瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » Backdoor.Gpigeon.uql .杀不干净
申苓白术 - 2006-4-29 19:47:00
我是个菜鸟,有许多东西我不懂 ,请大虾能详细说说,怎样才能杀掉这个病毒吗?
mopery - 2006-4-29 19:47:00
http://forum.ikaka.com/topic.asp?board=28&artid=6979213

一楼的HijackThis下载...把日志发上来...
申苓白术 - 2006-4-29 19:55:00
进程名称路径数值名称数值数据操作方式操作结果
D:\Windows 流氓软件清理大师\srieg.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAINStart Pagehttp://www.haokan123.com/修改同意修改
D:\Windows 流氓软件清理大师\IEG\winspeed.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNTkBellExe; "C:\Program Files\Common Files\Real\Update_OB\re修改同意修改
D:\Windows 流氓软件清理大师\IEG\winspeed.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNthunder_mini; F:\Maxthon\Thundermini\ThunderMini.exe修改同意修改
D:\Windows 流氓软件清理大师\IEG\iepro.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNSuper Rabbit IEProD:\Windows 流氓软件清理大师\IEG\SRIECLI.EXE /LOAD修改同意修改
D:\Windows 流氓软件清理大师\IEG\SRIECLI.EXEHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAINStart Pageabout:blank修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAINdefault_page_urlhttp://www.microsoft.com/windows/ie_intl/cn/start/修改同意修改
D:\Windows 流氓软件清理大师\IEG\winspeed.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCESuper Rabbit Winspeed"D:\Windows 流氓软件清理大师\IEG\winspeed.exe" /au修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAINStart Pagehttp://www.haokan123.com/修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSearchAssistant修改同意修改
D:\Windows 流氓软件清理大师\IEG\SRIECLI.EXEHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAINStart Pageabout:blank修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHCustomizeSearch修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSearchAssistant修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHCustomizeSearch修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSearchAssistanthttp://ie.search.msn.com/{SUB_RFC1766}/srchasst/sr修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHCustomizeSearchhttp://ie.search.msn.com/{SUB_RFC1766}/srchasst/sr修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWSLOAD删除同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWSload修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWSrun修改同意修改
D:\Windows 流氓软件清理大师\IEG\winspeed.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCESuper Rabbit Winspeed"D:\Windows 流氓软件清理大师\IEG\winspeed.exe" /au修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAINStart Pagehttp://www.haokan123.com/修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSearchAssistant修改同意修改
D:\Windows 流氓软件清理大师\IEG\SRIECLI.EXEHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAINStart Pageabout:blank修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHCustomizeSearch修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSearchAssistant修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHCustomizeSearch修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSearchAssistanthttp://ie.search.msn.com/{SUB_RFC1766}/srchasst/sr修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHCustomizeSearchhttp://ie.search.msn.com/{SUB_RFC1766}/srchasst/sr修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWSLOAD删除同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWSload修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWSrun修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CLASSES_ROOT\CHM.FILE\SHELL\OPEN\COMMAND"C:\WINDOWS\hh.exe" %1修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAINStart Pagehttp://www.haokan123.com/修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSearchAssistant修改同意修改
D:\Windows 流氓软件清理大师\IEG\SRIECLI.EXEHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAINStart Pageabout:blank修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHCustomizeSearch修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSearchAssistant修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHCustomizeSearch修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSearchAssistanthttp://ie.search.msn.com/{SUB_RFC1766}/srchasst/sr修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHCustomizeSearchhttp://ie.search.msn.com/{SUB_RFC1766}/srchasst/sr修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWSLOAD删除同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWSload修改同意修改
D:\Windows 流氓软件清理大师\IEG\iehelp.exeHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWSrun修改同意修改
C:\WINDOWS\Explorer.EXEHKEY_CLASSES_ROOT\.HTM\OPENWITHLIST\MICROSOFT OFFICE WORD\SHELL\EDITdefault添加(&P)拒绝修改
C:\WINDOWS\Explorer.EXEHKEY_CLASSES_ROOT\.HTM\OPENWITHLIST\MICROSOFT OFFICE WORDdefault添加(&P)拒绝修改
闪电风暴 - 2006-4-29 20:06:00
不是这个日志
闪电风暴 - 2006-4-29 20:06:00
请用http://forum.ikaka.com/topic.asp?board=28&artid=6979213    一楼的工具HijackThis扫描日志上来.
申苓白术 - 2006-4-29 20:15:00
HijackThis@Qoo的扫描日志  V1.97.7
Scan saved at 20:13:54, on 2006-4-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\瑞兴杀毒\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\瑞兴杀毒\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
d:\瑞兴杀毒\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
D:\瑞兴杀毒\Rising\Rav\RavStub.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
d:\瑞兴杀毒\rising\rfw\RfwMain.exe
F:\Maxthon\Max.exe
D:\xunlei\Thunder.exe
D:\新建文件夹\HijackThis.exe

O2 - BHO: (no name) - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\WINDOW~1\IEG\HAOKAN~2.DLL
O3 - Toolbar: ????? - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O3 - Toolbar: ????? - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\WINDOW~1\IEG\HAOKAN~2.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RfwMain] ; "D:\
O4 - HKLM\..\Run: [RavTask] "D:\
O4 - HKLM\..\Run: [SoundMan] ; SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [IMSCMig] ; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [17lelestart] C:\WINDOWS\windcheck2.exe COPYVNETEXE;d:\Program Files\VisionNet\17lele\system\17lele.exe
O4 - HKLM\..\Run: [thunder_mini] ; F:\Maxthon\Thundermini\ThunderMini.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Thunder] "D:\xunlei\ThunderShell.exe" /s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] D:\Windows
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Global Startup: ntuser.dat
O4 - Global Startup: ntuser.dat.LOG
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nsp.dll' missing
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1143209241827
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4BA3932C-973B-4121-8899-4C3FCF4E76EA}: NameServer = 202.106.46.151 202.106.0.20
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - %SystemRoot%\system32\mshtml.dll

申苓白术 - 2006-4-29 20:33:00
HijackThis@Qoo的扫描日志  V1.97.7
Scan saved at 20:13:54, on 2006-4-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\瑞兴杀毒\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\瑞兴杀毒\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
d:\瑞兴杀毒\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
D:\瑞兴杀毒\Rising\Rav\RavStub.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
d:\瑞兴杀毒\rising\rfw\RfwMain.exe
F:\Maxthon\Max.exe
D:\xunlei\Thunder.exe
D:\新建文件夹\HijackThis.exe

O2 - BHO: (no name) - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\WINDOW~1\IEG\HAOKAN~2.DLL
O3 - Toolbar: ????? - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O3 - Toolbar: ????? - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\WINDOW~1\IEG\HAOKAN~2.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RfwMain] ; "D:\
O4 - HKLM\..\Run: [RavTask] "D:\
O4 - HKLM\..\Run: [SoundMan] ; SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [IMSCMig] ; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [17lelestart] C:\WINDOWS\windcheck2.exe COPYVNETEXE;d:\Program Files\VisionNet\17lele\system\17lele.exe
O4 - HKLM\..\Run: [thunder_mini] ; F:\Maxthon\Thundermini\ThunderMini.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Thunder] "D:\xunlei\ThunderShell.exe" /s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] D:\Windows
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Global Startup: ntuser.dat
O4 - Global Startup: ntuser.dat.LOG
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nsp.dll' missing
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1143209241827
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4BA3932C-973B-4121-8899-4C3FCF4E76EA}: NameServer = 202.106.46.151 202.106.0.20
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - %SystemRoot%\system32\mshtml.dll

酷酷ku - 2006-4-29 21:28:00
【回复“申苓白术”的帖子】
版本太低了。
请用http://forum.ikaka.com/topic.asp?board=28&artid=6979213 一楼的附件
申苓白术 - 2006-4-30 11:59:00
Logfile of HijackThis v1.99.1
Scan saved at 11:57:03, on 2006-4-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\瑞兴杀毒\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
D:\瑞兴杀毒\Rising\Rav\Ravmond.exe
d:\瑞兴杀毒\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
D:\瑞兴杀毒\Rising\Rav\RavStub.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
d:\瑞兴杀毒\rising\rfw\RfwMain.exe
F:\Maxthon\Max.exe
D:\xunlei\Thunder.exe
D:\新建文件夹\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: 好看123上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\WINDOW~1\IEG\HAOKAN~2.DLL
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O3 - Toolbar: 好看123上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\WINDOW~1\IEG\HAOKAN~2.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RfwMain] ; "D:\瑞兴杀毒\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "D:\瑞兴杀毒\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [SoundMan] ; SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [IMSCMig] ; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [17lelestart] C:\WINDOWS\windcheck2.exe COPYVNETEXE;d:\Program Files\VisionNet\17lele\system\17lele.exe
O4 - HKLM\..\Run: [thunder_mini] ; F:\Maxthon\Thundermini\ThunderMini.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Thunder] "D:\xunlei\ThunderShell.exe" /s
O4 - HKLM\..\RunOnce: [RavStub] "D:\瑞兴杀毒\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] D:\Windows 流氓软件清理大师\IEG\SRIECLI.EXE /LOAD
O8 - Extra context menu item: 用比特精灵下载(&B) - E:\BitSpirit\bsurl.htm
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nsp.dll' missing
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1143209241827
O17 - HKLM\System\CCS\Services\Tcpip\..\{4BA3932C-973B-4121-8899-4C3FCF4E76EA}: NameServer = 202.106.46.151 202.106.0.20
O23 - Service: Plaug and Play (Retrieves the serial number ) - Unknown owner - C:\WINDOWS\msconfig.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\瑞兴杀毒\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\瑞兴杀毒\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\瑞兴杀毒\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\瑞兴杀毒\Rising\Rav\Ravmond.exe

申苓白术 - 2006-4-30 12:00:00
这个版本行吗?
zq77 - 2006-4-30 12:04:00
晕 那里有病毒
申苓白术 - 2006-4-30 12:35:00
我在从新开机,再把日志发上来
申苓白术 - 2006-4-30 12:43:00
Logfile of HijackThis v1.99.1
Scan saved at 12:42:04, on 2006-4-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\瑞兴杀毒\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\瑞兴杀毒\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
d:\瑞兴杀毒\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
D:\瑞兴杀毒\Rising\Rav\RavStub.exe
d:\瑞兴杀毒\rising\rfw\RfwMain.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\瑞兴杀毒\Rising\Rav\RavTask.exe
D:\瑞兴杀毒\Rising\Rav\Ravmon.exe
D:\xunlei\ThunderShell.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Windows 流氓软件清理大师\IEG\SRIECLI.EXE
F:\Maxthon\Max.exe
E:\BitSpirit\BitSpirit.exe
D:\新建文件夹\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: 好看123上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\WINDOW~1\IEG\HAOKAN~2.DLL
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O3 - Toolbar: 好看123上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\WINDOW~1\IEG\HAOKAN~2.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RfwMain] ; "D:\瑞兴杀毒\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "D:\瑞兴杀毒\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [SoundMan] ; SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [IMSCMig] ; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [17lelestart] C:\WINDOWS\windcheck2.exe COPYVNETEXE;d:\Program Files\VisionNet\17lele\system\17lele.exe
O4 - HKLM\..\Run: [thunder_mini] ; F:\Maxthon\Thundermini\ThunderMini.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Thunder] "D:\xunlei\ThunderShell.exe" /s
O4 - HKLM\..\RunOnce: [RavStub] "D:\瑞兴杀毒\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] D:\Windows 流氓软件清理大师\IEG\SRIECLI.EXE /LOAD
O8 - Extra context menu item: 用比特精灵下载(&B) - E:\BitSpirit\bsurl.htm
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nsp.dll' missing
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1143209241827
O17 - HKLM\System\CCS\Services\Tcpip\..\{4BA3932C-973B-4121-8899-4C3FCF4E76EA}: NameServer = 202.106.46.151 202.106.0.20
O23 - Service: Plaug and Play (Retrieves the serial number ) - Unknown owner - C:\WINDOWS\msconfig.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\瑞兴杀毒\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\瑞兴杀毒\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\瑞兴杀毒\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\瑞兴杀毒\Rising\Rav\Ravmond.exe

申苓白术 - 2006-4-30 12:49:00
请在帮我看看.我每次开机杀毒都能杀掉他.但在下一次开机杀毒,他又出现了.在 C:\Program Files\Internet Explorer下.
申苓白术 - 2006-4-30 12:55:00
Logfile of HijackThis v1.99.1
Scan saved at 12:53:38, on 2006-4-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\瑞兴杀毒\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\瑞兴杀毒\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
d:\瑞兴杀毒\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
D:\瑞兴杀毒\Rising\Rav\RavStub.exe
d:\瑞兴杀毒\rising\rfw\RfwMain.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\瑞兴杀毒\Rising\Rav\RavTask.exe
D:\瑞兴杀毒\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Windows 流氓软件清理大师\IEG\SRIECLI.EXE
F:\Maxthon\Max.exe
E:\BitSpirit\BitSpirit.exe
D:\xunlei\Thunder.exe
D:\新建文件夹\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: 好看123上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\WINDOW~1\IEG\HAOKAN~2.DLL
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O3 - Toolbar: 好看123上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - D:\WINDOW~1\IEG\HAOKAN~2.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RfwMain] ; "D:\瑞兴杀毒\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "D:\瑞兴杀毒\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [SoundMan] ; SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [IMSCMig] ; C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [17lelestart] C:\WINDOWS\windcheck2.exe COPYVNETEXE;d:\Program Files\VisionNet\17lele\system\17lele.exe
O4 - HKLM\..\Run: [thunder_mini] ; F:\Maxthon\Thundermini\ThunderMini.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Thunder] "D:\xunlei\ThunderShell.exe" /s
O4 - HKLM\..\RunOnce: [RavStub] "D:\瑞兴杀毒\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] D:\Windows 流氓软件清理大师\IEG\SRIECLI.EXE /LOAD
O8 - Extra context menu item: 用比特精灵下载(&B) - E:\BitSpirit\bsurl.htm
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nsp.dll' missing
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1143209241827
O17 - HKLM\System\CCS\Services\Tcpip\..\{4BA3932C-973B-4121-8899-4C3FCF4E76EA}: NameServer = 202.106.46.151 202.106.0.20
O23 - Service: Plaug and Play (Retrieves the serial number ) - Unknown owner - C:\WINDOWS\msconfig.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\瑞兴杀毒\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\瑞兴杀毒\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\瑞兴杀毒\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\瑞兴杀毒\Rising\Rav\Ravmond.exe

轩辕小聪 - 2006-4-30 14:16:00
O23 - Service: Plaug and Play (Retrieves the serial number ) - Unknown owner - C:\WINDOWS\msconfig.exe
以为它是系统配置实用程序?大错特错了。
真正的系统配置实用程序的路径为C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe(只要你用开始-运行打开它,再用HijackThis导出日志,看看运行进程,就真相大白了)
所以上面的那个O23服务项是不折不扣的假冒系统文件的灰鸽子。参考http://forum.ikaka.com/topic.asp?board=28&artid=7713905处理。
yuningqing - 2006-4-30 15:31:00
麻烦大哥总结以下手杀的全过程,小弟也中了此毒,这几天恨不得为次早生华发。求各位能伸出援手就就这只菜鸟。
轩辕小聪 - 2006-4-30 15:32:00
晕倒,手杀过程早有总结,抬头看看置顶帖“关于HijackThis日志发现灰鸽子的处理方法”。
yuningqing - 2006-4-30 15:36:00
谢谢。
yuningqing - 2006-4-30 16:20:00
【回复“yuningqing”的帖子】Logfile of HijackThis v1.99.1
Scan saved at 16:02:24, on 2006-4-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
D:\program files\DAEMON Tools\daemon.exe
D:\program files\文件夹加密超级大师\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Thunder Network\Thunder\Thunder.exe
D:\yuningqing\ha_hijackthis\HijackThis.exe

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll (file missing)
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v14.dll
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll (file missing)
O3 - Toolbar: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~1.DLL
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIModeChange] ; Ati2mdxx.exe
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [YLive.exe] ; C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [StormCodec_Helper] ; "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [yassistse] ; "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - HKLM\..\Run: [BigDogPath] ; C:\WINDOWS\VM_STI.EXE PC Camera CAMCAN
O4 - HKLM\..\Run: [DAEMON Tools] "D:\program files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [CdnCtr] ; C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [svchost] "D:\program files\文件夹加密超级大师\svchost.exe"  baohu
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgswitch] ; C:\WINDOWS\system32\bgswitch.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] ; C:\Program Files\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD
O4 - Startup: 腾讯QQ.lnk = D:\program files\QQ.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\program files\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\program files\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\program files\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\program files\SendMMS.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\program files\QQ.EXE
O9 - Extra 'Tools' menuitem: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\program files\QQ.EXE
O9 - Extra button: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\WINDOWS\system32\shdocvw.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdnns.dll
O11 - Options group: [CDNCLIENT]  中文上网
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: qqgame - Unknown owner - C:\WINDOWS\Hacker.com.cn.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

帮我看看啊!
轩辕小聪 - 2006-4-30 16:49:00
O23 - Service: qqgame - Unknown owner - C:\WINDOWS\Hacker.com.cn.exe
这个是灰鸽子。参考置顶帖处理。
yuningqing - 2006-4-30 20:27:00
【回复“轩辕小聪”的帖子】
高手您好,我的注册表选项里没有置顶帖里所说的:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services。确切的说是没有Services这个选项。那么我该怎么做呢?请不吝赐教!谢谢!
轩辕小聪 - 2006-4-30 20:35:00
没有这一项不可能!
所有的O23项目几乎都是里面的项目,除了这些,还有系统的其他服务。没有这个项目,你的机子压根就运行不起来。
在瑞星防火墙“启动选项”中右键勾选“显示服务项”,你就会在列表中找到这个项目,然后选中这一项右键点“切换到”,即可进入注册表的相应项目。
1
查看完整版本: Backdoor.Gpigeon.uql .杀不干净