|
limuyuan 考生

- 帖子
- 7
- 积分
- 8
- 金钱
- 93
- Z币
- 0
- 贡献
- 0
- 阅读权限
- 10
- 注册时间
- 2007-11-25
|
沙发
大 中
小 发表于 2007-11-25 07:04 只看该作者
正在运行的进程 分析方法:
这一项可以说是整个日志的主体部分,一般来说也是最长的一部分!(有时驱动可能会更长)虽然分析这一项时需要注意的事项并不多,但是一定要细心,还要有耐心!不要错过任何一个可能是病毒的项目! 这次用谁的日志好呢……这次就用我自己的好了……o(∩_∩)o...哈哈
Quote:
正在运行的进程 [PID: 712][SystemRootSystem32smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 776][??C:WINDOWSsystem32csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 292][C:WINDOWSsystem32ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [PID: 320][e:program files
ising
fwRfwMain.exe] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70] [e:program files
ising
fwRsGuiLib.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33] [e:program files
ising
fwRSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5] [e:program files
ising
fwRfwCtrl.dll] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11] [e:program files
ising
fwRsXML.dll] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2] [e:program files
ising
fwPngDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [C:DOCUME~1李牧原\LOCALS~1TempQqzo0.dll] [N/A, ] [PID: 1164][C:Program FilesATI TechnologiesATI.ACEcli.exe] [ATI Technologies Inc., 1.11.0.0] [C:WINDOWSsystem32mscoree.dll] [Microsoft Corporation, 1.1.4322.573] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322mscorwks.dll] [Microsoft Corporation, 1.1.4322.573] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322fusion.dll] [Microsoft Corporation, 1.1.4322.573] [c:windowsmicrosoft.netframeworkv1.1.4322mscorlib.dll] [Microsoft Corporation, 1.1.4322.573] [c:windowsassembly
ativeimages1_v1.1.4322mscorlib1.0.5000.0__b77a5c561934e089_422c3599mscorlib.dll] [N/A, ] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322mscorsn.dll] [Microsoft Corporation, 1.1.4322.573] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322MSCORJIT.DLL] [Microsoft Corporation, 1.1.4322.573] [c:windowsassemblygacsystem.windows.forms1.0.5000.0__b77a5c561934e089system.windows.forms.dll] [Microsoft Corporation, 1.1.4322.573] [c:windowsassembly
ativeimages1_v1.1.4322system.windows.forms1.0.5000.0__b77a5c561934e089_14cb2b7bsystem.windows.forms.dll] [N/A, ] [c:program filesati technologiesati.acecli.implementation.dll] [ATI Technologies Inc., 1.2.2114.465] [c:program filesati technologiesati.acelog.foundation.dll] [ATI Technologies Inc., 1.2.2026.29944] [c:program filesati technologiesati.acecli.foundation.dll] [ATI Technologies Inc., 1.2.2026.29944] [c:program filesati technologiesati.acelog.foundation.service.dll] [ATI Technologies Inc., 1.2.2114.464] [c:program filesati technologiesati.acelog.foundation.shared.dll] [ATI Technologies Inc., 1.2.2026.29970] [c:windowsassemblygacsystem1.0.5000.0__b77a5c561934e089system.dll] [Microsoft Corporation, 1.1.4322.573] [c:windowsassembly
ativeimages1_v1.1.4322system1.0.5000.0__b77a5c561934e089_96df10ffsystem.dll] [N/A, ] [c:program filesati technologiesati.acecli.foundation.xmanifestation.dll] [ATI Technologies Inc., 1.2.2114.464] [c:windowsassemblygacsystem.xml1.0.5000.0__b77a5c561934e089system.xml.dll] [Microsoft Corporation, 1.1.4322.573] [c:windowsassembly
ativeimages1_v1.1.4322system.xml1.0.5000.0__b77a5c561934e089_b39e651esystem.xml.dll] [N/A, ] [c:windowsassemblygacsystem.runtime.remoting1.0.5000.0__b77a5c561934e089system.runtime.remoting.dll] [Microsoft Corporation, 1.1.4322.573] [C:WINDOWSsystem32ldmedia4.dll] [N/A, ] [c:program filesati technologiesati.acecli.component.runtime.dll] [ATI Technologies Inc., 1.2.2114.465] [c:program filesati technologiesati.aceaem.foundation.dll] [ATI Technologies Inc., 1.2.2026.29944] [c:windowsassemblygacsystem.drawing1.0.5000.0__b03f5f7f11d50a3asystem.drawing.dll] [Microsoft Corporation, 1.1.4322.573] [c:windowsassembly
ativeimages1_v1.1.4322system.drawing1.0.5000.0__b03f5f7f11d50a3a_d3d144b1system.drawing.dll] [N/A, ] [C:PROGRA~1Yahoo!ASSIST~1Yhelper.dll] [N/A, ] [c:program filesati technologiesati.acecli.caste.graphics.runtime.dll] [ATI Technologies Inc., 1.2.2114.456] [c:program filesati technologiesati.acecli.component.runtime.shared.dll] [ATI Technologies Inc., 1.2.2026.29946] [c:program filesati technologiesati.acecli.caste.graphics.shared.dll] [ATI Technologies Inc., 1.2.2028.21076] [c:program filesati technologiesati.acedem.foundation.dll] [ATI Technologies Inc., 1.2.2026.29944] [c:program filesati technologiesati.acedem.graphics.displaysmanager.shared.dll] [ATI Technologies Inc., 1.2.2026.29945] [c:program filesati technologiesati.acedem.graphics.demosinfo.dll] [ATI Technologies Inc., 1.2.2026.29947] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322perfcounter.dll] [Microsoft Corporation, 1.1.4322.573] [c:program filesati technologiesati.acedem.graphics.demosadapterinfo.dll] [ATI Technologies Inc., 1.2.2026.29960] [c:program filesati technologiesati.acedem.graphics.dematiadapterinfo.dll] [ATI Technologies Inc., 1.2.2095.19505] [c:program filesati technologiesati.acedem.graphics.demdriversettings.dll] [ATI Technologies Inc., 1.2.2026.29947] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322aspnet_isapi.dll] [Microsoft Corporation, 1.1.4322.573] [c:windowsassemblygacsystem.web1.0.5000.0__b03f5f7f11d50a3asystem.web.dll] [Microsoft Corporation, 1.1.4322.573] [PID: 1152][D:Program FilesCyberLinkPowerDVDPDVDServ.exe] [Cyberlink Corp., 6.00.1027] [D:Program FilesCyberLinkPowerDVDCLRCEngine2.dll] [CyberLink Corp., 3.2.2021 ] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [PID: 1532][C:Program FilesRisingAntiSpyware
uniep.exe] [Beijing Rising Technology Co., Ltd., 1, 0, 1, 6] [C:Program FilesRisingAntiSpywareiep_ctrl.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 4] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [PID: 1844][C:Program FilesMSILive Update 3LMonitor.exe] [, 1, 0, 0, 3] [C:Program FilesMSILive Update 3Lang
es804.dll] [N/A, ] [C:Program FilesMSILive Update 3
vgpio.dll] [NVIDIA Corporation, 1.0.1.5] [C:WINDOWSsystem32msdmo.dll] [, ] [C:PROGRA~1Yahoo!ASSIST~1Yhelper.dll] [N/A, ] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [PID: 1972][C:WINDOWSSOUNDMAN.EXE] [Realtek Semiconductor Corp., 5, 1, 0, 58] [C:PROGRA~1Yahoo!ASSIST~1Yhelper.dll] [N/A, ] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [PID: 1960][C:Syswm1jsvchost.exe] [N/A, ] [C:Syswm1jGhook.dll] [N/A, ] [PID: 556][C:Program FilesATI TechnologiesATI.ACECLI.exe] [ATI Technologies Inc., 1.11.0.0] [C:WINDOWSsystem32mscoree.dll] [Microsoft Corporation, 1.1.4322.573] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322mscorwks.dll] [Microsoft Corporation, 1.1.4322.573] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322fusion.dll] [Microsoft Corporation, 1.1.4322.573] [c:windowsmicrosoft.netframeworkv1.1.4322mscorlib.dll] [Microsoft Corporation, 1.1.4322.573] [c:windowsassembly
ativeimages1_v1.1.4322mscorlib1.0.5000.0__b77a5c561934e089_422c3599mscorlib.dll] [N/A, ] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322mscorsn.dll] [Microsoft Corporation, 1.1.4322.573] [C:PROGRA~1Yahoo!ASSIST~1Yhelper.dll] [N/A, ] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322MSCORJIT.DLL] [Microsoft Corporation, 1.1.4322.573] [c:windowsassemblygacsystem.windows.forms1.0.5000.0__b77a5c561934e089system.windows.forms.dll] [Microsoft Corporation, 1.1.4322.573] [c:windowsassembly
ativeimages1_v1.1.4322system.windows.forms1.0.5000.0__b77a5c561934e089_14cb2b7bsystem.windows.forms.dll] [N/A, ] [c:program filesati technologiesati.acecli.implementation.dll] [ATI Technologies Inc., 1.2.2114.465] [c:program filesati technologiesati.acelog.foundation.dll] [ATI Technologies Inc., 1.2.2026.29944] [c:program filesati technologiesati.acecli.foundation.dll] [ATI Technologies Inc., 1.2.2026.29944] [c:program filesati technologiesati.acelog.foundation.service.dll] [ATI Technologies Inc., 1.2.2114.464] [c:program filesati technologiesati.acelog.foundation.shared.dll] [ATI Technologies Inc., 1.2.2026.29970] [c:windowsassemblygacsystem1.0.5000.0__b77a5c561934e089system.dll] [Microsoft Corporation, 1.1.4322.573] [c:windowsassembly
ativeimages1_v1.1.4322system1.0.5000.0__b77a5c561934e089_96df10ffsystem.dll] [N/A, ] [c:program filesati technologiesati.acecli.foundation.xmanifestation.dll] [ATI Technologies Inc., 1.2.2114.464] [c:windowsassemblygacsystem.xml1.0.5000.0__b77a5c561934e089system.xml.dll] [Microsoft Corporation, 1.1.4322.573] [c:windowsassembly
ativeimages1_v1.1.4322system.xml1.0.5000.0__b77a5c561934e089_b39e651esystem.xml.dll] [N/A, ] [c:windowsassemblygacsystem.runtime.remoting1.0.5000.0__b77a5c561934e089system.runtime.remoting.dll] [Microsoft Corporation, 1.1.4322.573] [C:WINDOWSsystem32ldmedia4.dll] [N/A, ] [c:program filesati technologiesati.acecli.component.systemtray.dll] [ATI Technologies Inc., 1.2.2114.432] [c:program filesati technologiesati.acecli.caste.graphics.shared.dll] [ATI Technologies Inc., 1.2.2028.21076] [c:program filesati technologiesati.acedem.graphics.displaysmanager.shared.dll] [ATI Technologies Inc., 1.2.2026.29945] [c:windowsassemblygacsystem.web1.0.5000.0__b03f5f7f11d50a3asystem.web.dll] [Microsoft Corporation, 1.1.4322.573] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322perfcounter.dll] [Microsoft Corporation, 1.1.4322.573] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322aspnet_isapi.dll] [Microsoft Corporation, 1.1.4322.573] [PID: 1400][E:Program FilesYahoo!Messengerymsgr_tray.exe] [Yahoo! Inc., 8,1,0,0] [E:Program FilesYahoo!MessengerMSVCP71.dll] [Microsoft Corporation, 7.10.3077.0] [E:Program FilesYahoo!MessengerMSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:PROGRA~1Yahoo!ASSIST~1Yhelper.dll] [N/A, ] [C:Program FilesYahoo!SharedYbSkin2.dll] [Yahoo! Inc., 2006, 10, 11, 1] [E:Program FilesYahoo!Messenger
es_msgr.dll] [Yahoo! Inc., 8,5,0,1] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [PID: 2032][C:WINDOWSsystem32wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)] [C:PROGRA~1Yahoo!ASSIST~1Yhelper.dll] [N/A, ] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [PID: 2468][E:Program FilesMaxthonMaxthon.exe] [Maxthon International Ltd., 1, 5, 9, 80] [E:Program FilesMaxthonmaxzlib.dll] [ , 1, 0, 0, 2] [C:PROGRA~1Yahoo!ASSIST~1Yhelper.dll] [N/A, ] [C:WINDOWSsystem32mscoree.dll] [Microsoft Corporation, 1.1.4322.573] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322CorperfmonExt.dll] [Microsoft Corporation, 1.1.4322.573] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [E:Program FilesMaxthonServicesRealTime
eal_time.dll] [, 1, 0, 0, 1] [C:WINDOWSsystem32ldmedia4.dll] [N/A, ] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322mscorie.dll] [Microsoft Corporation, 1.1.4322.573] [C:WINDOWSMicrosoft.NETFrameworkv1.1.4322mscorld.dll] [Microsoft Corporation, 1.1.4322.573] [C:WINDOWSsystem32MacromedFlashFlash9b.ocx] [Adobe Systems, Inc., 9,0,28,0] [C:DOCUME~1李牧原\LOCALS~1TempQqzo0.dll] [N/A, ] [PID: 3956][E:Program FilesRisingRavRsAgent.exe] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 12] [C:PROGRA~1Yahoo!ASSIST~1Yhelper.dll] [N/A, ] [E:Program FilesRisingRavRsCommX.dll] [rising, 18, 0, 0, 1] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [PID: 4020][C:WINDOWSmsagentAgentSvr.exe] [Microsoft Corporation, 2.00.0.3424] [C:PROGRA~1Yahoo!ASSIST~1Yhelper.dll] [N/A, ] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [PID: 2208][C:WINDOWSexplorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [C:Program FilesCommon FilesMicrosoft SharedMSINFONewInfo.dll] [N/A, ] [e:program files
ising
fwjifvpyyl.dll] [N/A, ] [D:Program FilesAdobeAcrobat 7.0ActiveXPDFShell.dll] [Adobe Systems, Inc., 7.0.0.0] [C:WINDOWSsystem32ldmedia4.dll] [N/A, ] [C:WINDOWSsystem32mppds.dll] [N/A, ] [e:program files
ising
fwzpkjuwgv.dll] [N/A, ] [C:DOCUME~1李牧原\LOCALS~1TempQqzo0.dll] [N/A, ] [PID: 3780][C:WINDOWSsystem32conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [PID: 3624][C:DOCUME~1李牧原\LOCALS~1TempRar$EX02.359SREng.EXE] [Smallfrogs Studio, 2.4.12.806] [C:Program FilesRisingAntiSpywareieprot.dll] [Beijing Rising Technology Co., Ltd., 1, 0, 0, 10] [C:Syswm1jGhook.dll] [N/A, ] [C:DOCUME~1李牧原\LOCALS~1TempQqzo0.dll] [N/A, ] [C:WINDOWSsystem32ldmedia4.dll] [N/A, ]
================================== http://bbs.pep.com.cn/viewthread.php?tid=90515秋风树林的这个精华帖对于进程的名称已经讲得很明白了,对于进程名我就不想多说什么了。 下面讲一下分析方法: PID:XXX:对于这一项,有兴趣的朋友可以参考一下10楼:什么是PID(进程标识符) 一般来说,进程前面没有[PID:XXXX]的进程是安全的,不用去分析。 我这个日志是用旧版的SREng扫描的,新版的SREng在进程前面的方括号[ ]里除了PID参数外,还有用户名。我的新版日志的方括号里面就是这样的: [ PID: 932 / SYSTEM][SystemRootSystem32smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [ PID: 296 / 李牧原][C:WINDOWSExplorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] “ PID:XXX/ ”后面的 SYSTEM和 李牧原就是运行这项进程的用户名。 SYSTEM说明这项进程为系统进程。 PID参数后面的,就是 进程路径了。 SystemRoot,如果是NT和2000系统,就是X:WINNT,如果是XP之类的,就是C:WINDOWS。再后面,就是公司信息。和前几项一样,如果是[N/A]或者假冒Microsoft Corporation,那么就是有问题的。进程名称的下几行(如果有的话)是进程加载的dll。一般来说,有[N/A]的就是有问题的。这时候应该用Google搜索一下这个dll,如果发现有问题或者根本搜索不到,就应该删除。有的dll名称是随机的n位字母数字,一般来说都是有问题的。如:[C:WINDOWSsystem32ldmedia4.dll] [N/A, ][C:WINDOWSsystem32mppds.dll] [N/A, ] [e:program files
ising
fwzpkjuwgv.dll] [N/A, ]对于Explorer.EXE加载的dll要格外注意!
|