今天开机的时候,发现启动得特别慢,然后进去了就在进程管理器里发现了一个名为adf.com.cn的进程
不知道这三个键是干啥用的,数值名称都是ImagePath数值都是C:\WINDOWS\adf.com.cn
然后偶用ProcessInfo查看了他加载的模块,发现用到了Ws2_32.dll,于是就用HookSend程序来拦截他往外发送的数据包,结果发现他发送的数据都是到同一个莫名其妙的网站,且一直访问同一页面,拦截数据如下:
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
GET /ip.txt HTTP/1.0
User-Agent: MYURL
Host: ningzi8887.27h.com
Pragma: no-cache
莫名其妙的程序。。。
|