我把SXE的信息弄出来了。大家一切来我这里已经结束了以下
Mutant \BaseNamedObjects\checks
Mutant \BaseNamedObjects\checks
Mutant \BaseNamedObjects\ShimCacheMutex
Mutant \BaseNamedObjects\WininetStartupMutex
下面是全部,大家不自己找着测试,回个帖子谁要结束那个分工这样咱们才能成功快点是不!
进程 PID CPU 描述 公司名
系统空闲进程 0 90.15
中断 n/a 硬件中断
DPCs n/a 延缓程序调用
sXe Injected.exe 840
prdddocexp.exe 1164 7.58 Sysinternals Process Explorer Sysinternals 汉化: fengdaolong
进程: sXe Injected.exe Pid: 840
类型 名称
Desktop \Default
Directory \KnownDlls
Directory \Windows
Directory \BaseNamedObjects
Event \BaseNamedObjects\crypt32LogoffEvent
Event \BaseNamedObjects\userenv: User Profile setup event
File C:\Program Files\sXe Injected
File \Device\KsecDD
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03
File C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
File C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
File C:\Documents and Settings\Administrator\Cookies\index.dat
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03
File \Device\NamedPipe\ROUTER
File \Device\Tcp
File \Device\Tcp
File \Device\Ip
File \Device\Ip
File \Device\Ip
File \Device\NamedPipe\ROUTER
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03
File \Device\ddsxei
File C:\Program Files\sXe Injected\sXe Injected.exe
Key HKLM
Key HKCU
Key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Key HKLM\SOFTWARE\sXe_Injected
Key HKLM\SOFTWARE\sXe_Injected
Key HKLM\SOFTWARE\sXe_Injected
Key HKLM\SOFTWARE\sXe_Injected
Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9
Key HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
Key HKLM\SOFTWARE\Microsoft\Tracing\RASAPI32
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Linkage
Key HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters
Key HKLM\SYSTEM\ControlSet001\Services\NetBT\Parameters\Interfaces
Key HKLM\SYSTEM\ControlSet001\Services\NetBT\Parameters
Key HKU
Key HKCU
Key HKLM\SYSTEM\ControlSet001\Hardware Profiles\Current
Key HKCU\Software\Classes
Key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Key HKLM\SOFTWARE\sXe_Injected
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Locale
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Language Groups
Key HKLM\SOFTWARE\sXe_Injected
KeyedEvent \KernelObjects\CritSecOutOfMemoryEvent
Mutant \BaseNamedObjects\DBWinMutex
Mutant \BaseNamedObjects\sXe Injected
Mutant \BaseNamedObjects\_!MSFTHISTORY!_
Mutant \BaseNamedObjects\c:!documents and settings!administrator!cookies!
Mutant \BaseNamedObjects\c:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Mutant \BaseNamedObjects\WininetStartupMutex
Mutant \BaseNamedObjects\c:!documents and settings!administrator!local settings!history!history.ie5!
Mutant \BaseNamedObjects\WininetConnectionMutex
Mutant \BaseNamedObjects\WininetProxyRegistryMutex
Mutant \BaseNamedObjects\RasPbFile
Mutant \BaseNamedObjects\ZonesCounterMutex
Mutant \BaseNamedObjects\ZonesCacheCounterMutex
Mutant \BaseNamedObjects\ZonesLockedCacheCounterMutex
Mutant \BaseNamedObjects\checks
Mutant \BaseNamedObjects\checks
Mutant \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-21-1644491937-1604221776-725345543-500
Mutant \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-21-1644491937-1604221776-725345543-500
Mutant \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-21-1644491937-1604221776-725345543-500
Mutant \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-21-1644491937-1604221776-725345543-500
Mutant \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-21-1644491937-1604221776-725345543-500
Mutant \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-1644491937-1604221776-725345543-500MUTEX.DefaultS-1-5-21-1644491937-1604221776-725345543-500
Mutant \BaseNamedObjects\ShimCacheMutex
Mutant \BaseNamedObjects\MSCTF.Shared.MUTEX.IIG
Section \BaseNamedObjects\C:_Documents and Settings_Administrator_Cookies_index.dat_32768
Section \BaseNamedObjects\C:_Documents and Settings_Administrator_Local Settings_Temporary Internet Files_Content.IE5_index.dat_32768
Section \BaseNamedObjects\C:_Documents and Settings_Administrator_Local Settings_History_History.IE5_index.dat_65536
Section \BaseNamedObjects\SENS Information Cache
Section \BaseNamedObjects\UrlZonesSM_Administrator
Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-1644491937-1604221776-725345543-500
Section \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-1644491937-1604221776-725345543-500SFM.DefaultS-1-5-21-1644491937-1604221776-725345543-500
Section \BaseNamedObjects\ShimSharedMemory
Section \BaseNamedObjects\MSCTF.Shared.SFM.IIG
Semaphore \BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}
Semaphore \BaseNamedObjects\shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}
WindowStation \Windows\WindowStations\WinSta0
WindowStation \Windows\WindowStations\WinSta0
这是SXE的句柄信息!