查看: 4811|回复: 34
收起左侧

[病毒样本] 12.exe过毒霸

  [复制链接]
hddu
发表于 2010-12-29 13:14:54 | 显示全部楼层 |阅读模式
12.exe过毒霸

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
rasis
发表于 2010-12-29 13:26:06 | 显示全部楼层
ess

2010-12-29 13:25:05        HTTP 过滤器        文件        http://bbs.kafan.cn/forum-attach ... UxfDI0MzM4Mg==.html        Win32/TrojanDropper.Agent.PBO 特洛伊木马 的变种                RASIS\Administrator        通过应用程序访问 web 时检测到威胁: D:\Program Files\FireFox\firefox.exe.
fatezero
发表于 2010-12-29 13:27:30 | 显示全部楼层
本帖最后由 fatezero 于 2010-12-29 13:29 编辑

KIS
Trojan-Dropper.Win32.Cadro.dxs

昨天的
llawliet
发表于 2010-12-29 14:18:21 | 显示全部楼层
GDATA 拒绝访问
lyqzg
发表于 2010-12-29 14:21:24 | 显示全部楼层
上报红伞
庄生
发表于 2010-12-29 14:22:30 | 显示全部楼层
360WD报

ESS秒杀
我是新手
发表于 2010-12-29 14:23:20 | 显示全部楼层
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\mfc42.dll C:\WINDOWS\system32\mfc42.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\msvcp60.dll C:\WINDOWS\system32\msvcp60.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\setupapi.dll C:\WINDOWS\system32\setupapi.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\imm32.dll C:\WINDOWS\system32\imm32.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\mfc42loc.dll C:\WINDOWS\system32\mfc42loc.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\Program Files\Common Files\Kingsoft\kiscommon\security\ksde\kisdcom.dll C:\Program Files\Common Files\Kingsoft\kiscommon\security\ksde\kisdcom.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建文件C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\ C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建文件C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\2.tmp C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\2.tmp
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写文件C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\2.tmp C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\2.tmp
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建文件C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\_uninstall C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\_uninstall
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建文件C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\tmp.exe.tmp C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\tmp.exe.tmp
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写文件C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\tmp.exe.tmp C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\tmp.exe.tmp
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\cabinet.dll C:\WINDOWS\system32\cabinet.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写文件C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\tmp.exe C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\tmp.exe
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建文件C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\tmp.exe C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\tmp.exe
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe删除文件C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\tmp.exe.tmp C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\tmp.exe.tmp
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写文件C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\_uninstall C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\_uninstall
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe删除文件C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\2.tmp C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\2.tmp
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建文件C:\KSafeBox\80D10EC6\windows\temp\tmp.exe C:\KSafeBox\80D10EC6\windows\temp\tmp.exe
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe重命名C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\tmp.exe C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\tmp.exe
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\uxtheme.dll C:\WINDOWS\system32\uxtheme.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件D:\金山\卫士\ksfmon.dll D:\金山\卫士\ksfmon.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\MSCTF.dll C:\WINDOWS\system32\MSCTF.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\clbcatq.dll C:\WINDOWS\system32\clbcatq.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\comres.dll C:\WINDOWS\system32\comres.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe打开设备\Device\MountPointManager \Device\MountPointManager
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6 HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500 HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\linkinfo.dll C:\WINDOWS\system32\linkinfo.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\ntshrui.dll C:\WINDOWS\system32\ntshrui.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\atl.dll C:\WINDOWS\system32\atl.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe加载库文件C:\WINDOWS\system32\netapi32.dll C:\WINDOWS\system32\netapi32.dll
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe打开服务LanmanServer LanmanServer
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe发送消息C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\ctfmon.exe
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建文件C:\KSafeBox\80D10EC6\Documents and Settings\All Users\「开始」菜单\程序\启动\ktv.lnk C:\KSafeBox\80D10EC6\Documents and Settings\All Users\「开始」菜单\程序\启动\ktv.lnk
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\80D10EC6\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写注册表HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe写文件C:\KSafeBox\80D10EC6\Documents and Settings\All Users\「开始」菜单\程序\启动\ktv.lnk C:\KSafeBox\80D10EC6\Documents and Settings\All Users\「开始」菜单\程序\启动\ktv.lnk
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe删除文件C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\_uninstall C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb\_uninstall
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe删除文件C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb C:\KSafeBox\80D10EC6\Documents and Settings\Administrator\Local Settings\Temp\daszkmb
2010-12-29 14:22:08 C:\Documents and Settings\Administrator\桌面\12.exe发送消息C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\ctfmon.exe
2010-12-29 14:22:08 结束进程C:\Documents and Settings\Administrator\桌面\12.exe C:\Documents and Settings\Administrator\桌面\12.exe



MPAV杀,金山报未知
3好流氓
发表于 2010-12-29 15:10:24 | 显示全部楼层
卡巴拦截下载...
萧剑
发表于 2010-12-29 15:27:08 | 显示全部楼层


TO COMODO
Humhook
发表于 2010-12-29 15:42:00 | 显示全部楼层
回复 7楼 我是新手 的帖子

这么详细  用什么工具测试的?
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-6-14 18:39 , Processed in 0.132227 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表