(1116)主程序,路径:C:\Documents and Settings\Administrator\桌面\gr.exe,命令行:C:\Documents and Settings\Administrator\桌面\gr.exe,隐藏(NO),成功(YES)
----线程(1164)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\1696,隐藏(NO),成功(YES)
----线程(708)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\436fa.dll,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\WINDOWS\System32\sadfasdf.jpg,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\279594,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\295033,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\308096,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\319894,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\334645,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\347006,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\378725,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\409445,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\440712,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\472697,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\486526,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\498574,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\531231,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\561732,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\572890,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\604781,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\641142,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\654393,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\694206,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\735957,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\752786,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\790553,隐藏(NO),成功(YES)
----线程(1040)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\82YRUMLK,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\82YRUMLK\desktop.ini,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\82YRUMLK\oo[1].txt,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\82YRUMLK\new1[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L31JBHM1,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L31JBHM1\desktop.ini,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L31JBHM1\new2[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\RJ9VAGKI,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\RJ9VAGKI\desktop.ini,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\RJ9VAGKI\new3[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\82YRUMLK\new4[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\7VEGKSVF,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\7VEGKSVF\desktop.ini,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\7VEGKSVF\new5[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L31JBHM1\new6[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\RJ9VAGKI\new7[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\82YRUMLK\new8[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\7VEGKSVF\new9[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L31JBHM1\new10[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\RJ9VAGKI\new11[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\82YRUMLK\new12[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\7VEGKSVF\new13[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L31JBHM1\new14[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\RJ9VAGKI\new15[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\82YRUMLK\new16[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\7VEGKSVF\new17[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L31JBHM1\new18[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\RJ9VAGKI\new19[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\82YRUMLK\new20[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\7VEGKSVF\new21[1].exe,隐藏(NO),成功(YES)
--------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L31JBHM1\new22[1].exe,隐藏(NO),成功(YES)
----(244)子程序,父程序PID(1116),路径:C:\Documents and Settings\Administrator\Local Settings\Temp\279594,命令行:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\279594,隐藏(NO),挂起(NO),成功(YES)
--------线程(248)
------------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\WowInitcode.dat,隐藏(NO),成功(YES)
----(260)子程序,父程序PID(1116),路径:C:\Documents and Settings\Administrator\Local Settings\Temp\295033,命令行:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\295033,隐藏(NO),挂起(NO),成功(YES)
--------线程(252)
------------文件操作(创建):目标文件:C:\WINDOWS\System32\oljhdhfi.dll,隐藏(NO),成功(YES)
------------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\SelfDel.bat,隐藏(NO),成功(YES)
------------(284)子程序,父程序PID(252),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {8531D1F2-A1FF-4FDD-B78B-F4823749A45A} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
------------(604)子程序,父程序PID(252),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {A065C44A-8829-4C86-A090-0FD0E7ADD9E2} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
------------(312)子程序,父程序PID(252),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {0AD59034-B6AA-4308-BAA3-79DDF0641001} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
------------(304)子程序,父程序PID(252),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {F35A5D41-CB5A-40CE-B94A-43E87B16D22F} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
----------------文件操作(创建):目标文件:C:\WINDOWS\System32\678FDD15.dat,隐藏(NO),成功(YES)
----------------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\b.bat,隐藏(NO),成功(YES)
----------------(956)子程序,父程序PID(304),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {8531D1F2-A1FF-4FDD-B78B-F4823749A45A} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
----------------(1688)子程序,父程序PID(304),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {A065C44A-8829-4C86-A090-0FD0E7ADD9E2} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
----------------(164)子程序,父程序PID(304),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {0AD59034-B6AA-4308-BAA3-79DDF0641001} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
--------------------线程(264)
------------------------文件操作(创建):目标文件:C:\WINDOWS\System32\46CC7FF7.dat,隐藏(NO),成功(YES)
--------------------(856)子程序,父程序PID(164),路径:C:\WINDOWS\System32\cmd.exe,命令行:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b.bat "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\641142",隐藏(NO),挂起(NO),成功(YES)
----------------(1084)子程序,父程序PID(304),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {F35A5D41-CB5A-40CE-B94A-43E87B16D22F} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
----------------(1536)子程序,父程序PID(304),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {60624537-57ED-4F8C-B7E9-64D21A4C7EB8} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
----------------(1780)子程序,父程序PID(304),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {9EB91889-7C32-447D-8FCE-1EB5FC103286} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
----------------(1524)子程序,父程序PID(304),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {C725FB98-CA70-4D79-91F5-16862951A304} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
----------------(1948)子程序,父程序PID(304),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {27A1D97C-F8C2-4514-B8B1-5B34884ADE5E} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
----------------(300)子程序,父程序PID(304),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {65EC7475-5492-4429-B5C7-93566CAB0930} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
----------------(932)子程序,父程序PID(304),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {D2656F6A-A764-47AE-9810-2631B5CC218A} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
----------------(860)子程序,父程序PID(304),路径:C:\WINDOWS\System32\cmd.exe,命令行:"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\SelfDel.bat" ,隐藏(NO),挂起(NO),成功(YES)
------------(400)子程序,父程序PID(252),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {60624537-57ED-4F8C-B7E9-64D21A4C7EB8} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
----------------线程(860)
--------------------文件操作(创建):目标文件:C:\WINDOWS\System32\inahdpnc.dll,隐藏(NO),成功(YES)
--------------------文件操作(创建):目标文件:C:\Documents and Settings\Administrator\Local Settings\Temp\SelfDel.bat,隐藏(NO),成功(YES)
--------------------线程(728)
------------------------文件操作(创建):目标文件:C:\WINDOWS\System32\hpffbbkb.dll,隐藏(NO),成功(YES)
--------------------(848)子程序,父程序PID(860),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {8531D1F2-A1FF-4FDD-B78B-F4823749A45A} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
--------------------(196)子程序,父程序PID(860),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {A065C44A-8829-4C86-A090-0FD0E7ADD9E2} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
--------------------(1712)子程序,父程序PID(860),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {0AD59034-B6AA-4308-BAA3-79DDF0641001} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
--------------------(1648)子程序,父程序PID(860),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {F35A5D41-CB5A-40CE-B94A-43E87B16D22F} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
--------------------(1596)子程序,父程序PID(860),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {60624537-57ED-4F8C-B7E9-64D21A4C7EB8} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
--------------------(576)子程序,父程序PID(860),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {9EB91889-7C32-447D-8FCE-1EB5FC103286} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
--------------------(756)子程序,父程序PID(860),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {C725FB98-CA70-4D79-91F5-16862951A304} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
--------------------(1660)子程序,父程序PID(860),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {27A1D97C-F8C2-4514-B8B1-5B34884ADE5E} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
--------------------(1844)子程序,父程序PID(860),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {65EC7475-5492-4429-B5C7-93566CAB0930} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
--------------------(1124)子程序,父程序PID(860),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {D2656F6A-A764-47AE-9810-2631B5CC218A} /I {00000000-0000-0000-C000-000000000046} /X 0x401,隐藏(NO),挂起(NO),成功(YES)
--------------------(1012)子程序,父程序PID(860),路径:C:\WINDOWS\System32\verclsid.exe,命令行:/S /C {B8F46E86-F3E6-40F9-91D7- |