📄 smb_suspicious_files.nasl
字号:
NAME=Sexxxpassport.com browser pluginURL=http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453079935KEY=CLSID\{11904CE8-632A-4856-A7CC-00B33FE71BD8}\InprocServer32ITEM=EXP=Spp3.dllNAME=SearchSquireURL=http://www.doxdesk.com/parasite/SearchSquire.html KEY=CLSID\{11990E9F-2A4D-11D6-9507-02608CDD2842}\InprocServer32ITEM=EXP=SearchSquire.dllNAME=CoolWebSearch parasite variantURL=http://www.richardthelionhearted.com/~merijn/cwschronicles.html#KEY=CLSID\{12D02C08-218F-4A11-BDE1-6611ADB7B81F}\InprocServer32ITEM=EXP=sys32_app.dllNAME=Winpage BlockerURL=http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453079932KEY=CLSID\{12DF6E3E-6272-4AE8-880B-2158D60791C0}\InprocServer32ITEM=EXP=WinPage.dllNAME=BrowserAid/Startium variantURL=http://www.doxdesk.com/parasite/BrowserAid.htmlKEY=CLSID\{12EE7A5E-0674-42f9-A76A-000000004D00}\InprocServer32ITEM=EXP=stlb2.dllNAME=ActiveSearch/411FerretURL=http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453088053KEY=CLSID\{12F02779-6D88-4958-8AD3-83C12D86ADC7}\InprocServer32ITEM=EXP=toolbar.dllNAME=SuperBarURL=http://www.doxdesk.com/parasite/SuperBar.htmlKEY=CLSID\{136A9D1D-1F4B-43D4-8359-6F2382449255}\InprocServer32ITEM=EXP=Superbar.dllNAME=FavoriteManURL=http://www.doxdesk.com/parasite/FavoriteMan.htmlKEY=CLSID\{139D88E5-C372-469D-B4C5-1FE00852AB9B}\InprocServer32ITEM=EXP=ofrg.dllNAME=p0rn relatedURL=KEY=CLSID\{13F90341-AD79-4A9F-9B57-0234675670D6}\InprocServer32ITEM=EXP=Ipsysdrv32.dllNAME=StickyPops.com adwareURL=KEY=CLSID\{1433F750-E53F-11D8-9669-0800200C9A66}\InprocServer32ITEM=EXP=STRAd32.dllNAME=ShopNavSearch/SrngURL=http://www.doxdesk.com/parasite/Srng.html KEY=CLSID\{14B3D246-6274-40B5-8D50-6C2ADE2AB29B}\InprocServer32ITEM=EXP=Snhelper.dllNAME=CoolWebSearch parasite variantURL=http://www.richardthelionhearted.com/~merijn/cwschronicles.html#KEY=CLSID\{150FA160-130D-451F-B863-B655061432BA}\InprocServer32ITEM=EXP=mgs_32.dllNAME=ClientManURL=http://www.doxdesk.com/parasite/ClientMan.htmlKEY=CLSID\{166348F1-2C41-4C9F-86BB-EB2B8ADE030C}\InprocServer32ITEM=EXP=msvrfyNAME=Comet CursorURL=http://www.doxdesk.com/parasite/CometCursor.htmlKEY=CLSID\{1678F7E1-C422-11D0-AD7D-00400515CAAA}\InprocServer32ITEM=EXP=comet.dllNAME=CoolWebSearch parasite variantURL=http://www.richardthelionhearted.com/~merijn/cwschronicles.html#KEY=CLSID\{17DA0C9E-4A27-4ac5-BB75-5D24B8CDB972}\InprocServer32ITEM=EXP=Excel10.dllNAME=Spyware.DigitalNames variantURL=http://securityresponse.symantec.com/avcenter/venc/data/spyware.digitalnames.htmlKEY=CLSID\{183D5161-0C62-4295-896C-44E7442CD6F2}\InprocServer32ITEM=EXP=DigitalNamesPlugIn150.dllNAME=VirtuMonde adware variantURL=http://securityresponse.symantec.com/avcenter/venc/data/adware.virtumonde.htmlKEY=CLSID\{18722863-6D1D-4300-BF29-406948EDA7CB}\InprocServer32ITEM=EXP=datNAME=I-LookupURL=http://www.doxdesk.com/parasite/ILookup.htmlKEY=CLSID\{18B79968-1A76-4953-9EBB-B651407F8998}\InprocServer32ITEM=EXP=winenc32.dllNAME=i-lookup/SbusURL=http://www.doxdesk.com/parasite/ILookup.htmlKEY=CLSID\{19A447BA-9C2E-4864-93F5-A0645229771E}\InprocServer32ITEM=EXP=Sbus.dllNAME=SearchExURL=http://www.doxdesk.com/parasite/Searchex.htmlKEY=CLSID\{1A98BCA2-0BD1-47DE-9710-C7665F7F1FCB}\InprocServer32ITEM=EXP=Iebrw.dllNAME=CnsMinURL=http://www.aluriasoftware.com/spyware-removal/details/CnsMin/KEY=CLSID\{1B0E7716-898E-48cc-9690-4E338E8DE1D3}\InprocServer32ITEM=EXP=Assist.dllNAME=Clickspring/PurityScanURL=http://doxdesk.com/parasite/PurityScan.htmlKEY=CLSID\{1B7D753B-1981-4bd2-91F3-6D055EE113A0}\InprocServer32ITEM=EXP=NDrv.dllNAME=Browserplugin.com malwareURL=KEY=CLSID\{1BDD55B8-3985-4E59-B906-5E0AD56D6710}\InprocServer32ITEM=EXP=WHNAME=Adware.IEPageHelperURL=http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453083026KEY=CLSID\{1C4DA27D-4D52-4465-A089-98E01BB725CA}\InprocServer32ITEM=EXP=inetdctr.dllNAME=iSearch toolbarURL=http://www.kephyr.com/spywarescanner/library/isearch/index.phtmlKEY=CLSID\{1C78AB3F-A857-482e-80C0-3A1E5238A565}\InprocServer32ITEM=EXP=toolbar.dllNAME=SpiderSearch, iLookup variantURL=KEY=CLSID\{1D022C27-3771-4D1D-B1B7-1953E271C6CA}\InprocServer32ITEM=EXP=winsps32.dllNAME=BlazeFind/SearchRelevancy hijackerURL=KEY=CLSID\{1D7E3B41-23CE-469B-BE1B-A64B877923E1}\InprocServer32ITEM=EXP=SearchRelevancy.dllNAME=SubSearch v22URL=http://www.doxdesk.com/parasite/SubSearch.htmlKEY=CLSID\{1D870C86-AA3C-4451-81E4-71D480A1A652}\InprocServer32ITEM=EXP=SbSrch_V22.dllNAME=NJStar Asian ExplorerURL=http://www.njstar.com/asianexplorer/KEY=CLSID\{1E1B2879-30C7-11D4-8DDF-525400E483E3}\InprocServer32ITEM=EXP=ETop100.dllNAME=Backdoor.Lixy.BURL=http://www.symantec.com/avcenter/venc/data/backdoor.lixy.b.htmlKEY=CLSID\{1E1B2879-88FF-11D2-8D96-000000000003}\InprocServer32ITEM=EXP=SSocks5.dllNAME=Backdoor.Lixy.BURL=http://www.symantec.com/avcenter/venc/data/backdoor.lixy.b.htmlKEY=CLSID\{1E1B2879-88FF-11D2-8D96-000000000004}\InprocServer32ITEM=EXP=Ssocks32.dllNAME=ClitorURL=http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453079921KEY=CLSID\{1E1B2879-88FF-11D2-8D96-123457123457}\InprocServer32ITEM=EXP=Explorer.dllNAME=unidentified adwareURL=KEY=CLSID\{1E1B2879-88FF-11D2-8D96-D7ACAC31337F}\InprocServer32ITEM=EXP=Mslink32.dllNAME=BackDoor LixyURL=http://securityresponse.symantec.com/avcenter/venc/data/backdoor.lixy.htmlKEY=CLSID\{1E1B2879-88FF-11D2-8D96-D7ACAC95951A}\InprocServer32ITEM=EXP=Lid.dllNAME=Commonname toolbarURL=http://www.doxdesk.com/parasite/CommonName.htmlKEY=CLSID\{1E1B2879-88FF-11D2-8D96-D7ACAC95951F}\InprocServer32ITEM=EXP=CnbarIE.dllNAME=CooolWebSearch parasite variantURL=http://www.spywareinfo.com/~merijn/cwschronicles.htmlKEY=CLSID\{1E1B2879-88FF-11D2-8D96-D7ACAC95951F}\InprocServer32ITEM=EXP=DNSErr.dllNAME=GoGoToolsURL=http://doxdesk.com/parasite/GogoTools.html parasiteKEY=CLSID\{1E1B2879-88FF-11D2-8D96-D7ACAC95951F}\InprocServer32ITEM=EXP=HTMLEdit.dllNAME=p0rn relatedURL=KEY=CLSID\{1E1B2879-88FF-11D2-8D96-D7ACAC97972F}\InprocServer32ITEM=EXP=Msudp.dllNAME=Personal Antispy keyloggerURL=http://www.botspot.com/Intelligent_Agent/2235.htmlKEY=CLSID\{1E1B2879-88FF-11D3-8D96-D7ACAC95951A}\InprocServer32ITEM=EXP=Funnywb.dllNAME=QuickFlicks Streaming PlayerURL=http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453073164KEY=CLSID\{1E6F1D6A-1F20-11D4-8859-00A0CCE26836}\InprocServer32ITEM=EXP=SVAplayer.dllNAME=ToolbarCCURL=http://www.doxdesk.com/parasite/ToolbarCC.htmlKEY=CLSID\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFA2}\InprocServer32ITEM=EXP=dllNAME=ToolbarCC/RndURL=http://www.doxdesk.com/parasite/ToolbarCC.htmlKEY=CLSID\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFA7}\InprocServer32ITEM=EXP=winNAME=ToolbarCC/RndURL=http://www.doxdesk.com/parasite/ToolbarCC.htmlKEY=CLSID\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFA8}\InprocServer32ITEM=EXP=winNAME=ToolbarCC/RndURL=http://www.doxdesk.com/parasite/ToolbarCC.html KEY=CLSID\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAF}\InprocServer32ITEM=EXP=dllNAME=CoolWebSearch parasite variantURL=http://www.richardthelionhearted.com/~merijn/cwschronicles.html#KEY=CLSID\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFB1}\InprocServer32ITEM=EXP=MSNAME=CoolWebSearch parasite variantURL=http://www.richardthelionhearted.com/~merijn/cwschronicles.html#KEY=CLSID\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFB2}\InprocServer32ITEM=EXP=MSNAME=i-lookup/AbebURL=http://www.doxdesk.com/parasite/ILookup.html KEY=CLSID\{2038A287-4221-4F76-A7C0-ADDD77AFABB3}\InprocServer32ITEM=EXP=abeb.dllNAME=Myaopop AdwareURL=KEY=CLSID\{204E9F8F-38CA-4E11-BA91-06B685285CC0}\InprocServer32ITEM=EXP=xpllog.dllNAME=HotBarURL=http://www.doxdesk.com/parasite/HotBar.htmlKEY=CLSID\{204F937E-519E-4597-96FA-8F1F59F3CB6D}\InprocServer32ITEM=EXP=ctor.dllNAME=Give4FreeURL=KEY=CLSID\{208E7E77-507A-4649-B0C9-D39E9049C7A2}\InprocServer32ITEM=EXP=ibho.dllNAME=CustomToolbarURL=http://www.doxdesk.com/parasite/CustomToolbar.html KEY=CLSID\{21301D69-B8F1-46AA-B0B5-09EE2285914C}\InprocServer32ITEM=EXP=CustomToolbar.dllNAME=SearchEnhancement hijackerURL=http://groups.google.com/groups?q=searchenhancement&hl=en&lr=&ie=UTF-8&oe=UTF-8&selm=5fa201c33b6c%24abac7a20%243101280a%40phx.gbl&rnum=1 KEY=CLSID\{22941A26-7033-432C-94C7-6371DE343822}\InprocServer32ITEM=EXP=Scbar.dllNAME=hijacker, as yet unidentifiedURL=KEY=CLSID\{22B9A67D-E689-44B6-B775-0E8FE84B4F9B}\InprocServer32ITEM=EXP=dllNAME=VirtuMonde adware variantURL=http://securityresponse.symantec.com/avcenter/venc/data/adware.virtumonde.htmlKEY=CLSID\{2316230A-C89C-4BCC-95C2-66659AC7A775}\InprocServer32ITEM=EXP=datNAME=Expext/MetaDirect hijackerURL=http://www.securemost.com/articles/trou_3_remove_expext.htmKEY=CLSID\{23BC1CCF-4BE7-497F-B154-6ADA68425FBB}\InprocServer32ITEM=EXP=expext.dllNAME=ClientManURL=http://www.doxdesk.com/parasite/ClientMan.htmlKEY=CLSID\{25F7FA20-3FC3-11D7-B487-00D05990014C}\InprocServer32ITEM=EXP=msNAME=XupiterURL=http://www.doxdesk.com/parasite/Xupiter.htmlKEY=CLSID\{2662BDD7-05D6-408F-B241-FF98FACE6054}\InprocServer32ITEM=EXP=Xtupdate.dllNAME=WhazitURL=http://www.doxdesk.com/parasite/Whazit.htmlKEY=CLSID\{267D5BD3-0DC2-4724-A196-7F4794FBB9EB}\InprocServer32ITEM=EXP=outones.dllNAME=eUniverse/Keenvalue variantURL=http://www.doxdesk.com/parasite/KeenValue.html
KEY=CLSID\{269B6797-664E-48AA-B283-B012BDF6E525}\InprocServer32ITEM=EXP=BHO.dllNAME=WurldMediaURL=http://www.doxdesk.com/parasite/WurldMedia.htmlKEY=CLSID\{2737A6C0-7E24-11D7-B299-00E0297E0844}\InprocServer32ITEM=EXP=NAME=WhistleSoftwareURL=http://www.uslocalweather.com/privacy.aspKEY=CLSID\{27557cf1-a237-496d-8c8f-08f3844c6a8b}\InprocServer32ITEM=EXP=WhistleHelper.dllNAME=CoolWebSearch parasite variantURL=http://www.richardthelionhearted.com/~merijn/cwschronicles.html#KEY=CLSID\{275636E4-A535-4668-9FF1-86DC0C62D446}\InprocServer32ITEM=EXP=msopt.dllNAME=MyPageFinderURL=http://www.doxdesk.com/parasite/MyPageFinder.htmlKEY=CLSID\{27A5FF76-9919-492C-98E3-EDA3502FC829}\InprocServer32ITEM=EXP=ml_32.dllNAME=SearchMiracle.EliteBarURL=http://www.giantcompany.com/antispyware/research/spyware/spyware-SearchMiracle.EliteBar.aspxKEY=CLSID\{28CAEFF3-0F18-4036-B504-51D73BD81ABC}\InprocServer32ITEM=EXP=EliteToolBar version 53.dllNAME=EliteBar/SearchMiracle adwareURL=http://www.giantcompany.com/antispyware/research/spyware/spyware-SearchMiracle.EliteBar.aspxKEY=CLSID\{28CAEFF3-0F18-4036-B504-51D73BD81C3A}\InprocServer32ITEM=EXP=Elitebar.dllNAME=Searchportal.info - CoolWebSearch parasite variantURL=http://www.spywareinfo.com/~merijn/cwschronicles.htmlKEY=CLSID\{28F65FCB-D130-11D8-BA48-8BE0C49AF370}\InprocServer32ITEM=EXP=popup_bl.dllNAME=unidentified hijackerURL=http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453073363KEY=CLSID\{29A38549-AF6F-11D4-89D6-BC1DFD912B00}\InprocServer32ITEM=EXP=bho1.dllNAME=Commander toolbarURL=http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453083035KEY=CLSID\{29F7B7FA-ADC8-48ea-9E1C-EA87A05AE642}\InprocServer32ITEM=EXP=sbb.dllNAME=FastFind.org SubSearchURL=http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453074896KEY=CLSID\{2A57772A-D963-4533-A999-A4D66B7EF424}\InprocServer32ITEM=EXP=00S00.dllNAME=Make-deal.com malwareURL=KEY=CLSID\{2A7B720A-7A28-4e99-80A0-2DF985EC93D0}\InprocServer32ITEM=EXP=Font.dllNAME=SmartShopperURL=http://www.giantcompany.com/antispyware/research/spyware/spyware-Hotbar.ShoppingReports.aspxKEY=CLSID\{2A8A997F-BB9F-48F6-AA2B-2762D50F9289}\InprocServer32ITEM=EXP=smrtshpr.dllNAME=LookThru Cool Search BarURL=KEY=CLSID\{2AF8CED6-5BD8-4310-A90C-9664EFB16B10}\InprocServer32ITEM=EXP=coolbar.dllNAME=BookedSpace/RemanentURL=http://www.doxdesk.com/parasite/BookedSpace.htmlKEY=CLSID\{2B3452C5-1B9A-440F-A203-F6ED0F64C895}\InprocServer32ITEM=EXP=rem00001.dllNAME=Dynamic Desktop Media adwareURL=http://www.spyany.com/program/article_spw_rm_Dynamic_Desktop_Media.htmlKEY=CLSID\{2BC43670-C0BD-4794-BB11-F60F3E001DC5}\InprocServer32ITEM=EXP=ddmp.dllNAME=IESearch ToolbarURL=http://www.giantcompany.com/antispyware/research/spyware/spyware-IESearchToolbar.aspxKEY=CLSID\{2c5175a2-adf3-4f57-ab70- ba90fd60a383}\InprocServer32ITEM=EXP=IESEARCHTOOLBAR.DLLNAME=IESearch toolbar hijackerURL=KEY=CLSID\{2C5175A2-ADF3-4F57-AB70-BA90FD60A383}\InprocServer32ITEM=EXP=IESearchToolbar.dllNAME=BrowserAid/StartiumURL=http://www.doxdesk.com/parasite/BrowserAid.htmlKEY=CLSID\{2CF0B992-5EEB-4143-99C0-5297EF71F443}\InprocServer32ITEM=EXP=stlbdist.dllNAME=BrowserAid/StartiumURL=http://www.doxdesk.com/parasite/BrowserAid.htmlKEY=CLSID\{2CF0B992-5EEB-4143-99C0-5297EF71F444}\InprocServer32ITEM=EXP=stlbdist.dllNAME=BrowserAid/StartiumURL=http://www.doxdesk.com/parasite/BrowserAid.htmlKEY=CLSID\{2CF0B992-5EEB-4143-99C0-5297EF71F44A}\InprocServer32ITEM=EXP=stlbad123.dllNAME=BrowserAid/StartiumURL=http://www.doxdesk.com/parasite/BrowserAid.htmlKEY=CLSID\{2CF0B992-5EEB-4143-99C2-5297EF71F44A}\InprocServer32ITEM=EXP=stlbad123.dllNAME=CoolWebSearch parasite variantURL=http://www.richardthelionhearted.com/~merijn/cwschronicles.html#KEY=CLSID\{2D38A51A-23C9-48a1-A33C-48675AA2B494}\InprocServer32ITEM=EXP=winres.dllNAME=i-lookup/DrbrURL=http://www.doxdesk.com/parasite/ILookup.html KEY=CLSID\{2D556983-83D7-4630-9AA5-27C74CA27B79}\InprocServer32ITEM=EXP=Drbr.dllNAME=AdBlaster AdwareURL=http://www.spyany.com/program/article_adw_rm_AdBlaster.htmlKEY=CLSID\{2D7CB618-CC1C-4126-A7E3-F5B12D3BCF71}\InprocServer32ITEM=
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -