瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » Backdoor.Gpigeon.2007.q
longkaini - 2007-4-3 23:16:00
跪求!这个毒总杀不掉咋办?总重新出来,杀完一开机又有了!
HijackThis_815汉化版扫描日志 V1.99.1
保存于      22:48:36, 日期 2007-4-3
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
E:\shadu\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
E:\shadu\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
e:\shadu\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
E:\shadu\Rising\Rav\RavStub.exe
e:\shadu\rising\rfw\RfwMain.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common

Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Rising\AntiSpyware\runiep.exe
E:\shadu\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wsttrs.exe
E:\shadu\Rising\Rav\Ravmon.exe
C:\WINDOWS\wgs3.exe
C:\Program Files\Common Files\ACD Systems\ACDSeeMC.EXE
C:\WINDOWS\system32\SVCH0ST.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
E:\shadu\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
E:\wenzicl\adobe\acrobat7.0\Distillr\AcroTray.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
e:\shadu\rising\rfw\SmartUp.exe
E:\压缩\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.063

\HijackThis1991zww.exe

R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-

ECA6A121BC78} - (no file)
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-

58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar0.dll
O2 - BHO: ThunderBHO - {06849E9E-C8D7-4D59-B87D-784B7D6BE0B3} -

E:\压缩\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-

784B7D6BE0B3} - E:\wenzicl\adobe\acrobat7.0

\ActiveX\AcroIEHelper.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} -

C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} -

C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} -

C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~2.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-

CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-

0445EE161910} - E:\wenzicl\adobe\acrobat7.0

\Acrobat\AcroIEFavClient.dll
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4A40-8DFD-

58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar0.dll
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-

009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1

\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [IntelZeroConfig] "C:\Program

Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - 启动项HKLM\\Run: [IntelWireless] "C:\Program

Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - 启动项HKLM\\Run: [igfxtray] C:\WINDOWS\system32

\igfxtray.exe
O4 - 启动项HKLM\\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - 启动项HKLM\\Run: [igfxpers] C:\WINDOWS\system32

\igfxpers.exe
O4 - 启动项HKLM\\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - 启动项HKLM\\Run: [SynTPEnh] C:\Program

Files\Synaptics\SynTP\SynTPEnh.exe
O4 - 启动项HKLM\\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - 启动项HKLM\\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1

\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - 启动项HKLM\\Run: [ISUSScheduler] "C:\Program Files\Common

Files\InstallShield\UpdateService\issch.exe" -start
O4 - 启动项HKLM\\Run: [runeip] C:\Program

Files\Rising\AntiSpyware\runiep.exe
O4 - 启动项HKLM\\Run: [RavTask]

"E:\shadu\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [RfwMain]

"E:\shadu\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [msccrt] C:\WINDOWS\msccrt.exe
O4 - 启动项HKLM\\Run: [wsttrs] C:\WINDOWS\wsttrs.exe
O4 - 启动项HKLM\\Run: [wgs3] C:\WINDOWS\wgs3.exe
O4 - 启动项HKLM\\Run: [mppsds] C:\WINDOWS\mppsds.exe
O4 - 启动项HKLM\\Run: [cmdbcs] C:\WINDOWS\cmdbcs.exe
O4 - 启动项HKLM\\RunOnce: [RavStub]

"E:\shadu\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [acdseemc.exe] C:\Program Files\Common

Files\ACD Systems\ACDSeeMC.EXE
O4 - HKCU\..\Run: [ravshell] C:\WINDOWS\system32\SVCH0ST.exe
O4 - HKCU\..\Run: [updateMgr] E:\wenzicl\adobe\acrobat7.0

\Acrobat\AdobeUpdateManager.exe AcPro7_0_0
O6 - HKCU\Software\Policies\Microsoft\Internet

Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control

Panel present
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - E:\压缩\Thunder

Network\Thunder\Program\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - E:\压缩

\Thunder Network\Thunder\Program\getallurl.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 -

E:\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) -

res://E:\wenzicl\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 -

E:\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 -

E:\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 添加到雅虎订阅(&Y) -

res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 -

E:\Tencent\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 转换为 Adobe PDF -

res://E:\wenzicl\adobe\acrobat7.0

\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - IE右键菜单中的新增项目: 转换为现有 PDF -

res://E:\wenzicl\adobe\acrobat7.0

\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - IE右键菜单中的新增项目: 转换选定的链接为 Adobe PDF -

res://E:\wenzicl\adobe\acrobat7.0

\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - IE右键菜单中的新增项目: 转换选定的链接为现有 PDF -

res://E:\wenzicl\adobe\acrobat7.0

\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - IE右键菜单中的新增项目: 转换选项为 Adobe PDF -

res://E:\wenzicl\adobe\acrobat7.0

\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - IE右键菜单中的新增项目: 转换选项为现有 PDF -

res://E:\wenzicl\adobe\acrobat7.0

\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - IE右键菜单中的新增项目: 转换链接目标为 Adobe PDF -

res://E:\wenzicl\adobe\acrobat7.0

\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - IE右键菜单中的新增项目: 转换链接目标为现有 PDF -

res://E:\wenzicl\adobe\acrobat7.0

\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:\PROGRA~1

\Yahoo!\ASSIST~1\Assist\yasbar0.dll/203
O9 - 浏览器额外的按钮: (no name) - RsAutorunsDisabled - (no

file)
O9 - 浏览器额外的按钮: (no name) - {08B0E5C0-4FCB-11CF-AAA5-

00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - 浏览器额外的“工具”菜单项: Sun Java 控制台 - {08B0E5C0-

4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - 浏览器额外的按钮: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-

C2A6C8E6B436} - E:\压缩\Thunder Network\Thunder\Thunder.exe
O9 - 浏览器额外的“工具”菜单项: 启动迅雷5 - {09BA8F6D-CB54-

424B-839C-C2A6C8E6B436} - E:\压缩\Thunder

Network\Thunder\Thunder.exe
O9 - 浏览器额外的按钮: 雅虎助手 - {5D73EE86-05F1-49ed-B850-

E423120EC338} - http://cn.zs.yahoo.com/start.htm?

source=yzs_icon&btn=yassistnew (file missing)
O9 - 浏览器额外的按钮: 信息检索 - {92780B25-18CC-41C8-B9BE-

3C9C571A8263} - E:\wenzicl\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-

00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-

F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {DC7094C6-8F61-42ED-AECE-63F5EEF647C5} (UpdateC2

Control) - http://www.uusee.com/player/updateC2.cab
O16 - DPF: {EF6205C1-3F17-4829-BCB5-1336ED89E356} -

http://online.jiangmin.com/KvDown.cab
O16 - DPF: {FCD61199-E187-4ADD-88E5-9AF238486D11} (CPPMediaCtrl

Object) - http://real.hbol.net/a_player/forceplayer.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-

94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - NT 服务: Intel(R) PROSet/Wireless Event Log (EvtEng) -

Intel Corporation - C:\Program

Files\Intel\Wireless\Bin\EvtEng.exe
O23 - NT 服务: Google Updater Service (gusvc) - Google -

C:\Program Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - NT 服务: NICCONFIGSVC - Dell Inc. - C:\Program

Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - NT 服务: Intel(R) PROSet/Wireless Registry Service

(RegSrvc) - Intel Corporation - C:\Program

Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - NT 服务: Rising Proxy  Service (RfwProxySrv) - Beijing

Rising Technology Co., Ltd. - e:\shadu\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) -

Beijing Rising Technology Co., Ltd. -

e:\shadu\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) -

Beijing Rising Technology Co., Ltd. -

E:\shadu\Rising\Rav\CCenter.exe
O23 - NT 服务: Rising RealTime Monitor (RsRavMon) - Beijing

Rising Technology Co., Ltd. - E:\shadu\Rising\Rav\Ravmond.exe
O23 - NT 服务: Intel(R) PROSet/Wireless Service

(S24EventMonitor) - Intel Corporation  - C:\Program

Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - NT 服务: systemu (Systen) - Unknown owner -

C:\WINDOWS\Systen.exe (file missing)
O23 - NT 服务: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER)

- Intel(R) Corporation - C:\Program

Files\Intel\Wireless\Bin\WLKeeper.exe
1
查看完整版本: Backdoor.Gpigeon.2007.q