|
|
昨天上传,结果浏览器死了,下面粘贴上来
【1】2024-05-09 20:11:57,其他,升级日志,自动更新成功,版本号:6.0.0.26
升级方式:自动更新
升级结果:成功,版本号:6.0.0.26,病毒库时间:2024-05-09 19:10
下载文件:
2024-05-09 20:11:49 C:\Program Files (x86)\Huorong\Sysdiag\bin\BugReport.exe
2024-05-09 20:11:49 C:\Windows\System32\drivers\hrwfpdrv.sys
2024-05-09 20:11:49 C:\Windows\System32\drivers\sysdiag.sys
2024-05-09 20:11:49 C:\Program Files (x86)\Huorong\Sysdiag\bin\scenter.dll
2024-05-09 20:11:49 C:\Program Files (x86)\Huorong\Sysdiag\bin\libxscore.bundle
2024-05-09 20:11:50 C:\Program Files (x86)\Huorong\Sysdiag\bin\libxsse.dll
2024-05-09 20:11:50 C:\Program Files (x86)\Huorong\Sysdiag\bin\libcobra.dll
2024-05-09 20:11:50 C:\Program Files (x86)\Huorong\Sysdiag\bin\uactmon.dll
2024-05-09 20:11:50 C:\Program Files (x86)\Huorong\Sysdiag\bin\DuiLib.dll
2024-05-09 20:11:51 C:\Program Files (x86)\Huorong\Sysdiag\bin\HipsLog.exe
2024-05-09 20:11:51 C:\Program Files (x86)\Huorong\Sysdiag\bin\HipsMain.exe
2024-05-09 20:11:51 C:\Program Files (x86)\Huorong\Sysdiag\bin\HipsTray.exe
2024-05-09 20:11:51 C:\Program Files (x86)\Huorong\Sysdiag\bin\HipsDaemon.exe
2024-05-09 20:11:51 C:\Program Files (x86)\Huorong\Sysdiag\bin\HRUpdate.exe
2024-05-09 20:11:52 C:\Program Files (x86)\Huorong\Sysdiag\bin\HRConfig.exe
2024-05-09 20:11:52 C:\Program Files (x86)\Huorong\Sysdiag\bin\NetFlow.exe
2024-05-09 20:11:52 C:\Program Files (x86)\Huorong\Sysdiag\bin\main.ui
2024-05-09 20:11:52 C:\Program Files (x86)\Huorong\Sysdiag\bin\hrconfig.ui
2024-05-09 20:11:52 C:\Program Files (x86)\Huorong\Sysdiag\bin\netflow.ui
2024-05-09 20:11:53 C:\Program Files (x86)\Huorong\Sysdiag\bin\Autoruns.ui
2024-05-09 20:11:53 C:\Program Files (x86)\Huorong\Sysdiag\bin\Autoruns.exe
2024-05-09 20:11:53 C:\Program Files (x86)\Huorong\Sysdiag\bin\NetDiag.exe
2024-05-09 20:11:53 C:\Program Files (x86)\Huorong\Sysdiag\bin\HRSwordui.ui
2024-05-09 20:11:53 C:\Program Files (x86)\Huorong\Sysdiag\bin\HRSword.exe
2024-05-09 20:11:54 C:\Program Files (x86)\Huorong\Sysdiag\bin\RightClickMan.exe
2024-05-09 20:11:54 C:\Program Files (x86)\Huorong\Sysdiag\bin\sysclean.ui
2024-05-09 20:11:54 C:\Program Files (x86)\Huorong\Sysdiag\bin\sysclean.exe
2024-05-09 20:11:54 C:\Program Files (x86)\Huorong\Sysdiag\bin\FileShred.ui
2024-05-09 20:11:54 C:\Program Files (x86)\Huorong\Sysdiag\bin\FileShred.exe
2024-05-09 20:11:54 C:\Program Files (x86)\Huorong\Sysdiag\bin\popblock.ui
2024-05-09 20:11:55 C:\Program Files (x86)\Huorong\Sysdiag\bin\PopBlock.exe
2024-05-09 20:11:55 C:\Program Files (x86)\Huorong\Sysdiag\bin\leakrepair.ui
2024-05-09 20:11:55 C:\Program Files (x86)\Huorong\Sysdiag\bin\leakrepair.exe
2024-05-09 20:11:55 C:\Program Files (x86)\Huorong\Sysdiag\bin\SysDiag.ui
2024-05-09 20:11:55 C:\Program Files (x86)\Huorong\Sysdiag\bin\SysDiag.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\uninst.exe
2024-05-09 20:11:56 C:\ProgramData\Huorong\Sysdiag\virdb\hwl.db
2024-05-09 20:11:56 C:\ProgramData\Huorong\Sysdiag\virdb\prop.db
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\virdb\pset.db
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\virdb\troj.db
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\db\hips.db
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\db\wlst.db
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\db\urlcls.db
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\db\popblk.db
更新文件:
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\BugReport.exe
2024-05-09 20:11:56 C:\Windows\System32\drivers\hrwfpdrv.sys
2024-05-09 20:11:56 C:\Windows\System32\drivers\sysdiag.sys
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\scenter.dll
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\libxscore.bundle
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\libxsse.dll
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\libcobra.dll
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\uactmon.dll
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\DuiLib.dll
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\HipsLog.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\HipsMain.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\HipsTray.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\HipsDaemon.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\HRUpdate.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\HRConfig.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\NetFlow.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\main.ui
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\hrconfig.ui
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\netflow.ui
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\Autoruns.ui
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\Autoruns.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\NetDiag.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\HRSwordui.ui
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\HRSword.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\RightClickMan.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\sysclean.ui
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\sysclean.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\FileShred.ui
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\FileShred.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\popblock.ui
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\PopBlock.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\leakrepair.ui
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\leakrepair.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\SysDiag.ui
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\bin\SysDiag.exe
2024-05-09 20:11:56 C:\Program Files (x86)\Huorong\Sysdiag\uninst.exe
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\virdb\hwl.db
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\virdb\prop.db
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\virdb\pset.db
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\virdb\troj.db
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\db\hips.db
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\db\wlst.db
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\db\urlcls.db
2024-05-09 20:11:57 C:\ProgramData\Huorong\Sysdiag\db\popblk.db
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【2】2024-05-09 14:06:17,系统防护,隐私设备保护,wwmapp.exe访问麦克风保护,已允许
防护类型:麦克风保护
操作结果:已允许
进程ID:22348
操作进程:C:\Program Files (x86)\WXWork\4.1.22.6014\WeMeet\wwmapp.exe
操作进程命令行:param=eyJzY2hlbWUiOiJ3ZW1lZXQ6Ly9wYWdlL2lubWVldGluZz9tZWV0aW5nX2NvZGU9NDE1MTQxOTczJnNjZW5lPTEmbWluaW1pemVfbW9kZT0tMSZmcm9tX2dyb3VwX2NoYXQ9MSZqb2luX3NlbmNlPXVua25vd24mc2hvd19mcmVlX21hcms9MCZ0aW1lc3RhbXA9MTcxNTIzNDc2MTQ4NyIsImlkIjoiMTYzNjY5ODUzNzIiLCJ0b2tlbiI6ImV5SmhiR2NpT2lKSVV6STFOaUlzSW5SNWNDSTZJa3BYVkNKOS5leUpoZFdRaU9pSlVaVzVqWlc1MElFMWxaWFJwYm1jaUxDSmxlSEFpT2pFM01UYzRNalkzTmpFc0ltbGhkQ0k2TVRjeE5USXpORGMyTVN3aWFYTnpJam9pTVRZek5qWTVPRFV6TnpJaWZRLm1jRWphOUtIQUoweE16QzJCWlNuNU90OW04UGc5bW1ETFZSRFEwRlZTcUUiLCJlbnZfbmFtZSI6InF3eHNldCIsImVudl9pZCI6IjEyMzUwIiwiZW52X2RlYnVnX21vZGUiOiIwIiwid3h3b3JrX3BpZCI6IjI0MjQiLCJlbnZfZG9tYWluIjp7InRjcCI6ImNvbm4ubWVldGluZy53b3JrLndlaXhpbi5xcS5jb20iLCJ3ZWJzb2NrZXQiOiJ3cy5tZWV0aW5nLndvcmsud2VpeGluLnFxLmNvbSIsImh0dHBDZ2kiOiJodHRwczovL2FwaS5tZWV0aW5nLndvcmsud2VpeGluLnFxLmNvbSIsIndlYiI6Im1lZXRpbmcudGVuY2VudC5jb20iLCJxdWljU2VydmVyIjoiY29ubnF1aWMubWVldGluZy53b3JrLndlaXhpbi5xcS5jb20iLCJxdWljU2VydmVyUG9ydCI6NDQzfSwiY29uZmlnIjp7Imxhbmd1YWdlIjoiemgtY24iLCJwcm94eSI6eyJpcCI6IiIsInBvcnQiOjgwL
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【3】2024-05-08 23:21:06,其他,升级日志,自动更新成功,版本号:6.0.0.25
升级方式:自动更新
升级结果:成功,版本号:6.0.0.25,病毒库时间:2024-05-08 21:45
下载文件:
2024-05-08 23:21:05 C:\ProgramData\Huorong\Sysdiag\virdb\hwl.db
2024-05-08 23:21:06 C:\ProgramData\Huorong\Sysdiag\virdb\troj.db
更新文件:
2024-05-08 23:21:06 C:\ProgramData\Huorong\Sysdiag\virdb\hwl.db
2024-05-08 23:21:06 C:\ProgramData\Huorong\Sysdiag\virdb\troj.db
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【4】2024-05-08 20:21:07,其他,升级日志,自动更新成功,版本号:6.0.0.25
升级方式:自动更新
升级结果:成功,版本号:6.0.0.25,病毒库时间:2024-05-08 18:51
下载文件:
2024-05-08 20:21:06 C:\ProgramData\Huorong\Sysdiag\virdb\hwl.db
2024-05-08 20:21:06 C:\ProgramData\Huorong\Sysdiag\virdb\prop.db
2024-05-08 20:21:06 C:\ProgramData\Huorong\Sysdiag\virdb\pset.db
2024-05-08 20:21:06 C:\ProgramData\Huorong\Sysdiag\virdb\troj.db
2024-05-08 20:21:07 C:\ProgramData\Huorong\Sysdiag\db\malurl.db
更新文件:
2024-05-08 20:21:07 C:\ProgramData\Huorong\Sysdiag\virdb\hwl.db
2024-05-08 20:21:07 C:\ProgramData\Huorong\Sysdiag\virdb\prop.db
2024-05-08 20:21:07 C:\ProgramData\Huorong\Sysdiag\virdb\pset.db
2024-05-08 20:21:07 C:\ProgramData\Huorong\Sysdiag\virdb\troj.db
2024-05-08 20:21:07 C:\ProgramData\Huorong\Sysdiag\db\malurl.db
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【5】2024-05-08 14:20:41,安全工具,垃圾清理,已手动清理25.0GB垃圾
扫描发现垃圾:28.3GB
共清理垃圾:25.0GB
清理详情
名称:常用软件日志;分类:百度产品日志;发现垃圾:312KB;清理垃圾:312KB
名称:常用软件日志;分类:腾讯产品日志;发现垃圾:87.1MB;清理垃圾:87.1MB
名称:系统缓存;分类:DirectX 着色器缓存;发现垃圾:3.3MB;清理垃圾:3.3MB
名称:系统缓存;分类:Windows更新传递优化文件;发现垃圾:17.8MB;清理垃圾:17.8MB
名称:系统缓存;分类:.NET 全局程序集缓存;发现垃圾:875MB;清理垃圾:875MB
名称:系统缓存;分类:缩略图缓存;发现垃圾:51.0MB;清理垃圾:51.0MB
名称:系统缓存;分类:自动更新补丁;发现垃圾:859MB;清理垃圾:859MB
名称:系统缓存;分类:预读文件缓存;发现垃圾:5.3MB;清理垃圾:5.3MB
名称:系统缓存;分类:CryptoAPI证书缓存;发现垃圾:865KB;清理垃圾:865KB
名称:系统缓存;分类:字体缓存文件;发现垃圾:74.6MB;清理垃圾:74.6MB
名称:系统缓存;分类:远程桌面缓存;发现垃圾:358MB;清理垃圾:358MB
名称:系统缓存;分类:WindowsDefender更新备份缓存;发现垃圾:175MB;清理垃圾:175MB
名称:系统缓存;分类:Windows Installer缓存;发现垃圾:14.9MB;清理垃圾:14.9MB
名称:系统临时文件;分类:内存转储文件;发现垃圾:291MB;清理垃圾:291MB
名称:系统临时文件;分类:临时文件;发现垃圾:19.6GB;清理垃圾:19.6GB
名称:系统日志;分类:系统日志文件;发现垃圾:13.2MB;清理垃圾:13.2MB
名称:系统日志;分类:Microsoft.NET Framework缓存文件;发现垃圾:732KB;清理垃圾:732KB
名称:系统日志;分类:设置日志文件;发现垃圾:12.0KB;清理垃圾:12.0KB
名称:系统日志;分类:Internet信息服务日志;发现垃圾:512KB;清理垃圾:512KB
名称:系统日志;分类:错误报告;发现垃圾:288KB;清理垃圾:288KB
名称:系统日志;分类:自动更新补丁日志;发现垃圾:6.3MB;清理垃圾:0KB
名称:Media Player;分类:Media Player;发现垃圾:4.0KB;清理垃圾:4.0KB
名称:Chrome;分类:Chrome浏览器升级文件;发现垃圾:354MB;清理垃圾:354MB
名称:Chrome;分类:Chrome浏览器缓存文件;发现垃圾:14.1MB;清理垃圾:14.1MB
名称:Microsoft Edge浏览器;分类:Microsoft Edge浏览器缓存;发现垃圾:22.8MB;清理垃圾:22.8MB
名称:火狐浏览器;分类:火狐浏览器崩溃报告;发现垃圾:0.1KB;清理垃圾:0.1KB
名称:火狐浏览器;分类:火狐浏览器缓存文件;发现垃圾:1.0GB;清理垃圾:1.0GB
名称:IE浏览器;分类:IE浏览器缓存;发现垃圾:6.3MB;清理垃圾:6.3MB
名称:微信;分类:微信聊天记录中的视频;发现垃圾:1.6GB;清理垃圾:1.6GB
名称:微信;分类:微信聊天记录中的图片;发现垃圾:136KB;清理垃圾:0KB
名称:微信;分类:微信缓存的图片;发现垃圾:606MB;清理垃圾:0KB
名称:微信;分类:微信日志;发现垃圾:204MB;清理垃圾:204MB
名称:腾讯QQ(NT);分类:QQ(NT)缓存;发现垃圾:2.3MB;清理垃圾:2.3MB
名称:百度网盘;分类:百度网盘日志;发现垃圾:996KB;清理垃圾:996KB
名称:WPS Office;分类:WPS Office缓存文件;发现垃圾:656KB;清理垃圾:0KB
名称:WPS Office;分类:WPS Office日志缓存;发现垃圾:35.4MB;清理垃圾:0KB
名称:WPS Office;分类:WPS Office日志;发现垃圾:20.5MB;清理垃圾:20.5MB
名称:WPS Office;分类:WPS Office更新缓存;发现垃圾:3.5MB;清理垃圾:0KB
名称:123云盘;分类:123云盘日志;发现垃圾:8.0KB;清理垃圾:0KB
名称:123云盘;分类:123云盘缓存;发现垃圾:20.1MB;清理垃圾:20.1MB
名称:系统相关;分类:无效Windows 服务;发现垃圾:0.1KB;清理垃圾:0.1KB
名称:程序相关;分类:无效的防火墙规则;发现垃圾:0.1KB;清理垃圾:0.1KB
名称:程序相关;分类:废弃的软件;发现垃圾:0.1KB;清理垃圾:0.1KB
名称:程序相关;分类:安装程序引用;发现垃圾:0.1KB;清理垃圾:0.1KB
名称:系统使用痕迹;分类:最近使用痕迹;发现垃圾:0.1KB;清理垃圾:0.1KB
名称:系统使用痕迹;分类:Search日志;发现垃圾:4.0MB;清理垃圾:4.0MB
名称:系统使用痕迹;分类:WindowsDefender扫描历史;发现垃圾:37.6MB;清理垃圾:0KB
名称:系统使用痕迹;分类:Windows 跳转列表;发现垃圾:132KB;清理垃圾:0KB
名称:系统使用痕迹;分类:最近打开文件;发现垃圾:1.4MB;清理垃圾:1.4MB
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【6】2024-05-07 20:07:00,其他,升级日志,自动更新成功,版本号:6.0.0.25
升级方式:自动更新
升级结果:成功,版本号:6.0.0.25,病毒库时间:2024-05-07 18:29
下载文件:
2024-05-07 20:07:00 C:\ProgramData\Huorong\Sysdiag\virdb\hwl.db
2024-05-07 20:07:00 C:\ProgramData\Huorong\Sysdiag\virdb\prop.db
2024-05-07 20:07:00 C:\ProgramData\Huorong\Sysdiag\virdb\pset.db
2024-05-07 20:07:00 C:\ProgramData\Huorong\Sysdiag\virdb\troj.db
2024-05-07 20:07:00 C:\ProgramData\Huorong\Sysdiag\db\behav.db
2024-05-07 20:07:00 C:\ProgramData\Huorong\Sysdiag\db\malurl.db
更新文件:
2024-05-07 20:07:00 C:\ProgramData\Huorong\Sysdiag\virdb\hwl.db
2024-05-07 20:07:00 C:\ProgramData\Huorong\Sysdiag\virdb\prop.db
2024-05-07 20:07:00 C:\ProgramData\Huorong\Sysdiag\virdb\pset.db
2024-05-07 20:07:00 C:\ProgramData\Huorong\Sysdiag\virdb\troj.db
2024-05-07 20:07:00 C:\ProgramData\Huorong\Sysdiag\db\behav.db
2024-05-07 20:07:00 C:\ProgramData\Huorong\Sysdiag\db\malurl.db
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【7】2024-05-07 14:12:44,网络防护,恶意网址拦截,svchost.exe尝试访问【tongji.upzxt.com/】,已阻止
风险分类:木马盗号
访问网址:tongji.upzxt.com/
操作结果:已阻止
进程ID:2620
操作进程:C:\Windows\System32\svchost.exe
操作进程命令行:C:\Windows\system32\svchost.exe -k NetworkService -p -s Dnscache
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
【8】2024-05-07 11:21:13,病毒防护,WEB扫描,发生扫描错误【www.xmind.net】,已添加到排除域名
发生扫描错误
网站:www.xmind.net
操作结果:已添加到排除域名
进程ID:17996
操作进程:C:\Program Files (x86)\XMind\XMind.exe
操作进程命令行:"C:\Program Files (x86)\XMind\XMind.exe"
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
|
|