請問木馬程式 是怎樣的

看板NetSecurity (資安 資訊安全)作者時間20年前 (2005/12/29 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
我的木馬程式抓到好多 很奇怪 以下是清單 煩請幫我看看 Lavasoft Ad-aware Personal Build 6.181 Logfile created on :2005年12月22日 上午 07:32:09 Created with Ad-aware Personal, free for private use. Using reference-file :01R347 26.10.2004 ______________________________________________________ Ad-aware Settings ========================= Set : Activate in-depth scan (Recommended) Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep scan registry 2005-12-22 上午 07:32:09 - Scan started. (Smart mode) Listing running processes 秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤 #:1 [smss.exe] FilePath : \SystemRoot\System32\ ThreadCreationTime : 2005-12-21 下午 10:19:48 BasePriority : Normal #:2 [winlogon.exe] FilePath : \??\C:\WINDOWS\system32\ ThreadCreationTime : 2005-12-21 下午 10:19:51 BasePriority : High #:3 [services.exe] FilePath : C:\WINDOWS\system32\ ThreadCreationTime : 2005-12-21 下午 10:19:51 BasePriority : Normal FileSize : 105 KB FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 Copyright : (C) Microsoft Corporation. All rights reserved. CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe OriginalFilename : services.exe ProductName : Microsoft(R) Windows(R) Operating System Created on : 2004/8/4 上午 04:00:00 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2004/8/4 上午 04:00:00 #:4 [lsass.exe] FilePath : C:\WINDOWS\system32\ ThreadCreationTime : 2005-12-21 下午 10:19:51 BasePriority : Normal FileSize : 13 KB FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 Copyright : c Microsoft Corporation. All rights reserved. CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe OriginalFilename : lsass.exe ProductName : MicrosoftR WindowsR Operating System Created on : 2004/8/4 上午 04:00:00 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2004/8/4 上午 04:00:00 #:5 [svchost.exe] FilePath : C:\WINDOWS\system32\ ThreadCreationTime : 2005-12-21 下午 10:19:51 BasePriority : Normal FileSize : 14 KB FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 Copyright : c Microsoft Corporation. All rights reserved. CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe OriginalFilename : svchost.exe ProductName : MicrosoftR WindowsR Operating System Created on : 2004/8/4 上午 04:00:00 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2004/8/4 上午 04:00:00 #:6 [svchost.exe] FilePath : C:\WINDOWS\System32\ ThreadCreationTime : 2005-12-21 下午 10:19:52 BasePriority : Normal FileSize : 14 KB FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 Copyright : c Microsoft Corporation. All rights reserved. CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe OriginalFilename : svchost.exe ProductName : MicrosoftR WindowsR Operating System Created on : 2004/8/4 上午 04:00:00 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2004/8/4 上午 04:00:00 #:7 [ccsetmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ThreadCreationTime : 2005-12-21 下午 10:19:54 BasePriority : Normal FileSize : 161 KB FileVersion : 103.0.3.8 ProductVersion : 103.0.3.8 Copyright : Copyright (c) 2000-2004 Symantec Corporation. All rights reserved. CompanyName : Symantec Corporation FileDescription : Symantec Settings Manager Service InternalName : ccSetMgr OriginalFilename : ccSetMgr.exe ProductName : Client and Host Security Platform Created on : 2004/8/21 上午 06:25:22 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2005/1/24 上午 10:22:46 #:8 [sndsrvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ThreadCreationTime : 2005-12-21 下午 10:19:54 BasePriority : Normal FileSize : 201 KB FileVersion : 5.5.1.6 ProductVersion : 5.5 Copyright : Copyright 2002, 2003, 2004 Symantec Corporation CompanyName : Symantec Corporation FileDescription : Network Driver Service InternalName : SndSrvc OriginalFilename : SndSrvc.exe ProductName : Symantec Security Drivers Created on : 2005/4/5 上午 03:17:22 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2005/4/5 上午 03:17:22 #:9 [spbbcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\SPBBC\ ThreadCreationTime : 2005-12-21 下午 10:19:54 BasePriority : Normal FileSize : 169 KB FileVersion : 1,0,1,47 ProductVersion : 1,0,1,47 Copyright : Copyright (c) 2004 Symantec Corporation. All rights reserved. CompanyName : Symantec Corporation FileDescription : SPBBC Service InternalName : SPBBCSvc OriginalFilename : SPBBCSvc.exe ProductName : SPBBC Created on : 2004/7/21 上午 08:24:00 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2004/7/21 上午 08:24:00 #:10 [ccevtmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ThreadCreationTime : 2005-12-21 下午 10:19:55 BasePriority : Normal FileSize : 193 KB FileVersion : 103.0.3.8 ProductVersion : 103.0.3.8 Copyright : Copyright (c) 2000-2004 Symantec Corporation. All rights reserved. CompanyName : Symantec Corporation FileDescription : Symantec Event Manager Service InternalName : ccEvtMgr OriginalFilename : ccEvtMgr.exe ProductName : Client and Host Security Platform Created on : 2004/8/21 上午 06:24:50 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2005/1/24 上午 10:16:18 #:11 [spoolsv.exe] FilePath : C:\WINDOWS\system32\ ThreadCreationTime : 2005-12-21 下午 10:19:55 BasePriority : Normal FileSize : 56 KB FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) ProductVersion : 5.1.2600.2696 Copyright : c Microsoft Corporation. All rights reserved. CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe OriginalFilename : spoolsv.exe ProductName : MicrosoftR WindowsR Operating System Created on : 2004/8/4 上午 04:00:00 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2005/6/10 下午 11:53:32 #:12 [navapsvc.exe] FilePath : C:\Program Files\Norton AntiVirus\ ThreadCreationTime : 2005-12-21 下午 10:20:02 BasePriority : Normal FileSize : 173 KB FileVersion : 11.0.9.16 ProductVersion : 11.0.9 Copyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright c 2004 Symantec Corporation. All rights reserved. CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Auto-Protect Service InternalName : NAVAPSVC OriginalFilename : NAVAPSVC.EXE ProductName : Norton AntiVirus Created on : 2004/9/1 上午 07:51:40 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2005/1/24 上午 10:30:32 #:13 [npfmntor.exe] FilePath : C:\Program Files\Norton AntiVirus\IWP\ ThreadCreationTime : 2005-12-21 下午 10:20:02 BasePriority : Normal FileSize : 45 KB FileVersion : 11.0.9.16 ProductVersion : 11.0.9 Copyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright c 2004 Symantec Corporation. All rights reserved. CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Firewall Install Monitor InternalName : NPFMonitor OriginalFilename : NPFMonitor.EXE ProductName : Norton AntiVirus Created on : 2004/9/1 上午 07:53:22 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2005/1/24 上午 10:37:04 #:14 [symlcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\ ThreadCreationTime : 2005-12-21 下午 10:20:10 BasePriority : Normal FileSize : 800 KB FileVersion : 1, 8, 54, 478 ProductVersion : 1, 8, 54, 478 Copyright : Copyright (C) 2003 CompanyName : Symantec Corporation FileDescription : Symantec Core Component InternalName : symlcsvc OriginalFilename : symlcsvc.exe ProductName : Symantec Core Component Created on : 2005/12/2 上午 08:51:28 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2005/12/2 上午 08:51:30 #:15 [explorer.exe] FilePath : C:\WINDOWS\ ThreadCreationTime : 2005-12-21 下午 10:20:16 BasePriority : Normal FileSize : 954 KB FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 Copyright : (C) Microsoft Corporation. All rights reserved. CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer OriginalFilename : EXPLORER.EXE ProductName : Microsoft(R) Windows(R) Operating System Created on : 2004/8/4 上午 04:00:00 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2004/8/4 上午 04:00:00 #:16 [vttimer.exe] FilePath : C:\WINDOWS\system32\ ThreadCreationTime : 2005-12-21 下午 10:20:18 BasePriority : Normal FileSize : 48 KB FileVersion : 1.100.2004.0115 ProductVersion : 1.100.2004.0115 Copyright : Copyright (C) 2001-2004 S3 Graphics, Inc. CompanyName : S3 Graphics, Inc. InternalName : S3Timer ProductName : S3 Graphics, Inc. Utilities Created on : 2004/10/20 下午 01:05:16 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2004/1/15 下午 12:33:44 #:17 [soundman.exe] FilePath : C:\WINDOWS\ ThreadCreationTime : 2005-12-21 下午 10:20:18 BasePriority : Normal FileSize : 64 KB FileVersion : 5.1.0.22 ProductVersion : 5.1.0.22 Copyright : Copyright (c) 2001-2003 Realtek Semiconductor Corp. CompanyName : Realtek Semiconductor Corp. FileDescription : Realtek Sound Manager InternalName : ALSMTray OriginalFilename : ALSMTray.exe ProductName : Realtek Sound Manager Created on : 2004/10/20 下午 01:05:59 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2004/1/8 下午 06:54:06 #:18 [pdvdserv.exe] FilePath : C:\Program Files\CyberLink\PowerDVD\ ThreadCreationTime : 2005-12-21 下午 10:20:18 BasePriority : Normal FileSize : 32 KB FileVersion : 5.00.0000 ProductVersion : 5.00.0000 Copyright : Copyright (c) CyberLink Corp. 1997-2002 CompanyName : Cyberlink Corp. FileDescription : PowerDVD RC Service InternalName : PowerDVD RC Service OriginalFilename : PDVDSERV.EXE ProductName : PowerDVD Created on : 2004/10/27 上午 08:23:38 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2003/10/31 上午 11:42:40 #:19 [ccapp.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ThreadCreationTime : 2005-12-21 下午 10:20:18 BasePriority : Normal FileSize : 57 KB FileVersion : 103.0.3.8 ProductVersion : 103.0.3.8 Copyright : Copyright (c) 2000-2004 Symantec Corporation. All rights reserved. CompanyName : Symantec Corporation FileDescription : Symantec User Session InternalName : ccApp OriginalFilename : ccApp.exe ProductName : Client and Host Security Platform Created on : 2004/8/21 上午 06:24:32 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2005/1/24 上午 10:12:46 #:20 [apdproxy.exe] FilePath : C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\ ThreadCreationTime : 2005-12-21 下午 10:20:18 BasePriority : Normal FileSize : 56 KB FileVersion : 3.0.0.52115 ProductVersion : 3.0.0.52115 Copyright : c 2005 Adobe Systems Incorporated CompanyName : Adobe Systems Incorporated FileDescription : Adobe Photoshop Album Starter Edition 3.0 component InternalName : Adobe Photoshop Album Starter Edition ProductName : Adobe Photoshop Album Starter Edition Created on : 2005/7/21 上午 08:51:48 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2005/7/21 上午 08:51:48 #:21 [ctfmon.exe] FilePath : C:\WINDOWS\system32\ ThreadCreationTime : 2005-12-21 下午 10:20:18 BasePriority : Normal FileSize : 15 KB FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 Copyright : c Microsoft Corporation. All rights reserved. CompanyName : Microsoft Corporation FileDescription : CTF Loader InternalName : CTFMON OriginalFilename : CTFMON.EXE ProductName : MicrosoftR WindowsR Operating System Created on : 2004/8/4 上午 04:00:00 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2004/8/4 上午 04:00:00 #:22 [raid_tool.exe] FilePath : C:\Program Files\VIA\RAID\ ThreadCreationTime : 2005-12-21 下午 10:20:18 BasePriority : Normal FileSize : 548 KB FileVersion : 2, 0, 0, 0 ProductVersion : 2, 0, 0, 0 Copyright : Copyright (C) 2002 CompanyName : VIA FileDescription : VIA RAID Tool InternalName : raid_tool OriginalFilename : raid_tool.EXE ProductName : VIA RAID Tool Created on : 2004/10/20 下午 01:07:16 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2003/7/31 上午 05:59:14 #:23 [abmtsr.exe] FilePath : C:\Program Files\Ulead Systems\Ulead PhotoImpact 5 Bundled Edition\ ThreadCreationTime : 2005-12-21 下午 10:20:18 BasePriority : Normal FileSize : 36 KB FileVersion : 5.0 ProductVersion : 5.0 Copyright : Copyright (c) 1992-1999. Ulead Systems, Inc. CompanyName : Ulead Systems, Inc. FileDescription : PhotoImpact Album InternalName : ALBUM OriginalFilename : ALBUM.EXE ProductName : PhotoImpact Bundled Ed. Created on : 2004/10/27 上午 08:15:59 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 1999/9/9 上午 09:53:54 #:24 [svchost.exe] FilePath : C:\WINDOWS\system32\ ThreadCreationTime : 2005-12-21 下午 10:20:32 BasePriority : Normal FileSize : 14 KB FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 Copyright : c Microsoft Corporation. All rights reserved. CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe OriginalFilename : svchost.exe ProductName : MicrosoftR WindowsR Operating System Created on : 2004/8/4 上午 04:00:00 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2004/8/4 上午 04:00:00 #:25 [iexplore.exe] FilePath : C:\Program Files\Internet Explorer\ ThreadCreationTime : 2005-12-21 下午 10:55:37 BasePriority : Normal FileSize : 91 KB FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 Copyright : (C) Microsoft Corporation. All rights reserved. CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore OriginalFilename : IEXPLORE.EXE ProductName : Microsoft(R) Windows(R) Operating System Created on : 2004/10/20 下午 12:52:14 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2004/8/4 下午 12:00:00 #:26 [conime.exe] FilePath : C:\WINDOWS\system32\ ThreadCreationTime : 2005-12-21 下午 11:10:55 BasePriority : Normal FileSize : 27 KB FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 Copyright : c Microsoft Corporation. All rights reserved. CompanyName : Microsoft Corporation FileDescription : Console IME InternalName : Console OriginalFilename : CONIME.EXE ProductName : MicrosoftR WindowsR Operating System Created on : 2004/8/4 上午 04:00:00 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2004/8/4 上午 04:00:00 #:27 [msmsgs.exe] FilePath : C:\Program Files\Messenger\ ThreadCreationTime : 2005-12-21 下午 11:31:22 BasePriority : Normal FileSize : 1654 KB FileVersion : 4.7.3001 ProductVersion : Version 4.7.3001 Copyright : Copyright (c) Microsoft Corporation 2004 CompanyName : Microsoft Corporation FileDescription : Windows Messenger InternalName : msmsgs OriginalFilename : msmsgs.exe ProductName : Messenger Created on : 2004/10/20 下午 12:51:01 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2004/10/13 下午 04:24:38 #:28 [ad-aware.exe] FilePath : C:\PROGRA~1\LAVASOFT\AD-AWA~1\ ThreadCreationTime : 2005-12-21 下午 11:31:56 BasePriority : Normal FileSize : 668 KB FileVersion : 6.0.1.181 ProductVersion : 6.0.0.0 Copyright : Copyright c Lavasoft Sweden CompanyName : Lavasoft Sweden FileDescription : Ad-aware 6 core application InternalName : Ad-aware.exe OriginalFilename : Ad-aware.exe ProductName : Lavasoft Ad-aware Plus Created on : 2005/12/14 下午 01:15:19 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2003/7/12 下午 01:00:20 Memory scan result : 秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤 New objects : 0 Objects found so far: 0 Started registry scan 秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤 Registry scan result : 秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤 New objects : 0 Objects found so far: 0 Started deep registry scan 秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤 Deep registry scan result : 秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤 New objects : 0 Objects found so far: 0 秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤 Tracking Cookie Object recognized! Type : File Data : user@atdmt[2].txt Object : C:\Documents and Settings\user\Cookies\ Created on : 2005/12/21 下午 01:51:36 Last accessed : 2005/12/21 下午 04:00:00 Last modified : 2005/12/21 下午 01:51:38 秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤 Deep scanning and examining files (C:) 秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤 Performing conditional scans.. 秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤 Conditional scan result: 秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤 New objects : 0 Objects found so far: 1 上午 07:33:50 Scan complete Summary of this scan 秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤秤 Total scanning time :00:01:40:750 Objects scanned :44454 Objects identified :1 Objects ignored :0 New objects :1 ---------------------------------------------- 樓上的 誰跟你網路的芳鄰呀^^ 你看的到我的 我看不到你的 這很好 有天我會親自登門拜訪 看你的桌面放的是什麼照片 妳廳的音樂是什麼 加油了 偽別人而活 不是件好事 -- ※ 來源:‧杏林綠意 passion.tmu.edu.tw‧[FROM: 61-230-124-62.dynami]
文章代碼(AID): #13ijBy00 (NetSecurity)
文章代碼(AID): #13ijBy00 (NetSecurity)