本帖最后由 willjjyu 于 2010.8.2 11:47 编辑
- 全部过程 (25)
- Process ID 0, File Name: (SystemIdle),
- Process ID 4, File Name: (System),
- Process ID 224, File Name: C:\WINDOWS\system32\cmd.exe, File Name Hash: 2751DD6A00570674F0080506F4B6C600B64FDB50.
- Process ID 308, File Name: C:\WINDOWS\System32\smss.exe, File Name Hash: 33A0AB030064EFA6C69B00AD18ED030054CE3826.
- Process ID 364, File Name: C:\WINDOWS\system32\cmd.exe /c C:\DOCUME~1\Dave\LOCALS~1\Temp\tmpb80dc665.bat, File Name Hash:2751DD6A00570674F0080506F4B6C600B64FDB50.
- Process ID 428, File Name: C:\WINDOWS\system32\csrss.exe, File Name Hash: B4E7351200C6D8C218E800665DD0AE001975146F.
- Process ID 452, File Name: C:\WINDOWS\system32\winlogon.exe, File Name Hash: 65AC26F6009EAAB8C01307D21BFA850005C731B9.
- Process ID 504, File Name: C:\WINDOWS\system32\services.exe, File Name Hash: 2C560F210066FD4CA85C016C25DE39002D329A6C.
- Process ID 516, File Name: C:\WINDOWS\system32\lsass.exe, File Name Hash: 09DB5EC900AF6D2D3445003B3C2E07008DAECC19.
- Process ID 664, File Name: C:\WINDOWS\system32\svchost.exe, File Name Hash: 52BDB1F1005527D0384D00B1B6718300527EEB16.
- Process ID 744, File Name: C:\WINDOWS\system32\svchost.exe, File Name Hash: 52BDB1F1005527D0384D00B1B6718300527EEB16.
- Process ID 780, File Name: C:\WINDOWS\System32\svchost.exe, File Name Hash: 52BDB1F1005527D0384D00B1B6718300527EEB16.
- Process ID 852, File Name: C:\WINDOWS\system32\svchost.exe, File Name Hash: 52BDB1F1005527D0384D00B1B6718300527EEB16.
- Process ID 932, File Name: C:\WINDOWS\system32\svchost.exe, File Name Hash: 52BDB1F1005527D0384D00B1B6718300527EEB16.
- Process ID 1112, File Name: C:\Documents and Settings\Dave\Application Data\Woyqy\fakue.exe, File Name Hash: 33C29C7400B37D5834BB02990540530056CA390E.
- Process ID 1136, File Name: C:\WINDOWS\Explorer.EXE, File Name Hash: 7BA51796002B8BEEC6F00FDC583A42008EE45077.
- Process ID 1288, File Name: C:\WINDOWS\system32\spoolsv.exe, File Name Hash: 2C3E540B00AFB573E240000320EF83001114DA67.
- Process ID 1416, File Name: C:\WINDOWS\system32\cmd.exe, File Name Hash: 2751DD6A00570674F0080506F4B6C600B64FDB50.
- Process ID 1584, File Name: C:\WINDOWS\system32\wuauclt.exe, File Name Hash: 5D9EF4ECE0722577D09600DE168DCC00EF2F8802.
- Process ID 1628, File Name: C:\69147381.exe, File Name Hash: hash_error.
- Process ID 1840, File Name: C:\WINDOWS\system32\wbem\wmiprvse.exe, File Name Hash: B38ABA89005EF55F549603092FD48400AE03A0D3.
- Process ID 1916, File Name: C:\WINDOWS\system32\wscntfy.exe, File Name Hash: 8FBFA6FA00E6E09B3694001AFC0EFA001CA5DA83.
- Process ID 1956, File Name: C:\WINDOWS\System32\alg.exe, File Name Hash: B789899500A84BB2AEC2005EDE65FA004F6B7ADA.
- Process ID 2032, File Name: C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe, File Name Hash: D6ADD7F570B8CCAB8BE800659CBCA80027D54BA7.
- Process ID 2044, File Name: C:\WINDOWS\system32\ctfmon.exe, File Name Hash: CB94C76000E5509F3C0D00C310E23300C6DC8A05.
- 打开的文件
- File: \\.\PIPE\lsarpc
- File Type: namedpipe
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: SECURITY_ANONYMOUS
- Quantity: 4
- File: C:\69147381.exe
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ
- Flags: SECURITY_ANONYMOUS
- Quantity: 2
- File: C:\Documents and Settings\Dave\Application Data
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_DELETE FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: SECURITY_ANONYMOUS
- File: C:\Documents and Settings\Dave\Application Data\Woyqy\fakue.exe
- File Type: file
- Source File Hash: 33C29C7400B37D5834BB02990540530056CA390E
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS FILE_WRITE_ATTRIBUTES
- Share Access: FILE_SHARE_READ
- Flags: SECURITY_ANONYMOUS
- Stored as: 4702b064ec87544b635e2df7c43910d8.exe
- File: C:\Documents and Settings\Dave\Application Data\Woyqy
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS FILE_WRITE_ATTRIBUTES
- Share Access: FILE_SHARE_READ
- Flags: SECURITY_ANONYMOUS
- File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.oxe
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS FILE_WRITE_ATTRIBUTES
- Share Access: FILE_SHARE_READ
- Flags: SECURITY_ANONYMOUS
- File: C:\Documents and Settings\Dave\Application Data\Miifny
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS FILE_WRITE_ATTRIBUTES
- Share Access: FILE_SHARE_READ
- Flags: SECURITY_ANONYMOUS
- File: C:\WINDOWS\AppPatch\sysmain.sdb
- File Type: file
- Source File Hash: 178984DA5623C3D05AF212C03BD2D300E4481614
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS FILE_READ_ATTRIBUTES
- Share Access: FILE_SHARE_READ
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- Quantity: 2
- File: C:\WINDOWS\AppPatch\systest.sdb
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS FILE_READ_ATTRIBUTES
- Share Access: FILE_SHARE_READ
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- Quantity: 2
- File: \Device\NamedPipe\ShimViewer
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS FILE_WRITE_ACCESS FILE_WRITE_DATA FILE_ADD_FILE FILE_ADD_SUBDIRECTORY FILE_APPEND_DATA FILE_CREATE_PIPE_INSTANCE FILE_WRITE_EA FILE_WRITE_ATTRIBUTES
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- Quantity: 2
- File: C:\Documents and Settings\Dave\Application Data\Woyqy\
- File Type: file
- Source File Hash: hash_error
- Desired Access: FILE_ANY_ACCESS FILE_READ_ACCESS FILE_READ_DATA FILE_LIST_DIRECTORY
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: SECURITY_ANONYMOUS
- File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.dat
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ
- Flags: SECURITY_ANONYMOUS
- File: C:\WINDOWS\system32\
- File Type: file
- Source File Hash: hash_error
- Desired Access: FILE_ANY_ACCESS FILE_READ_ACCESS FILE_READ_DATA FILE_LIST_DIRECTORY
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: SECURITY_ANONYMOUS
- 创建的文件
- File: C:\Documents and Settings\Dave\Application Data\Woyqy\fakue.exe
- File Type: file
- Source File Hash: 33C29C7400B37D5834BB02990540530056CA390E
- Creation/Distribution: CREATE_ALWAYS
- Desired Access: FILE_ANY_ACCESS
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- Stored as: 4702b064ec87544b635e2df7c43910d8.exe
- File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.oxe
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: CREATE_ALWAYS
- Desired Access: FILE_ANY_ACCESS
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- File: C:\Documents and Settings\Dave\Application Data\Woyqy\fakue.exe
- File Type: file
- Source File Hash: 33C29C7400B37D5834BB02990540530056CA390E
- Creation/Distribution: CREATE_ALWAYS
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- Stored as: 4702b064ec87544b635e2df7c43910d8.exe
- File: C:\DOCUME~1\Dave\LOCALS~1\Temp\tmpb80dc665.bat
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: CREATE_ALWAYS
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- Quantity: 2
- Stored as: c28e784cea35faeb9387cc516e43852b.bat
- Process # 2, (ID: 1112).
- 打开的文件
- File: \\.\PIPE\lsarpc
- File Type: namedpipe
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: SECURITY_ANONYMOUS
- File: C:\Documents and Settings\Dave\Application Data\Woyqy\fakue.exe
- File Type: file
- Source File Hash: 33C29C7400B37D5834BB02990540530056CA390E
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ
- Flags: SECURITY_ANONYMOUS
创建/打开 的文件...- File Type: file
- Desired Access: FILE_ANY_ACCESS
- Flags: SECURITY_ANONYMOUS
- Process # 3, (ID: 1136).
- 打开的文件
- File: \\.\PIPE\lsarpc
- File Type: namedpipe
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: SECURITY_ANONYMOUS
- File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.dat
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ
- Flags: SECURITY_ANONYMOUS
- File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.oxe
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_DELETE FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: SECURITY_ANONYMOUS
- Stored as: d4f2ce821b597e2e6f709671144ec64c.oxe
- File: \\.\PIPE\ROUTER
- File Type: namedpipe
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: SECURITY_ANONYMOUS
- Quantity: 2
- File: c:\autoexec.bat
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- Quantity: 5
- File: \\.\Ip6
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: SECURITY_ANONYMOUS
- Quantity: 5
- File: \\.\Ip6
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.tmp
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_DELETE FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: SECURITY_ANONYMOUS
- 创建、打开的文件
- File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.oxe
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_ALWAYS
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- Stored as: d4f2ce821b597e2e6f709671144ec64c.oxe
- File: \Device\RasAcd
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_ALWAYS
- Desired Access: FILE_ANY_ACCESS FILE_READ_ACCESS FILE_READ_DATA FILE_LIST_DIRECTORY FILE_WRITE_ACCESS FILE_WRITE_DATA FILE_ADD_FILE
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- Quantity: 5
- File: \Device\Tcp6
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_ALWAYS
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- Quantity: 2
- File: \Device\Ip6
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_ALWAYS
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- File: \Device\Ip6
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_ALWAYS
- Desired Access: FILE_ANY_ACCESS FILE_READ_ACCESS FILE_READ_DATA FILE_LIST_DIRECTORY FILE_WRITE_ACCESS FILE_WRITE_DATA FILE_ADD_FILE
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- File: \Device\Tcp
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_ALWAYS
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- File: \Device\NetBT_Tcpip_{AC33AA7D-86BB-40D5-BEF6-51C33880EAF1}
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_ALWAYS
- Desired Access: FILE_ANY_ACCESS FILE_READ_ACCESS FILE_READ_DATA FILE_LIST_DIRECTORY FILE_WRITE_ACCESS FILE_WRITE_DATA FILE_ADD_FILE
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- Quantity: 2
- File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.tmp
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_ALWAYS
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- 创建的文件
- File: C:\DOCUME~1\Dave\LOCALS~1\Temp\tmp6999c57b\d45hr.exe
- File Type: file
- Source File Hash: C303D0FC000F1FA7D099001234D9BC00F5896FA6
- Creation/Distribution: CREATE_ALWAYS
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- Process # 5, (ID: 1916).
- 打开的文件
- File: \\.\PIPE\lsarpc
- File Type: namedpipe
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: SECURITY_ANONYMOUS
- File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.dat
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ
- Flags: SECURITY_ANONYMOUS
- Process # 6, (ID: 2032).
- 打开的文件
- File: \\.\PIPE\lsarpc
- File Type: namedpipe
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: SECURITY_ANONYMOUS
- File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.dat
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ
- Flags: SECURITY_ANONYMOUS
- Process # 7, (ID: 2044).
- 打开的文件
- File: \\.\PIPE\lsarpc
- File Type: namedpipe
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: SECURITY_ANONYMOUS
- File: C:\Documents and Settings\Dave\Application Data\Miifny\cyipa.dat
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ
- Flags: SECURITY_ANONYMOUS
- Process # 8, (ID: 364).
- 打开的文件
- File: C:\DOCUME~1\Dave\LOCALS~1\Temp\tmpb80dc665.bat
- File Type: file
- Source File Hash: hash_error
- Creation/Distribution: OPEN_EXISTING
- Desired Access: FILE_ANY_ACCESS
- Share Access: FILE_SHARE_READ FILE_SHARE_WRITE
- Flags: FILE_ATTRIBUTE_NORMAL SECURITY_ANONYMOUS
- Quantity: 6
|