.exe]
LoadLibrary(oleaut32.dll) [c:\windows\syswow64\cmd.exe]
CreateProcess(C:\Windows\SysWOW64\PING.EXE,ping -n 5 localhost ,C:\Users\Shamrock\Desktop) [c:\windows\syswow64\cmd.exe]
GetModuleHandle(advapi32.dll) [c:\windows\syswow64\cmd.exe]
FindWindow(Shell_TrayWnd,(null)) [c:\windows\syswow64\cmd.exe]
GetModuleHandle(shlwapi.dll) [c:\windows\syswow64\cmd.exe]
LoadLibrary(version.dll) [c:\windows\syswow64\cmd.exe]
LoadLibrary(c:\windows\syswow64\cmd.exe) [c:\windows\syswow64\cmd.exe]
LoadLibrary(apphelp.dll) [c:\windows\syswow64\cmd.exe]
Executing: c:\windows\syswow64\ping.exe
LoadLibrary(iphlpapi.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(nsi.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(winnsi.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(ws2_32.dll) [c:\windows\syswow64\ping.exe]
GetModuleHandle(lz32.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(lz32.dll) [c:\windows\syswow64\ping.exe]
GetModuleHandle(user32.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(c:\windows\system32\uxtheme.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(uxtheme.dll) [c:\windows\syswow64\ping.exe]
IsDebuggerPresent() [c:\windows\syswow64\ping.exe]
LoadLibrary(dwmapi.dll) [c:\windows\syswow64\ping.exe]
GetModuleHandle(shell32.dll) [c:\windows\syswow64\ping.exe]
CreateEvent(SBIE_BOXED_ServiceInitComplete_RpcSs) [c:\windows\syswow64\ping.exe]
LoadLibrary(shell32.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(shlwapi.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(ole32.dll) [c:\windows\syswow64\ping.exe]
GetModuleHandle(ole32.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(propsys.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(oleaut32.dll) [c:\windows\syswow64\ping.exe]
GetModuleHandle(advapi32.dll) [c:\windows\syswow64\ping.exe]
FindWindow(Shell_TrayWnd,(null)) [c:\windows\syswow64\ping.exe]
LoadLibrary(mswsock.dll) [c:\windows\syswow64\ping.exe]
GetModuleHandle(shlwapi.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(wshtcpip.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(wship6.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(dnsapi.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(version.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(c:\windows\syswow64\ping.exe) [c:\windows\syswow64\ping.exe]
LoadLibrary(rasadhlp.dll) [c:\windows\syswow64\ping.exe]
LoadLibrary(fwpuclnt.dll) [c:\windows\syswow64\ping.exe]
|