文档库 最新最全的文档下载
当前位置:文档库 › 360保险箱诊断报告(2011-07-25)

360保险箱诊断报告(2011-07-25)

检测时间:2011-07-25 20:19
操作系统版本:Microsoft Windows XP
保险箱:C:\Program Files\360Safebox\360Safebox.exe - 4.1.0.1005
360安全卫士:C:\Program Files\360\360Safe\360safe.exe - 7.5.0.1103
! 发现了木马对保险箱的镜像劫持, 已经修复!

===========================================================

-->驱动程序的版本号<--

C:\Program Files\360Safebox\HookPort.sys - 1.0.0.1008
C:\Program Files\360Safebox\EfiMon.sys - 1.0.0.1004
C:\Program Files\360Safebox\AntiDrv.sys - 4.1.0.1010
C:\WINDOWS\system32\Drivers\AntiDrv.sys - 4.1.0.1010
C:\WINDOWS\system32\Drivers\HookPort.sys - 1.1.0.1001
C:\WINDOWS\system32\Drivers\360selfprotection.sys - 1.0.0.1074
C:\WINDOWS\system32\Drivers\EfiMon.sys - 1.0.0.1007

-->本地文件校验<--

文件"sysoptm.dll"版本号不匹配!本地版本:1.3.0.1001 正确版本:1.2.1.1011

-->配置文件:sprotect.ini<--

[main]
SoftProtect=1
ProtectType=1
Use360SE=1
EnableHotKey=0
UserFeels=1
OEMID=home
mid=a806605c41f3e4a5d20c266b4e705813
NeedProtectData=1
NeedProtectLog=1
WndMax=0
ShowLogWhenObjExit=0
IsFirstRun=0
UpdateTime=1310120199
UserType=1
modifyinject=1
modifyinjectsoft=1
modifyxunyou=1
recommendgameinterval=300
LastIconID=6
NeedUpdateGames=1
[scan]
QuickScan=1
SpecialScan=1
[FileDate]
ListPreDef.dat=3489088512
[tip]
ShowGameBoot=1
[Optimize]
type=2

-->配置文件:dpath.ini<--

[main]
datapath=C:\Program Files\360Safebox

-->黑白名单:ListBlackUser.dat<--

-->保护程序:ListUserDef.dat<--
MSN - C:\Program Files\Windows Live Messenger\Messenger\msnmsgr.exe
招商银行 -
工商银行 -
QQ游戏大厅 - C:\Program Files\腾讯游戏\QQGAME\QQGame.exe
穿越火线 - e:\crossfire\qqlogin.exe
地下城与勇士 - e:\地下城与勇士\start\dnfchina.exe
QQ飞车 - e:\qq飞车\qqspeedlauncher.exe
歪歪 - e:\yy-3.0\start.exe
腾讯QQ - C:\Program Files\Tencent\QQ\bin\QQ.exe
鹿鼎记 - e:\ldj\launch.exe
淘宝特卖 -
支付宝 -
360手机充值 -
360网游点卡 -
360游戏中心 -
游戏浏览器 -
彩票投注 -
360购物返利 -
Dota对战 -
网游加速 -


-->正在运行的进程信息<--

- - -
C:\WINDOWS\System32\smss.exe - 32D5D8666E082F567923DB579B5390FC - Microsoft Corporation - 5.1.2600.2180
C:\WINDOWS\system32\csrss.exe - 3502114E4CB83E491A80FC361C1DC7B7 - Microsoft Corporation - 5.1.2600.2180
C:\WINDOWS\system32\winlogon.exe - A5153E6B7B02545F789AF2FCD27FB325 - Microsoft Corporation - 5.1.2600.2180
C:\WINDOWS\system32\services.exe - 9CABF264CE1177CAFBBBA4B910A44C79 - Microsoft Corporation - 5.1.2600.2180
C:\WINDOWS\system32\lsass.exe - 891600E79C38249028F1BACC1C6CC5D2 - Microsoft Corporation - 5.1.2600.2180
C:\WINDOWS\system32\svchost.exe - A22D7B3594C381EFB3395A072725FE95 - Microsoft Corporation - 5.1.2600.2180
C:\WINDOWS\system32\svchost.exe - A22D7B3594C381EFB3395A072725FE95 - Microsoft Co

rporation - 5.1.2600.2180
C:\WINDOWS\System32\svchost.exe - A22D7B3594C381EFB3395A072725FE95 - Microsoft Corporation - 5.1.2600.2180
C:\WINDOWS\system32\svchost.exe - A22D7B3594C381EFB3395A072725FE95 - Microsoft Corporation - 5.1.2600.2180
C:\WINDOWS\system32\svchost.exe - A22D7B3594C381EFB3395A072725FE95 - Microsoft Corporation - 5.1.2600.2180
C:\WINDOWS\system32\spoolsv.exe - 38EBFAB700F1B22AE84FDD87BE6D1548 - Microsoft Corporation - 5.1.2600.3740
C:\WINDOWS\system32\nvsvc32.exe - 1D0F9EF8CEE12338EBC12626E7A460C6 - NVIDIA Corporation - 6.14.11.6501
C:\WINDOWS\system32\svchost.exe - A22D7B3594C381EFB3395A072725FE95 - Microsoft Corporation - 5.1.2600.2180
C:\WINDOWS\system32\ctfmon.exe - 4CC6277445D2D388A4CD827086A5F5F0 - Microsoft Corporation - 5.1.2600.2180
C:\WINDOWS\System32\alg.exe - A9DE20DF2C89B6B2FFDA0E6CD52A8599 - Microsoft Corporation - 5.1.2600.2180
C:\Program Files\Internet Explorer\iexplore.exe - - -
C:\WINDOWS\explorer.exe - 82B8373ED12A602820108F6154BF0C4C - Microsoft Corporation - 6.0.2900.2180
C:\WINDOWS\system32\2003ads6.exe - DF127752B05E618533CE9DB97DF2D0AD - -
C:\WINDOWS\services.exe - 65A70EC4649499399B50AC75D911A501 - Microsoft Corporation - 5.1.2600.2180
C:\WINDOWS\system32\87kciaodx.exe - BDE263540D521FA5FCD3B3A764AA919C - - 1.0.0.0
C:\WINDOWS\system32\id238.exe - 208CE6840C1B5AFEDFAD0606EFAA9C62 - 微软中国 - 1.0.0.0
C:\Program Files\Internet Explorer\iexplore.exe - - -
C:\WINDOWS\system32\Macromadendt\MsShellExt\behkor.exe - B88868CC7943CB8249E3DD6BCF03CEE9 - 深圳康欣科技有限公司 - 7.2.1225.2
C:\WINDOWS\system32\sf99.exe - 9F6AFAEE2A81A0F1F407159CE7C925C2 - -
C:\Program Files\Messenger\31.exe - E53928BB692566682C1B2624D541C40D - - 4.7.0.3001
C:\Program Files\Messenger\dmremote.exe - 6C02BD1A47A2F972AFD1252404F31F78 - - 4.7.0.3001
C:\WINDOWS\system32\sf99.exe - 9F6AFAEE2A81A0F1F407159CE7C925C2 - -
C:\WINDOWS\system32\Macromadendt\MsShellExt\behkor.exe - B88868CC7943CB8249E3DD6BCF03CEE9 - 深圳康欣科技有限公司 - 7.2.1225.2
C:\Program Files\Internet Explorer\iexplore.exe - - -
C:\WINDOWS\system32\S53Xj2D\deFxFOI.exe - B8B741BFBD187BB06EFFB15810AE261F - -
C:\WINDOWS\system32\Macromadendt\xbehkr.exe - B4A86CE39EE3A47889889379695BA494 - 北京合为四通科技有限公司 - 2.2.1007.3
C:\WINDOWS\system32\deFxFOI\S53Xj2D.exe - B8B741BFBD187BB06EFFB15810AE261F - -
C:\WINDOWS\system32\conime.exe - 30162FF3B6FE72A9799DFB496111FE02 - Microsoft Corporation - 5.1.2600.2180
C:\Program Files\san3550.exe - 279E9849C0CD49FE05A5610DE630998B - -
C:\WINDOWS\system32\RTRTNEI1.exe - B8B741BFBD187BB06EFFB15810AE261F - -
C:\WINDOWS\system32\RTRTNEI4.exe - B8B741BFBD187BB06EFFB15810AE261F - -
C:\Program Files\Thunder Network\Thunder\Program\Thunder.exe - EEB9AF8E54F406F28B55F550F8D77FC5 - 深圳市迅雷网络技术有限公司 - 7.1.8.2302
c:\program files\common files\thunder network\tp\ver1\1.1.2.67_1111\thunderplatform.exe - D7F16AA3CC92C030E5B18EC1C7467E54 -

深圳市迅雷网络技术有限公司 - 1.1.2.67
F:\Program Files\KuGou\KuGou2010\KuGoo.exe - 48AC65A729163AC9FF4B1598C72C8C2F - 酷狗音乐 - 6.2.27.563
F:\Program Files\KuGou\KuGou2010\kgdaemon.exe - 8D31E7C24FC5C01F1D655EE4B141B2F2 - 酷狗计算机科技有限公司 - 1.0.0.36
C:\Program Files\360Safebox\BoxChecker.exe - AEB551B379DC6ABCF796A74F2D8DF057 - - 1.0.0.1015

相关文档