瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中毒了,疑似灰鸽子,但好像又不是..高手看看

123   1  /  3  页   跳转

中毒了,疑似灰鸽子,但好像又不是..高手看看

中毒了,疑似灰鸽子,但好像又不是..高手看看

今天电脑一开机杀毒软件说检查到了病毒,目录在E:\Windows\IEXPLORE.exe,我上网搜了一下,看起来好像是灰鸽子木马,但我在安全模式下搜_.hook.dll,却只能搜到“mag_hook.dll”,可又没有“mag.exe”,“mag.dll”这两个文件。在任务管理器里有IEXPLORE.exe这个进程,而且不能结束,但CPU的使用率却正常,而且也能网速好像并没有慢很多,这是什么原因阿?

请问这是灰鸽子病毒么,应该怎么解决阿?非常感谢阿~~
最后编辑2006-12-02 20:01:31
分享到:
gototop
 

【回复“西域帕米尔”的帖子】
你看的那“黄历”太老了,没用。
用SREng扫日志贴上来看看。
gototop
 

谢谢斑竹~~不过我不是很懂啊,“黄历”太老是啥意思?汗~~另外,我对“SREng”也不是很了解,这个软件方便下载么?我等会去搜一下,昨天我搜另外的一个扫日志的老师搜不到,可能是我太菜了~~
gototop
 

HijackThis1.99.1
扫描日志上来
中文版:
http://free5.ys168.com/?aqfrs
gototop
 

终于扫描了,但是怎么看啊,高手帮忙,再谢~~
Logfile of HijackThis v1.99.1
Scan saved at 10:54:41, on 2006-11-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\SYSTEM32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\basfipm.exe
E:\WINDOWS\system32\lkcitdl.exe
E:\WINDOWS\system32\lkads.exe
E:\WINDOWS\system32\lktsrv.exe
E:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
F:\Program Files\National Instruments\MAX\nimxs.exe
F:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
E:\WINDOWS\system32\nisvcloc.exe
F:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
E:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
E:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Program Files\Common Files\Sogou PXP\p2psvr.exe
F:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Messenger\msmsgs.exe
E:\WINDOWS\system32\nipalsm.exe
E:\WINDOWS\system32\nipalsm.exe
E:\WINDOWS\system32\nipalsm.exe
F:\Program Files\National Instruments\LabVIEW 8.0\LabVIEW.exe
E:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
F:\Thunder Network\Thunder\Program\Thunder5.exe
E:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
E:\WINDOWS\system32\DllHost.exe
E:\WINDOWS\explorer.exe
E:\WINDOWS\system32\wscntfy.exe
I:\新建文件夹\Hijackthis扫描工具\HijackThis.exe

R3 - URLSearchHook: (no name) - {6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} - (no file)
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - E:\WINDOWS\system32\xunleibho_v13.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - E:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - E:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - E:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - E:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - E:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - E:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O3 - Toolbar: (no name) - {56A7DC70-E102-4408-A34A-AE06FEF01586} - (no file)
O3 - Toolbar: (no name) - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O4 - HKLM\..\Run: [KAVPersonal50] "F:\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - HKLM\..\Run: [TkBellExe] ; "E:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [ISUSPM Startup] ; E:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [niDevMon] F:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe
O4 - HKLM\..\Run: [StormCodec_Helper] "E:\Program Files\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [WinStar] E:\WINDOWS\IEXPL0RE.exe
O4 - HKLM\..\Run: [ATIPTA] ; E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dla] ; E:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "E:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMSCMig] ; E:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [ISUSScheduler] ; "E:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NIDAQmxDriverStatus] ;
O4 - HKLM\..\Run: [PHIME2002A] ; E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] ; E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [SoundMAXPnP] ; E:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [yassistse] ; "E:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ; E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] ; "E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoCAD 启动加速器.lnk = E:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: 绿鹰PC万能精灵.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - F:\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - E:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://E:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - F:\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - F:\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: Bysoo Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O9 - Extra 'Tools' menuitem: Bysoo Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: 易趣购物 - {DE607142-AC19-422e-864A-4D70ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=5 (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {DE607142-AC19-422e-864A-4D70ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=5 (file missing)
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: e:\windows\system32\aelupsvc32.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\aelupsvc32.dll
O16 - DPF: {18F57D30-EF36-4C0E-9343-7BFA6DF79B4A} (XLink Class) - http://active.micr0media.com/swflash.CAB
O16 - DPF: {48FE89A0-486C-48DF-9DEC-BED22BDC6057} (XIsOro Control) - http://www.sinago.com/download/OroCheck.cab
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89} - http://toolsbar.kuaiso.com/Kuaiso.cab
O16 - DPF: {D39A7678-3647-45FA-8E7B-727E9984BAC7} - http://dl.bysoo.com/bysooTBV10/bysoo.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB9A2D2A-1E38-43EA-94A0-329D22ACAF96}: NameServer = 202.119.208.10,202.102.24.35
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "E:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - E:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - E:\WINDOWS\system32\basfipm.exe
O23 - Service: kavsvc - Kaspersky Lab - F:\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - E:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments, Inc. - E:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments, Inc. - E:\WINDOWS\system32\lktsrv.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - F:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: nidevldu - National Instruments Corporation - E:\WINDOWS\system32\nipalsm.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments, Inc. - F:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - F:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: nimcdldu - National Instruments Corporation - E:\WINDOWS\system32\nipalsm.exe
O23 - Service: nimcrpcsu - National Instruments Corporation - E:\WINDOWS\system32\nipalsm.exe
O23 - Service: nipxirmu - National Instruments Corporation - E:\WINDOWS\system32\nipalsm.exe
O23 - Service: NiRioSvc - National Instruments Corporation - E:\WINDOWS\system32\nipalsm.exe
O23 - Service: niRTProxy - National Instruments Corporation - (no file)
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - E:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments, Inc. - F:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: P4P Service - Sohu.com Inc. - E:\Program Files\Common Files\Sogou PXP\p2psvr.exe

gototop
 

现在发现好像问题比昨天严重了,因为CPU的使用率一直是100%,但是网速好像并未受太大影响,咋回事哟?急死了

高人指点阿~~顿首再谢~~
gototop
 

E:\WINDOWS\system32\DllHost.exe
O4 - HKLM\..\Run: [WinStar] E:\WINDOWS\IEXPL0RE.exe
O10 - Unknown file in Winsock LSP: e:\windows\system32\aelupsvc32.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\aelupsvc32.dll
gototop
 

E:\WINDOWS\system32\nisvcloc.exe
这个文件是什么
gototop
 

O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - E:\WINDOWS\system32\nisvcloc.exe
还有这个
gototop
 

上面的兄台,是不是要把你说的这些删掉啊?请明示,谢谢!
gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT