|
作者: hkcc [hkcc] 论坛用户 | 登录 |
我的电脑D盘里有个个文件,good.exe和DosGame.exe每次开机我的防火墙都会提醒我要运行这个程序,删也删不掉,这些以前是没有的,D盘下面还有 手,是不是我的电脑被人入侵了,现在里面有个文件是这样的:: Microsoft (R) DrWtsn32 Copyright (C) 1985-2001 Microsoft Corp. All rights reserved. 发生应用程序意外错误: 应用程序: <unknown> (pid=2660) 时间: 2004-3-26 @ 22:32:07.203 意外情况编号: c0000005 (访问侵犯) *----> 系统信息 <----* 计算机名: AS-AHBFUGHM7EME 用户名: a 终端会话 Id: 0 处理器数量: 1 处理器类型: x86 Family 15 Model 2 Stepping 4 Windows 版本: 5.1 当前内部版本号: 2600 Service Pack: None 当前类型: Uniprocessor Free 注册的单位: as 注册的所有者: a *----> 任务列表 <----* 0 System Process 4 System 428 smss.exe 492 csrss.exe 516 winlogon.exe 560 services.exe 572 lsass.exe 760 svchost.exe 784 svchost.exe 888 svchost.exe 940 svchost.exe 1008 spoolsv.exe 1260 Explorer.EXE 1452 Rundll32.exe 1484 soundman.exe 1500 realsched.exe 1516 navapw32.exe 1536 rundll32.exe 1544 rundll32.exe 1552 assistse.exe 1568 System.exe 1616 rnathchk.exe 1640 alg.exe 1656 msstart.exe 1716 Error 0x8007007A 1808 mdm.exe 1816 DosGame.exe 1832 navapsvc.exe 1880 ctfmon.exe 1920 CNCnsMln.exe 1960 msmsgs.exe 1980 Error 0x8007007A 2028 conime.exe 2180 Error 0x8007007A 2636 Error 0x8007007A 2644 Error 0x8007007A 2660 Error 0x8007007A 2744 drwtsn32.exe *----> 模块清单 <----* (0000000000400000 - 0000000000b29000: D:\ÓÎÏ・\ºìÉ«¾¯½ä2³àÁúÖ®ºðÖÐÎÄ°æ\game.TMP0 (0000000001010000 - 00000000010f4000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll (0000000001ad0000 - 0000000001b23000: C:\PROGRA~1\3721\Ces\cmail.dll (0000000010000000 - 0000000010057000: D:\ÓÎÏ・\ºìÉ«¾¯½ä2³àÁúÖ®ºðÖÐÎÄ°æ\binkw32.dll (0000000011000000 - 0000000011039000: D:\ÓÎÏ・\ºìÉ«¾¯½ä2³àÁúÖ®ºðÖÐÎÄ°æ\blowfish.dll (0000000037210000 - 0000000037246000: C:\WINDOWS\DOWNLO~1\CnsMin.dll (0000000053000000 - 0000000053007000: C:\PROGRA~1\3721\helper.dll (000000005adc0000 - 000000005adf4000: C:\WINDOWS\system32\uxtheme.dll (0000000062c20000 - 0000000062c28000: C:\WINDOWS\System32\LPK.DLL (00000000719c0000 - 00000000719fb000: C:\WINDOWS\System32\MSWSOCK.dll (0000000071a10000 - 0000000071a18000: C:\WINDOWS\System32\WS2HELP.dll (0000000071a20000 - 0000000071a35000: C:\WINDOWS\System32\WS2_32.dll (0000000071a40000 - 0000000071a4a000: C:\WINDOWS\System32\WSOCK32.dll (0000000072f10000 - 0000000072f6a000: C:\WINDOWS\System32\USP10.dll (00000000736d0000 - 0000000073715000: C:\WINDOWS\System32\DDRAW.dll (0000000073b30000 - 0000000073b36000: C:\WINDOWS\System32\DCIMAN32.dll (0000000073e70000 - 0000000073ec5000: C:\WINDOWS\System32\DSOUND.dll (0000000074680000 - 00000000746cb000: C:\WINDOWS\System32\MSCTF.dll (0000000075e00000 - 0000000075ea1000: C:\WINDOWS\System32\SXS.DLL (0000000075eb0000 - 0000000075ecd000: C:\WINDOWS\system32\Apphelp.dll (0000000076300000 - 000000007631a000: C:\WINDOWS\System32\IMM32.dll (0000000076b10000 - 0000000076b3c000: C:\WINDOWS\System32\WINMM.dll (0000000076fa0000 - 0000000077018000: C:\WINDOWS\System32\CLBCATQ.DLL (0000000077020000 - 00000000770e5000: C:\WINDOWS\System32\COMRes.dll (00000000770f0000 - 000000007717b000: C:\WINDOWS\system32\OLEAUT32.dll (0000000077180000 - 000000007729a000: C:\WINDOWS\system32\ole32.dll (00000000772a0000 - 0000000077303000: C:\WINDOWS\system32\SHLWAPI.dll (0000000077310000 - 000000007739b000: C:\WINDOWS\system32\COMCTL32.dll (00000000773a0000 - 0000000077b94000: C:\WINDOWS\system32\SHELL32.dll (0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\VERSION.dll (0000000077be0000 - 0000000077c33000: C:\WINDOWS\system32\msvcrt.dll (0000000077c40000 - 0000000077c80000: C:\WINDOWS\system32\GDI32.dll (0000000077c90000 - 0000000077d05000: C:\WINDOWS\system32\RPCRT4.dll (0000000077d10000 - 0000000077d9d000: C:\WINDOWS\system32\USER32.dll (0000000077da0000 - 0000000077e39000: C:\WINDOWS\system32\ADVAPI32.dll (0000000077e40000 - 0000000077f4d000: C:\WINDOWS\system32\kernel32.dll (0000000077f50000 - 0000000077ff9000: C:\WINDOWS\System32\ntdll.dll *----> 线程 ID 0xa68 的状态转储 <----* eax=00000000 ebx=0012f078 ecx=00000000 edx=0012efc4 esi=0012f078 edi=0012f030 eip=004aa900 esp=0012efac ebp=00000005 iopl=0 vif nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00080246 *** WARNING: Unable to verify checksum for D:\ÓÎÏ・\ºìÉ«¾¯½ä2³àÁúÖ®ºðÖÐÎÄ°æ\game.TMP0 *** ERROR: Module load completed but symbols could not be loaded for D:\ÓÎÏ・\ºìÉ«¾¯½ä2³àÁúÖ®ºðÖÐÎÄ°æ\game.TMP0 函数: game Error 0x80070057 错误 ->004aa900 8b08 mov ecx,[eax] ds:0023:00000000=???????? Error 0x80070057 *----> 堆栈反向跟踪 <---* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 00000005 00000000 00000000 00000000 00000000 game+0xaa900 *----> 原始堆栈转储 <----* 000000000012efac 01 00 00 00 00 00 00 00 - 58 02 00 00 78 f0 12 00 ........X...x... 000000000012efbc d7 ad d3 77 00 00 00 00 - 6c 00 00 00 00 00 00 00 ...w....l....... 000000000012efcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000012efdc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000012efec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000012effc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000012f00c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000012f01c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000012f02c 00 00 00 00 89 f7 75 00 - 05 00 00 00 05 00 00 00 ......u......... 000000000012f03c 58 02 00 00 05 00 00 00 - 00 00 00 00 be 54 49 00 X............TI. 000000000012f04c 58 f0 12 00 10 00 00 00 - 20 03 00 00 05 00 00 00 X....... ....... 000000000012f05c 05 00 00 00 81 a6 70 73 - f8 25 6e 73 ff ff ff ff ......ps.%ns.... 000000000012f06c 48 1c 6e 73 55 1b 70 73 - a8 2f 16 00 ec bb 78 00 H.nsU.ps./....x. 000000000012f07c 40 00 00 00 40 00 00 00 - 00 00 00 00 00 00 00 00 @...@........... 000000000012f08c 00 00 00 00 00 00 16 00 - 00 00 00 00 b0 e2 1c 01 ................ 000000000012f09c 02 5b 49 00 34 15 82 00 - c0 77 d1 77 34 ff 12 00 .[I.4....w.w4... 000000000012f0ac 80 02 00 00 bc 0a 7c 00 - 30 00 00 00 44 44 52 41 ......|.0...DDRA 000000000012f0bc 57 2e 44 4c 4c 20 45 72 - 72 6f 72 20 63 6f 64 65 W.DLL Error code 000000000012f0cc 20 3d 20 38 38 37 36 30 - 32 34 35 00 03 00 00 00 = 88760245..... 000000000012f0dc 00 c0 72 00 00 00 00 00 - 00 00 00 00 00 00 40 00 ..r...........@. 这是怎么回事谁能帮我一下,我开QQ的时候就回弹出很多Norton AntiVirus 2002里的电子邮件保护说是Norton AntiVirus正在扫描我的电子邮件,但是一点进程都没有,开1个QQ就弹出2个,很麻烦啊,按也关不掉,哪位好心人指点一下!!! |
地主 发表时间: 04-03-27 06:56 |
|
20CN网络安全小组版权所有
Copyright © 2000-2010 20CN Security Group. All Rights Reserved.
论坛程序编写:NetDemon
粤ICP备05087286号