瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了Backdoor.Gpigeon.pi。。先把扫描日志拿上来,高手帮看!!!

1   1  /  1  页   跳转

中了Backdoor.Gpigeon.pi。。先把扫描日志拿上来,高手帮看!!!

中了Backdoor.Gpigeon.pi。。先把扫描日志拿上来,高手帮看!!!

Logfile of HijackThis v1.99.2
Scan saved at 16:14:18, on 2005-10-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
F:\SKYNET\FIREWALL\pfw.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
F:\RISING\RISING\RAV\CCENTER.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
F:\广电客户端\ishare_user.exe
F:\腾讯\tt\TTraveler.exe
C:\DOCUME~1\user\LOCALS~1\Temp\HijackThis.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\Rundll32.exe

O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v8.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: BrowserHAP Class - {AEF6F648-78D8-4456-BEE7-5ADE23D209FD} - C:\Program Files\HBClient\hapast.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O4 - HKLM\..\Run: [SKYNET Personal FireWall] F:\SKYNET\FIREWALL\pfw.exe
O4 - HKLM\..\Run: [hbpassport] C:\PROGRA~1\HBCLIENT\hbast.exe
O4 - HKLM\..\Run: [VikaClient] "C:\Program Files\VIKA\vkclient.exe"
O8 - Extra context menu item: &使用迅雷下载 - F:\Thunder5\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\Thunder5\getAllurl.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\PROGRA~1\FLASHGET\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\PROGRA~1\FLASHGET\jc_all.htm
O9 - Extra button: 唯刊.VIKA - {2BB49E59-100F-4ca6-9127-E0E3FF76F98E} - C:\Program Files\VIKA\vkclient.exe.lnk
O9 - Extra 'Tools' menuitem: 唯刊.VIKA - {2BB49E59-100F-4ca6-9127-E0E3FF76F98E} - C:\Program Files\VIKA\vkclient.exe.lnk
O9 - Extra button: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - F:\豪杰V8\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - F:\豪杰V8\STHSDVD.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdog0.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdog0.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdogr0.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tcpipdogr0.dll
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: COM+ System Service (COMSSERV) - Unknown owner - C:\WINDOWS\Cursors\svchost.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - F:\RISING\RISING\RAV\CCENTER.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
最后编辑2005-10-14 16:19:30
分享到:
gototop
 

谢拉。。。我先在就去看
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT