123456   5  /  6  页   跳转

一只极其变态的灰鸽子

太厉害了,顶
gototop
 

楼主,帮我看看吧。实在是没办法了,不知道是哪个。
Logfile of HijackThis v1.99.1
Scan saved at 23:00:13, on 2006-5-13
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\MSSQL7\binn\sqlservr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\Fmctrl.EXE
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\MSSQL7\Binn\sqlmangr.exe
C:\Program Files\Rising\Rav\rav.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\ha_hijackthis_1991\HijackThis.exe
C:\WINNT\regedit.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - E:\wjh\SONG\新建文件夹\BitComet\BitCometBar\BitCometBar0.2.dll (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [FmctrlTray] Fmctrl.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [MNCN USB] C:\WINNT\system32\ShellExt\mncntray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\qq\QQ.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\MSSQL7\Binn\sqlmangr.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\qq\SendMMS.htm
O9 - Extra button: 卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll
O9 - Extra button: 金山词霸 - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - C:\PROGRA~1\Kingsoft\XDict\IEPlugin.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\qq\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\qq\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\qq\QQIEHelper.dll
O16 - DPF: ServerPushBox - http://www.jtjc.cn/cab/servp12.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {A3CD7F74-93C9-4BC4-B892-CCDF1514F714} (Submit Class) - https://pbank.95559.com.cn/personbank/ocx/safe.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{450A3A49-736B-42DF-8905-B607D495527B}: NameServer = 202.96.134.133,202.96.128.166
O17 - HKLM\System\CS1\Services\Tcpip\..\{450A3A49-736B-42DF-8905-B607D495527B}: NameServer = 202.96.134.133,202.96.128.166
O17 - HKLM\System\CS2\Services\Tcpip\..\{450A3A49-736B-42DF-8905-B607D495527B}: NameServer = 202.96.134.133,202.96.128.166
O20 - Winlogon Notify: System Safety Monitor - C:\WINNT\SYSTEM32\SSMWinlogonEx.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Network Management Center Task (W32Tasks) - Unknown owner - C:\WINNT\system32\taskman32.exe
瑞星查杀结果。
病毒名:Backdoor Gpigeon.cdd
文件名:IEXPLORE.EXE
文件路径:IEXPLORE.EXE>>C:\Program Files\Internet Explorer\IEXPLORE.EXE
清除成功。但重启后又有了。
先谢谢了。
gototop
 

【回复“songnanqiao”的帖子】
O23 - Service: Network Management Center Task (W32Tasks) - Unknown owner - C:\WINNT\system32\taskman32.exe
灰鸽子
查杀参考:http://forum.ikaka.com/topic.asp?board=28&artid=7713905
gototop
 

好好向斑竹学习呀,不让他们有机可乘哟
gototop
 

来迟了.这些日子常看到大叔用SSM调戏那些小马鸽,很有意思...
gototop
 

引用:
【baohe的贴子】
1、在IE中创建线程是鸽子的传统。
2、至于这样是不是更容易实现多线程插入,我不知道。我不动编程。
3、“在SSM中对IE的“系统控制”“代码注入”进行设置”——只是禁止其它程序插入IE,并不能阻止被恶意程序搞过的IE进程往其它进程中插入线程。
...........................

如果先把IE程序删到回收站,那鸽子会不会容易搞一点
gototop
 

引用:
【轩辕小聪的贴子】
如果先把IE程序删到回收站,那鸽子会不会容易搞一点
...........................

比较另类的想法!
你可以试试。
gototop
 

厉害!
gototop
 

我这几天中了一个很嚣张的灰鸽子,直接就显示在我计算机右下角托盘。
瑞星查毒根本没反应,下了专杀工具清除,再次开机又会跳出来,
好像用了什么进程隐藏,慢慢看了,晕
gototop
 

已阅
gototop
 
123456   5  /  6  页   跳转
页面顶部
Powered by Discuz!NT