瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】救命啊,我的电脑中了Backdoor.Gpigeon.trz!!!!

12   2  /  2  页   跳转

【求助】救命啊,我的电脑中了Backdoor.Gpigeon.trz!!!!

顶一下,不能沉下去
gototop
 

用Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项
保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)

工具的下载、使用参考http://forum.ikaka.com/topic.asp?board=28&artid=7318038
gototop
 

thanks!
Autoruns日志:


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ BigDogPathStill Image (STI) DriverVM.c:\windows\vm_sti.exe

+ CdnCtrLiveUpdate Modulec:\program files\cnnic\cdn\cdnup.exe

+ DAEMON Tools-2052Virtual DAEMON ManagerDAEMON'S HOMEd:\program files\d-tools\daemon.exe

+ Media GatewayFile not found: C:\PROGRA~1\MEDIAG~1\MEDIAG~1.EXE

+ MSConfigFile not found: ;

+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe

+ StormCodec_Helperd:\program files\ringz studio\storm codec\stormset.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ ewido shell guardd:\program files\ewido\security suite\shellhook.dll

+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\windows\system32\ravext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ AcroIEHlprObj ClassAcroIEHelper Moduled:\program files\adobe\acrobat 5.0\reader\activex\acroiehelper.ocx

+ BandIE ClassBaiduBar ModuleBaidu.com, Inc.c:\program files\baidu\bar\baidubar.dll

+ CNNIC_IDNCndnIEHelper Modulec:\program files\cnnic\cdn\cdniehlp.dll

+ IeCatch2 Classjccatch ModuleAmaze Softd:\program files\flashget\jccatch.dll

+ LinkFilter Class51NET DiyBar北京金络神电子商务有限责任公司c:\windows\system32\diybar2\diybar2.dll

+ WMHlprObj ClassWMHlpr Modulec:\program files\cnnic\cdn\wmhlpr.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ FlashGet BarFlashGet IE BarAmaze Softd:\program files\flashget\fgiebar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ 访问卡卡社区File not found: http://www.ikaka.com

+ 访问瑞星网站File not found: http://www.rising.com.cn

+ 浩方对战平台浩方对战平台上海浩方在线信息技术有限公司e:\program files\浩方对战平台\gameclient.exe

+ 腾讯QQQQTENCENTd:\program files\tencent\qq.exe

+ 易趣购物File not found: http://click2.ad4all.net/url2/urlmanage/url.asp?id=1

HKLM\System\CurrentControlSet\Services

+ ATI SmartATI Smartc:\windows\system32\ati2sgag.exe

+ ewido security suite controlewido controlewido networksd:\program files\ewido\security suite\ewidoctrl.exe

+ ewido security suite guardguardewido networksd:\program files\ewido\security suite\ewidoguard.exe

+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

HKLM\System\CurrentControlSet\Services

+ ati2mtagATI Radeon WindowsNT Miniport DriverATI Technologies Inc.c:\windows\system32\drivers\ati2mtag.sys

+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\windows\system32\drivers\basetdi.sys

+ BtAudioFile not found: system32\DRIVERS\btaudio.sys

+ BTDriverFile not found: system32\DRIVERS\btport.sys

+ BTWDNDISFile not found: system32\DRIVERS\btwdndis.sys

+ cdnprotcdnprotCNNICc:\windows\system32\drivers\cdnprot.sys

+ cdntrancdntranCNNICc:\windows\system32\drivers\cdntran.sys

+ CinemsupSW CineMaster SupportSonic Solutionsc:\windows\system32\drivers\cinemsup.sys

+ CmdIdeCMD PCI IDE Bus DriverCMD Technology, Inc.c:\windows\system32\drivers\cmdide.sys

+ d347busPnP BIOS Extension c:\windows\system32\drivers\d347bus.sys

+ d347prtSCSI miniport c:\windows\system32\drivers\d347prt.sys

+ es1371ENSONIQ AudioPCI 97 WDM Audio MiniportCreative Technology Ltd.c:\windows\system32\drivers\es1371mp.sys

+ ewido security suite driverd:\program files\ewido\security suite\guard.sys

+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys

+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys

+ HookRegc:\program files\rising\rav\hookreg.sys

+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys

+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys

+ New0c:\windows\system32\new.sys

+ Nokia USB GenericNokia USB Phone Generic ClientNokiac:\windows\system32\drivers\nmwcdc.sys

+ Nokia USB ModemNokia USB Phone Modem ClientNokiac:\windows\system32\drivers\nmwcdcm.sys

+ Nokia USB Phone ParentNokia USB Phone Bus DriverNokiac:\windows\system32\drivers\nmwcd.sys

+ nv_agpNVIDIA nForce AGP FilterNVIDIA Corporationc:\windows\system32\drivers\nv_agp.sys

+ nvatabusNVIDIA? nForce(TM) IDE Performance DriverNVIDIA Corporationc:\windows\system32\drivers\nvatabus.sys

+ NVENETNVIDIA nForce MCP Networking Driver.NVIDIA Corporationc:\windows\system32\drivers\nvenet.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\windows\system32\drivers\ptilink.sys

+ RTL8023Realtek 10/100/1000 NDIS 5.1 Driver                        Realtek Semiconductor Corporation                          c:\windows\system32\drivers\rtlnic51.sys

+ rtl8139Realtek RTL8139 NDIS 5.0 DriverRealtek Semiconductor Corporationc:\windows\system32\drivers\rtl8139.sys

+ SaiH0464Saitek Hid DriverSaitekc:\windows\system32\drivers\saih0464.sys

+ SaiMiniSaitek Magic Mini DriverSaitekc:\windows\system32\drivers\saimini.sys

+ SaiNtBusSaitek Magic BusSaitekc:\windows\system32\drivers\saintbus.sys

+ SecdrvSafeDisc driverMacrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.c:\windows\system32\drivers\secdrv.sys

+ xinstallc:\windows\system32\drivers\xinstall.sys

+ ZSMC301bVideo streaming and Capture Device DriverVMc:\windows\system32\drivers\usbvm31b.sys

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ AtiExtEventATI External Event Utility DLL ModuleATI Technologies Inc.c:\windows\system32\ati2evxx.dll

gototop
 

up
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT