|
初生襁褓狮
|
发表于:
2006-07-05 20:04
|
显示全部
短消息
资料
灰鸽子病毒为什么在安全模式下找不到其行踪?
我的WINDOWS XP 在任务管理器多出1进程iexplore.exe.其路径为C:\Program Files\Internet Explorer\iexplore.exe.用灰鸽子专杀提示发现灰鸽子病毒名为BACKDOOR.GPIGEON但是由于其隐藏进程,无法提取。在安全模式下全部按照卡卡社区首页关于手动杀除灰鸽子的方法,但却查找不到其GAME开头的2个文件和键盘记录文件。下面附上瑞星听诊器扫描结果,希望大家帮忙看看。人在线等。 未知家族病毒分析 扫描结果: C:\Program Files\Internet Explorer\IEXPLORE.EXE --> 与 Backdoor.Gpigeon 100%相似. HijackThis_815汉化版扫描日志 V1.99.1 保存于 20:33:28, 日期 2006-7-5 操作系统: Windows XP SP1 (WinNT 5.01.2600) 浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Rising\Rav\CCenter.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Rising\Rfw\rfwsrv.exe C:\WINDOWS\system32\spoolsv.exe D:\Program Files\磁盘碎片整理\DkService.exe D:\Program Files\ewido anti-malware\ewidoctrl.exe D:\Program Files\ewido anti-malware\ewidoguard.exe C:\WINDOWS\System32\nvsvc32.exe D:\Program Files\Stardock\Object Desktop\ThemeManager\wbload.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Rising\Rfw\RfwMain.exe C:\WINDOWS\System32\Internat.exe C:\Program Files\jj4\jjsvr4.exe C:\Program Files\Rising\Rav\RAVTASK.EXE C:\Program Files\Rising\Rav\Ravmond.exe C:\Program Files\Rising\Rav\RAVMON.EXE C:\DOCUME~1\luo\LOCALS~1\Temp\Rar$EX00.406\HijackThis1991zww.exe
R3 - 默认的URLSearchHook丢失。用HijackThis修复 O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - IE工具栏增项: BitComet工具栏 - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - D:\Program Files\BitComet\BitCometBar\BitCometBar0.5.dll O3 - IE工具栏增项: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - (no file) O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\KakaTool.dll O4 - 启动项HKLM\\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system O4 - 启动项HKLM\\Run: [Thunder] ; "C:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - 启动项HKLM\\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - 启动项HKLM\\Run: [StormCodec_Helper] ; "D:\Program Files\Storm Codec\StormSet.exe" /S /opti O4 - 启动项HKLM\\Run: [DiskeeperSystray] "D:\Program Files\磁盘碎片整理\DkIcon.exe" O4 - 启动项HKLM\\Run: [WingKav] D:\Program Files\流行病毒统杀工具2006\WingKav2006.exe O4 - HKCU\..\Run: [pyjj] ; C:\Program Files\jj4\jjsvr4.exe O4 - HKCU\..\Run: [Super Rabbit IEPro] ; C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD O4 - HKCU\..\Run: [Internat.exe] Internat.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: DSLMON.lnk = ? O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm O8 - IE右键菜单中的新增项目: Google 搜索(&G) - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - 浏览器额外的按钮: 百万图库 - {6713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/star (file missing) (HKCU) O9 - 浏览器额外的“工具”菜单项: 百万图库 - {6713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/star (file missing) (HKCU) O9 - 浏览器额外的按钮: 铃声图片下载 - {7713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/sms/index.htm (file missing) (HKCU) O9 - 浏览器额外的“工具”菜单项: 铃声图片下载 - {7713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/sms/index.htm (file missing) (HKCU) O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing O16 - DPF: {05DA0521-0B6B-458C-BFB1-1EFEF1F3C8FF} (SSOClientAgent Class) - http://member.segame.com/common/SEGAme.cab O16 - DPF: {0CBF7EDC-17EC-442C-8AE9-5E804707B6CA} (NeffyClient Class) - http://dist.cdnetworks.co.kr/cdndist/neffy/Neffy.cab O16 - DPF: {43E839C5-E10F-443A-BC1F-F09CFD2ABC77} (updatePanelX Control) - http://www.uusee.com/jmd/player/updateC.cab O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab O16 - DPF: {53AF6E02-F18F-4228-AC13-3E79773FBE50} (CMCBooter Object) - http://download.mysee.com/plugin/booter.cab O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} ({5DD731E6-D4F0-11D3-BE3F-00105A6FDA50}) - http://www.zvc.com.cn/zvconline/plugin/myv3na.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1132573878570 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1134293541781 O16 - DPF: {81BF1A75-0075-4525-9E2F-51076A4DE7B1} (SlangFilter Control) - http://images.segame.com/_cab/SEGAmeCtrls.cab O16 - DPF: {87CCFDB0-C4BE-4BC2-A78C-9EAA7CF96667} - http://ps.itv.mop.com/dn/files/vodupdate_1.0.0.8_20051009.cab O16 - DPF: {C661F36D-DF85-4EF4-83C7-E107B83D04B1} (WebActivater Control) - http://dl_dir.qq.com/3dshow/3DShowVM.cab O16 - DPF: {E1CE4482-98E9-48F8-8D0D-EF03BC9E26F3} (BugsGameStarts Class) - http://audition.bugs.co.kr/Game/BugsGameStart.cab O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl Object) - https://www.tenpay.com/download/qqedit.cab O16 - DPF: {F6119B33-74FB-42C8-862E-FA3A5AAB9F5A} (LiteHtmlInstall Class) - http://update.biget.com/BiGetInst.cab O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} - http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.84_20060511.cab O20 - Winlogon Notify: WB - D:\Program Files\Stardock\Object Desktop\ThemeManager\fastload.dll O23 - NT 服务: Diskeeper - Diskeeper Corporation - D:\Program Files\磁盘碎片整理\DkService.exe O23 - NT 服务: ewido security suite control - ewido networks - D:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - NT 服务: ewido security suite guard - ewido networks - D:\Program Files\ewido anti-malware\ewidoguard.exe O23 - NT 服务: Kingsoft Personal Firewall Service (KPfwSvc) - Unknown owner - C:\KAV2006\KPfwSvc.EXE (file missing) O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - NT 服务: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rfw\rfwsrv.exe O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe O23 - NT 服务: OnQueueFileOps (sysmain) - Unknown owner - C:\WINDOWS\DAEMON
 2006-07-05 23:47:48
|