eda991025 - 2006-6-5 15:32:00
1:昨天中了那个红色龙图标的病毒后,监控跟防火墙关闭,打不开,照版主大哥的方法清除掉后,D盘已经正常,但监控跟防火墙依然打不开。
2:用杀毒软件杀毒,每次都查出C:\Program Files\Internet Explorer\IEXPLORE.EXE --> 与 Backdoor.Gpigeon ,提示杀掉,但重启后再杀,还在。
在此请各位大哥帮帮忙,看是什么问题,先谢谢了,稍后贴上日志,拜托。。
eda991025 - 2006-6-5 15:27:00
正在运行的进程(包括进程模块信息)
文件关联
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\System32\ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<nwiz><nwiz.exe /install>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<kav><"F:\新建文件夹 (2)\卡巴斯基6.0中文破解版\avp.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe >
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<Userinit><C:\WINDOWS\System32\Userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><>
eda991025 - 2006-6-5 15:28:00
启动文件夹
服务
[AVP / AVP]
<"F:\新建文件夹 (2)\卡巴斯基6.0中文破解版\avp.exe -r"><Kaspersky Lab>
[IMAPI CD-Burning COM Service / ImapiService]
<C:\WINDOWS\System32\imapi.exe><Microsoft Corporation>
[NVIDIA Display Driver Service / NVSvc]
<C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
[Remote Manage / Reman]
<C:\WINDOWS\Hacker.com.cn.exe><N/A>
[Rising Personal Firewall Service / RfwService]
<C:\Program Files\Rising\Rfw\rfwsrv.exe><N/A>
[Rising Process Communication Center / RsCCenter]
<"C:\Program Files\Rising\Rav\CCenter.exe"><N/A>
eda991025 - 2006-6-5 15:31:00
浏览器加载项
[ThunderIEHelper Class]
{0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\System32\xunleibho_v8.dll, Thunder Networking Technologies,LTD>
[IEMonitor Class]
{08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\Program Files\DeskAdTop\deskipn.dll, N/A>
[Zhongsou Browser Helper]
{2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, N/A>
[IE Browser Helper]
{3CE496D1-1746-41CD-9489-3C0B93DF10E2} <C:\WINDOWS\Downlo~1\nml.dll, 中搜在线软件有限公司>
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} <D:\Program Files\qq\QQIEHelper.dll, N/A>
[Thunder Browser Helper]
{889D2FEB-5411-4565-8998-1DD2C5261283} <C:\Program Files\Thunder Network\Thunder\ComDlls\XUNLEIBHO_001.dll, Thunder Networking Technologies,LTD>
[Web Anti-Virus]
{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} <F:\新建文件夹 (2)\卡巴斯基6.0中文破解版\scieplugin.dll, Kaspersky Lab>
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} <D:\Program Files\qq\QQ.EXE, N/A>
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <D:\Program Files\qq\QQIEHelper.dll, N/A>
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[金山快译(&K)]
{6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} <C:\PROGRA~1\Kingsoft\FastAIT\IEBand.dll, >
[CKAVWebScan Object]
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} <C:\WINDOWS\System32\Kaspersky Lab\Kaspersky Online Scanner Pro\kavwebscan.dll, Kaspersky Lab>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\System32\LegitCheckControl.DLL, Microsoft Corporation>
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\System32\aliedit\AliEdit.dll, www.alipay.com>
[VnetAnprIns Class]
{74447F9C-5691-4A9A-8BE4-564092E40B03} <C:\WINDOWS\Downloaded Program Files\anprins.dll, 中国电信股份有限公司>
[pcastup Class]
{87CCFDB0-C4BE-4BC2-A78C-9EAA7CF96667} <C:\WINDOWS\Downloaded Program Files\vodupdate.dll, N/A>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co., Ltd.>
[&使用迅雷下载]
<C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm, N/A>
[&使用迅雷下载全部链接]
<C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm, N/A>
[上传到QQ网络硬盘]
<D:\Program Files\qq\AddToNetDisk.htm, N/A>
[添加到QQ自定义面板]
<D:\Program Files\qq\AddPanel.htm, N/A>
[添加到QQ表情]
<D:\Program Files\qq\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
<D:\Program Files\qq\SendMMS.htm, N/A>
eda991025 - 2006-6-5 15:32:00
正在运行的进程
[PID: 460][\SystemRoot\System32\smss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 536][\??\C:\WINDOWS\system32\csrss.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 560][\??\C:\WINDOWS\system32\winlogon.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[C:\WINDOWS\System32\klogon.dll] <Kaspersky Lab><6.0.0.297>
[C:\WINDOWS\system32\SSMWinlogonEx.dll] <System Safety Limited><2.0.7.570>
[PID: 604][C:\WINDOWS\system32\services.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 616][C:\WINDOWS\system32\lsass.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 800][C:\WINDOWS\system32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 852][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 964][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 976][C:\WINDOWS\System32\svchost.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1060][C:\WINDOWS\system32\spoolsv.exe] <Microsoft Corporation><5.1.2600.0 (XPClient.010817-1148)>
[PID: 1380][C:\WINDOWS\Explorer.exe] <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
[C:\WINDOWS\System32\msipri.dll] <N/A><N/A>
[C:\WINDOWS\System32\nvcpl.dll] <NVIDIA Corporation><6.14.10.8185>
[C:\WINDOWS\System32\NVRSZHC.DLL] <NVIDIA Corporation><6.14.10.8185>
[C:\WINDOWS\System32\nvshell.dll] <N/A><N/A>
[C:\Program Files\Thunder Network\Thunder\ComDlls\XUNLEIBHO_001.dll] <Thunder Networking Technologies,LTD><5, 0, 0, 1>
[PID: 1568][C:\WINDOWS\System32\nvsvc32.exe] <NVIDIA Corporation><6.14.10.8185>
[PID: 1752][C:\WINDOWS\System32\ctfmon.exe] <Microsoft Corporation><5.1.2600.0 (xpclient.010817-1148)>
[PID: 1852][C:\WINDOWS\System32\wdfmgr.exe] <Microsoft Corporation><5.2.3790.1230 built by: DNSRV(bld4act)>
[PID: 1144][C:\Program Files\Internet Explorer\iexplore.exe] <Microsoft Corporation><6.00.2600.0000 (xpclient.010817-1148)>
[C:\WINDOWS\System32\xunleibho_v8.dll] <Thunder Networking Technologies,LTD><4, 5, 1, 33>
[C:\WINDOWS\Downlo~1\nml.dll] <中搜在线软件有限公司><2, 0, 2, 5>
[C:\Program Files\Thunder Network\Thunder\ComDlls\XUNLEIBHO_001.dll] <Thunder Networking Technologies,LTD><5, 0, 0, 1>
[F:\新建文件夹 (2)\卡巴斯基6.0中文破解版\scr_ch_pg.dll] <Kaspersky Lab><1.0.6.297>
[F:\新建文件夹 (2)\卡巴斯基6.0中文破解版\klscav.dll] <Kaspersky Lab><6.0.0.297>
[C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx] <Macromedia, Inc.><8,0,24,0>
[F:\新建文件夹 (2)\卡巴斯基6.0中文破解版\prloader.dll] <Kaspersky Lab><6.0.0.297>
[C:\WINDOWS\Downloaded Program Files\OL2005.dll] <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
[PID: 920][F:\新建文件夹 (2)\SREng.exe] <Smallfrogs Studio><2.0.12.350>
==================================
文件关联
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
==================================
sasade - 2006-6-5 15:33:00
【回复“eda991025”的帖子】
[Remote Manage / Reman]
<C:\WINDOWS\Hacker.com.cn.exe><N/A>
这分明是只鸽子啊
那里是什么龙啊
汗
eda991025 - 2006-6-5 15:35:00
红色龙标志病毒已被我手工清除掉了,照版主的方法弄的。
sasade - 2006-6-5 15:47:00
| 引用: |
【eda991025的贴子】红色龙标志病毒已被我手工清除掉了,照版主的方法弄的。 ........................... |
快去把那只鸽子灭了吧
© 2000 - 2026 Rising Corp. Ltd.