瑞星卡卡安全论坛
六和铁风筝 - 2005-11-20 1:48:00
[求助]前几天中了灰鸽子,网速非常慢,用HIJACKTHIS扫描了,请大家帮忙分析和指点.谢谢.
O2 - BH ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v4.dll
O2 - BH IDDTInitObj Class - {15DDE989-CD45-4561-BF99-D22C0D5C2B74} - C:\PROGRA~1\sina\UC\UCddt\ddtinit.dll
O2 - BH KillObj Class - {66C28884-4E5D-494B-80C9-CAA27528FD6D} - C:\PROGRA~1\sina\UC\UCddt\ddtkillw.ocx
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (没有文件)
O3 - Toolbar: 新浪点点通 - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - C:\PROGRA~1\sina\UC\UCddt\DDTONG~1.DLL
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\BitComet\BitCometBar\BitCometBar0.2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - Extra context menu item: 使用彩信超级自写发送到手机 - http://mms.sina.com.cn/mmsnews.html
O8 - Extra context menu item: 使用新浪下载助手下载 - C:\PROGRA~1\sina\UC\UCddt\sinadl.htm
O8 - Extra context menu item: 发送图片到手机(&M) - http://sms.sina.com.cn/diy/send.html?from=467
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://c:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 收藏此页到新浪ViVi - http://vivi.sina.com.cn/collect/click.php?agent=ddt
O8 - Extra context menu item: 新浪搜索 - http://cha.sina.com.cn/ddt.html
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\QQ2005春节贺岁版\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\QQ2005春节贺岁版\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\QQ2005春节贺岁版\qq\SendMMS.htm
O9 - Extra button: 新浪UC - {2253922F-1B26-4C74-8B57-E3AEE748DBB8} - F:\UC\UC.exe
O9 - Extra button: 易趣购物 - {DE607143-AC19-423e-862A-2D70ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=5 (文件故障)
O9 - Extra 'Tools' menuitem: 易趣购物 - {DE607143-AC19-423e-862A-2D70ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=5 (文件故障)
O9 - Extra button: 新浪点点通 - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - C:\PROGRA~1\sina\UC\UCddt\DDTONG~1.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {974AD624-EA50-4831-A6C0-3040F6665396} - C:\PROGRA~1\sina\UC\UCddt\rssband.dll (HKCU)
O9 - Extra 'Tools' menuitem: 新浪点点通阅读器 - {974AD624-EA50-4831-A6C0-3040F6665396} - C:\PROGRA~1\sina\UC\UCddt\rssband.dll (HKCU)
O9 - Extra button: 新浪点点通阅读器 - {F0646DC8-58CD-4C64-8F6B-525043914685} - C:\PROGRA~1\sina\UC\UCddt\rssband.dll (HKCU)
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
此主题相关图片如下:
六和铁风筝 - 2005-11-20 1:48:00
同时我还用SRENG扫描了.请大家指点哪些是可疑的,教教我如何KILL掉,谢谢.
2005-11-20,01:34:48
System Repair Engineer 1.1.0.269
Windows XP Professional Service Pack 2 - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Smapp><C:\Program Files\Analog Devices\SoundMAX\SMTray.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<AVG7_CC><C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<AVG7_EMC><C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavTimer><C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RavMon><C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\Windows\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
==================================
启动文件夹
服务
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\system32\Ati2evxx.exe><N/A>
[ATI Smart / ATI Smart]
<C:\WINDOWS\system32\ati2sgag.exe><N/A>
[AVG7 Alert Manager Server / Avg7Alrt]
<C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe><GRISOFT, s.r.o.>
[AVG7 Update Service / Avg7UpdSvc]
<C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe><GRISOFT, s.r.o.>
[Macromedia Licensing Service / Macromedia Licensing Service]
<"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[Rising Personal Firewall Service / RfwService]
<C:\Program Files\Rising\Rfw\rfwsrv.exe><Beijing Rising Technology Corporation Limited>
[Rising Process Communication Center / RsCCenter]
<C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE><rising>
[RsRavMon Service / RsRavMon]
<C:\PROGRAM FILES\RISING\RAV\Ravmond.exe><Beijing Rising Technology Co., Ltd.>
[SoundMAX Agent Service / SoundMAX Agent Service (default)]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
==================================
浏览器加载项
[ThunderIEHelper Class]
<C:\WINDOWS\system32\xunleibho_v4.dll>
[新浪UC]
<F:\UC\UC.exe>
[易趣购物]
<http://click2.ad4all.net/url2/urlmanage/url.asp?id=5>
[Messenger]
<C:\Program Files\Messenger\msmsgs.exe>
[BitCometBar]
<C:\Program Files\BitComet\BitCometBar\BitCometBar0.2.dll>
[Shockwave ActiveX Control]
<C:\WINDOWS\system32\macromed\Shockwave 10\Download.dll>
[WebActivater Control]
<C:\WINDOWS\system32\WEBACT~1.OCX>
[Shockwave Flash Object]
<C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx>
[ThunderIEHelper Class]
<C:\WINDOWS\system32\xunleibho_v4.dll>
[Windows Media Player]
<C:\WINDOWS\system32\wmpdxm.dll>
[BitCometBar]
<C:\Program Files\BitComet\BitCometBar\BitCometBar0.2.dll>
[Microsoft Web 浏览器]
<C:\WINDOWS\system32\shdocvw.dll>
[Shockwave Flash Object]
<C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx>
[&使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\geturl.htm>
[&使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\getAllurl.htm>
[导出到 Microsoft Office Excel(&X)]
<res://c:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000>
[收藏此页到新浪ViVi]
<http://vivi.sina.com.cn/collect/click.php?agent=ddt>
[新浪搜索]
<http://cha.sina.com.cn/ddt.html>
[添加到QQ自定义面板]
<F:\QQ2005春节贺岁版\qq\AddPanel.htm>
[添加到QQ表情]
<F:\QQ2005春节贺岁版\qq\AddEmotion.htm>
[用QQ彩信发送该图片]
<F:\QQ2005春节贺岁版\qq\SendMMS.htm>
==================================
六和铁风筝 - 2005-11-20 1:53:00
==================================
正在运行的进程
[PID: 472][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 528][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 552][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 596][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 608][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 760][C:\WINDOWS\system32\Ati2evxx.exe] <N/A><N/A>
[PID: 772][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 828][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 936][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\System32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 1020][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 1088][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 1108][C:\PROGRAM FILES\RISING\RAV\Ravmond.exe] <Beijing Rising Technology Co., Ltd.><17, 0, 1, 57>
[C:\PROGRAM FILES\RISING\RAV\guidll.dll] <rising><17, 0, 0, 13>
[C:\PROGRAM FILES\RISING\RAV\RsCommX.dll] <rising><17, 0, 0, 3>
[C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL] <Rising Corp.><17, 0, 0, 7>
[C:\PROGRAM FILES\RISING\RAV\CfgDll.dll] <rising><17, 0, 0, 60>
[C:\Program Files\Rising\Rav\Scanner.dll] <Rising><17, 0, 0, 43>
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
[C:\Program Files\Rising\Rav\libload.dll] <Rising><17, 0, 0, 14>
[C:\Program Files\Rising\Rav\VirusLib.dll] <Rising><17, 0, 0, 26>
[C:\PROGRAM FILES\RISING\RAV\MailMon.dll] < ><17, 0, 0, 9>
[C:\Program Files\Rising\Rav\engine.dll] <rising><17, 0, 0, 39>
[C:\Program Files\Rising\Rav\UnExe.dll] <Rising><17, 0, 0, 27>
[C:\Program Files\Rising\Rav\SpamEng.dll] <N/A><17, 0, 0, 7>
[C:\Program Files\Rising\Rav\ScanEx.dll] <Rising><17, 0, 0, 33>
[C:\PROGRAM FILES\RISING\RAV\MemMon.dll] <北京瑞星><17, 8, 0, 0>
[C:\Program Files\Rising\Rav\PostTrt.dll] <Rising><17, 0, 0, 21>
[C:\Program Files\Rising\Rav\NvFile.dll] <瑞星><17, 0, 0, 13>
[C:\PROGRAM FILES\RISING\RAV\expscan.dll] <N/A><17, 0, 0, 6>
[C:\Program Files\Rising\Rav\ScanMac.dll] <rising><17, 0, 0, 17>
[C:\Program Files\Rising\Rav\ScanSct.dll] <rising><17, 0, 0, 29>
[C:\Program Files\Rising\Rav\ScanExec.dll] <N/A><17, 0, 0, 21>
[C:\Program Files\Rising\Rav\Unpacker.dll] <rising><17, 0, 0, 19>
[C:\Program Files\Rising\Rav\ExtFile.dll] <rising><17, 0, 0, 42>
[C:\PROGRAM FILES\RISING\RAV\mPorts.dll] <Beijing Rising Technology Corporation Limited><3, 0, 0, 3>
[C:\PROGRAM FILES\RISING\RAV\regmon.dll] < ><17, 0, 0, 12>
[C:\PROGRAM FILES\RISING\RAV\HookWeb.dll] <rising><17, 0, 0, 4>
[C:\Program Files\Rising\Rav\ExtOLE.dll] <rising><17, 0, 0, 20>
[C:\Program Files\Rising\Rav\ExtMail.dll] <瑞星><17, 0, 0, 15>
[PID: 1132][C:\PROGRAM FILES\RISING\RAV\RavStub.exe] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 27>
[C:\PROGRAM FILES\RISING\RAV\RsCommX.dll] <rising><17, 0, 0, 3>
[C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
[PID: 1152][C:\Program Files\Rising\Rfw\rfwsrv.exe] <Beijing Rising Technology Corporation Limited><3, 2, 0, 0>
[C:\Program Files\Rising\Rfw\Rfwdrv.dll] <Beijing Rising Technology Corporation Limited><3, 0, 1, 5>
[C:\Program Files\Rising\Rfw\rfwrule.dll] <Beijing Rising Technology Corporation Limited><3, 1, 0, 0>
[C:\Program Files\Rising\Rfw\rfwlog.dll] <Beijing Rising Technology Corporation Limited><3, 1, 0, 2>
[PID: 1308][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 1504][C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe] <GRISOFT, s.r.o.><7,1,0,357>
[C:\PROGRA~1\Grisoft\AVGFRE~1\avglog.dll] <GRISOFT, s.r.o.><7,1,0,349>
[C:\Program Files\Grisoft\AVG Free\avgcfg.dll] <GRISOFT, s.r.o.><7,1,0,349>
[C:\Program Files\Grisoft\AVG Free\avgklib.dll] <GRISOFT, s.r.o.><7,1,0,321>
[C:\Program Files\Grisoft\AVG Free\avglng.dll] <GRISOFT, s.r.o.><7,1,0,349>
[C:\Program Files\Grisoft\AVG Free\avgamint.dll] <GRISOFT, s.r.o.><7,1,0,349>
[C:\Program Files\Grisoft\AVG Free\avgamsps.dll] <GRISOFT, s.r.o.><7,1,0,285>
六和铁风筝 - 2005-11-20 2:04:00
[PID: 1584][C:\WINDOWS\Explorer.EXE] <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <N/A><17, 0, 0, 8>
[C:\Program Files\WinRAR\rarext.dll] <N/A><N/A>
[C:\WINDOWS\system32\RAVEXT.DLL] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 8>
[C:\Program Files\Grisoft\AVG Free\avgse.dll] <GRISOFT, s.r.o.><7,1,0,354>
[C:\WINDOWS\system32\xunleibho_v4.dll] <N/A><4, 3, 2, 29>
[PID: 1644][C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe] <GRISOFT, s.r.o.><7,1,0,349>
[PID: 1776][C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE] <rising><17, 0, 0, 1>
[PID: 1796][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] <Analog Devices, Inc.><3, 2, 6, 0>
[PID: 1860][C:\WINDOWS\system32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1948][C:\Program Files\Rising\Rfw\RfwMain.exe] <Beijing Rising Technology Corporation Limited><3, 1, 0, 19>
[C:\Program Files\Rising\Rfw\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 40>
[C:\Program Files\Rising\Rfw\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
[C:\Program Files\Rising\Rfw\PngDll.dll] <Rising><17, 0, 0, 2>
[PID: 204][C:\Program Files\Analog Devices\SoundMAX\SMTray.exe] <Analog Devices, Inc.><3, 2, 17, 0>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 272][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe] <ATI Technologies, Inc.><6.14.10.5120>
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll] <ATI Technologies, Inc.><6.14.10.5120>
[C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS] <ATI Technologies, Inc.><6.14.10.5120>
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll] <ATI Technologies, Inc.><6.14.10.5120>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 392][C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe] <GRISOFT, s.r.o.><7,1,0,362>
[C:\PROGRA~1\Grisoft\AVGFRE~1\libsasl.dll] <GRISOFT, s.r.o.><7,1,0,285>
[C:\Program Files\Grisoft\AVG Free\avgcfg.dll] <GRISOFT, s.r.o.><7,1,0,349>
[C:\Program Files\Grisoft\AVG Free\avgklib.dll] <GRISOFT, s.r.o.><7,1,0,321>
[C:\Program Files\Grisoft\AVG Free\avglng.dll] <GRISOFT, s.r.o.><7,1,0,349>
[C:\Program Files\Grisoft\AVG Free\avgscan.dll] <GRISOFT, s.r.o.><7,1,0,357>
[C:\Program Files\Grisoft\AVG Free\avgunarc.dll] <GRISOFT, s.r.o.><7,1,0,354>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[C:\PROGRA~1\Grisoft\AVGFRE~1\saslcrammd5.dll] <GRISOFT, s.r.o.><7,1,0,285>
[C:\PROGRA~1\Grisoft\AVGFRE~1\sasldigestmd5.dll] <GRISOFT, s.r.o.><7,1,0,285>
[C:\PROGRA~1\Grisoft\AVGFRE~1\sasllogin.dll] <GRISOFT, s.r.o.><7,1,0,285>
[C:\PROGRA~1\Grisoft\AVGFRE~1\saslplain.dll] <GRISOFT, s.r.o.><7,1,0,300>
[C:\Program Files\Grisoft\AVG Free\avgmail.dll] <GRISOFT, s.r.o.><7,1,0,358>
[PID: 412][C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 39>
[C:\PROGRA~1\RISING\RAV\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
[C:\PROGRA~1\RISING\RAV\RSAPPMGR.DLL] <Rising Corp.><17, 0, 0, 7>
[C:\PROGRA~1\RISING\RAV\CfgDll.dll] <rising><17, 0, 0, 60>
[C:\PROGRA~1\RISING\RAV\RsCommX.dll] <rising><17, 0, 0, 3>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 420][C:\PROGRA~1\RISING\RAV\RAVMON.EXE] <Beijing Rising Technology Co., Ltd.><17, 0, 1, 37>
[C:\PROGRA~1\RISING\RAV\RsGuiLib.dll] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 40>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[C:\PROGRA~1\RISING\RAV\RSAPPMGR.DLL] <Rising Corp.><17, 0, 0, 7>
[C:\PROGRA~1\RISING\RAV\CfgDll.dll] <rising><17, 0, 0, 60>
[C:\PROGRA~1\RISING\RAV\RsCommX.dll] <rising><17, 0, 0, 3>
[C:\PROGRA~1\RISING\RAV\PngDll.dll] <Rising><17, 0, 0, 2>
[C:\PROGRA~1\RISING\RAV\RSCOMMON.DLL] <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
[PID: 500][C:\WINDOWS\system32\ctfmon.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 2240][C:\WINDOWS\System32\alg.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\System32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 2704][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\System32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 172][F:\QQ2005春节贺岁版\tt\TTraveler.exe] <腾讯公司><2, 2, 0, 224>
[F:\QQ2005春节贺岁版\tt\PersonalDesktop.dll] <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[C:\Program Files\Rising\Rav\RavScrCh.dll] <N/A><17, 0, 0, 8>
[C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx] <Macromedia, Inc.><8,0,22,0>
[C:\WINDOWS\system32\msdmo.dll] <N/A><N/A>
[PID: 4100][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 4972][E:\反间谍软件\ha-hijackthis1991-xqb\HijackThis.exe] <Soeperman Enterprises Ltd.><1.99.0001>
[PID: 2532][C:\WINDOWS\system32\mspaint.exe] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 4568][C:\WINDOWS\system32\NOTEPAD.EXE] <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[C:\WINDOWS\system32\SYNCOR11.DLL] <SoundMAX><1.2.3>
[PID: 4484][E:\反间谍软件\SREng.exe] <Smallfrogs Studio><1.1.0.269>
==================================
文件关联
.TXT OK. [C:\WINDOWS\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [C:\WINDOWS\System32\winhlp32.exe %1]
.INI OK. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
还有一个可能大家要笑话我的问题,我的瑞星2005正版,自从这次中毒以后,再也不能升级.总出现什么:序列号使用过多,无法升级.
这该如何解决,希望大虾能帮帮我,我也想进步.建设中国,打倒美国....
六和铁风筝 - 2005-11-20 19:00:00
怎么没人理我啊,大家帮帮忙,谢谢!
笑乐 - 2005-11-20 19:02:00
你用的HIJACKTHIS版本过旧
神无 - 2005-11-20 19:49:00
http://forum.ikaka.com/topic.asp?board=28&artid=6979213用一楼附件里的再扫一个.
七彩黄花菜萱草 - 2005-11-20 22:22:00
Hijackthis日志不全.SREng日志没看出灰鸽子.杀软有报什么?
断网,清空IE临时文件夹, 禁用系统还原(Me,XP),用最新版本瑞星杀毒.
必要时在安全模式或DOS下全面查杀.
六和铁风筝 - 2005-11-20 23:13:00
我重新扫描过了:
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 23:09:00, 日期 2005-11-20
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Rising\Rfw\RfwMain.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\WINDOWS\system32\ctfmon.exe
E:\反间谍软件\2535952005811174944\HijackThis1991zww.exe
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v4.dll
O3 - IE工具栏增项: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - IE工具栏增项: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (no file)
O3 - IE工具栏增项: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\BitComet\BitCometBar\BitCometBar0.2.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - 启动项HKLM\\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 启动项HKLM\\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - 启动项HKLM\\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - 启动项HKLM\\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - 启动项HKLM\\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - 启动项HKLM\\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://c:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 收藏此页到新浪ViVi - http://vivi.sina.com.cn/collect/click.php?agent=ddt
O8 - IE右键菜单中的新增项目: 新浪搜索 - http://cha.sina.com.cn/ddt.html
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - F:\QQ2005春节贺岁版\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - F:\QQ2005春节贺岁版\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - F:\QQ2005春节贺岁版\qq\SendMMS.htm
O9 - 浏览器额外的按钮: 新浪UC - {2253922F-1B26-4C74-8B57-E3AEE748DBB8} - F:\UC\UC.exe
O9 - 浏览器额外的按钮: 易趣购物 - {DE607143-AC19-423e-862A-2D70ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=5 (file missing)
O9 - 浏览器额外的“工具”菜单项: 易趣购物 - {DE607143-AC19-423e-862A-2D70ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=5 (file missing)
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4BFB03E9-D6F7-48AD-A961-727A0FD87578}
O17 - HKLM\System\CS1\Services\Tcpip\..\{4BFB03E9-D6F7-48AD-A961-727A0FD87578}
O23 - NT 服务: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - NT 服务: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - NT 服务: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - C:\Program Files\Rising\Rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - NT 服务: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
飓风小子 - 2005-11-20 23:23:00
O23 - NT 服务: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - NT 服务: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
初步判断,还是要请高手看一下
影子110 - 2005-11-21 11:53:00
C:\PROGRA~1\Grisoft\AVGFRE~1
你看看这个是不是你装的什么软件的路径~~~
另,鸽子的文件名是什么~~及杀软显示的文件路径~(在日志中已经看不到什么了~)
可以用下面的方法先试一下看看~~~
| 引用: |
【七彩黄花菜萱草的贴子】 断网,清空IE临时文件夹, 禁用系统还原(Me,XP),用最新版本瑞星杀毒. 必要时在安全模式或DOS下全面查杀.
........................... |
我的电脑》属性》系统还原》关闭所有盘的系统还原》确定
清空临时文件夹:
IE》属性》删除文件(包括脱机文件)》确定
我不郁闷 - 2005-11-21 12:28:00
同意9楼的,确实可疑!修复先!
天天泡泡 - 2005-11-21 21:39:00
你的日志中的确没有看到灰鸽子2005,不过这两项:O17 - HKLM\System\CCS\Services\Tcpip\..\{4BFB03E9-D6F7-48AD-A961-727A0FD87578}
O17 - HKLM\System\CS1\Services\Tcpip\..\{4BFB03E9-D6F7-48AD-A961-727A0FD87578}
有点奇怪,没有看到之后的IP。
PS.楼上的一些朋友,AVG是一款来自捷克的杀毒软件,有免费版本。
七彩黄花菜萱草 - 2005-11-21 22:07:00
| 引用: |
【天天泡泡的贴子】你的日志中的确没有看到灰鸽子2005,不过这两项:O17 - HKLM\System\CCS\Services\Tcpip\..\{4BFB03E9-D6F7-48AD-A961-727A0FD87578} O17 - HKLM\System\CS1\Services\Tcpip\..\{4BFB03E9-D6F7-48AD-A961-727A0FD87578} 有点奇怪,没有看到之后的IP。
PS.楼上的一些朋友,AVG是一款来自捷克的杀毒软件,有免费版本。 ........................... |
谢谢泡泡,
那楼主同时又装了瑞星,会不会是冲突引起的卡机呢?
六和铁风筝 - 2005-11-24 21:52:00

谢谢各位,那就是没有什么可疑进程了?我在硬盘搜索了一堆这些东西,是什么啊?
AVG是一款不错的杀软,升级快.
天天网 - 2005-11-24 23:22:00
最好用一套监控
bridgewr - 2005-11-24 23:45:00
推荐楼主到www.micropoint.com.cn下载微点主动防御软件,有了这个软件你就能自己解决问题了,我壮丽个,感觉不错.
末妍 - 2005-11-25 0:05:00
对呀试试微点啦
六和铁风筝 - 2005-11-26 20:23:00
谢谢各位!!
1
© 2000 - 2026 Rising Corp. Ltd.