今天查毒时发现了loaddriver.exe这个木马文件,删除后用hijack生成了日志文件,大家帮忙看看
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 19:49:53, 日期 2006-8-29
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Unable to get Internet Explorer version!
当前运行的进程:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
G:\Rising\Rav\CCenter.exe
C:\windows\System32\svchost.exe
G:\Rising\Rav\Ravmond.exe
g:\rising\rfw\rfwsrv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\svchost.exe
G:\Rising\Rav\RavStub.exe
g:\rising\rfw\RfwMain.exe
C:\windows\SOUNDMAN.EXE
G:\WinPatrol\winpatrol.exe
G:\WinPatrol\tasktrap.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
G:\Rising\Rav\RavTask.exe
G:\Rising\Rav\Ravmon.exe
G:\Atomic Alarm Clock\AtomicAlarmClock.exe
G:\volumouse\volumouse.exe
C:\windows\system32\ctfmon.exe
G:\PROCEXP-V9.11H\PROCEXP.EXE
G:\xplorer2\XPlorer2.exe
G:\ADSL拨号王\HNMainUI.exe
G:\μTorrent\utorrent164.exe
G:\Maxthon\Maxthon.exe
G:\10moons\TVBABY~2\TV BABY.exe
G:\PROCEXP-V9.11H\PROCEXP.EXE
G:\Rising\Rav\Rav.exe
G:\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
G:\HijackThis1991汉化版\HijackThis1991zww.exe
O2 - BHO: GigagetIEHelper Class - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\windows\system32\gigagetbho_v10.dll
O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O3 - IE工具栏增项: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [WinPatrol] G:\WinPatrol\winpatrol.exe
O4 - 启动项HKLM\\Run: [Task Catcher] G:\WinPatrol\tasktrap.exe
O4 - 启动项HKLM\\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 启动项HKLM\\Run: [TVTray] G:\10moons\TVBABY~2\TVTray.exe
O4 - 启动项HKLM\\Run: [RavTask] "G:\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [RfwMain] "G:\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKCU\\Run: [SkinClock] G:\Atomic Alarm Clock\AtomicAlarmClock.exe
O4 - 启动项HKCU\\Run: [$Volumouse$] "G:\volumouse\volumouse.exe" /nodlg
O4 - 启动项HKCU\\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O8 - IE右键菜单中的新增项目: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - IE右键菜单中的新增项目: 使用Gigaget下载 - g:\Gigaget\geturl.htm
O8 - IE右键菜单中的新增项目: 使用gigaget下载全部链接 - g:\Gigaget\getallurl.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - G:\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - G:\FlashGet\jc_all.htm
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - G:\FlashGet\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - G:\FlashGet\flashget.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{DD5687E5-62BF-4BDE-98B8-3CB54D4F42E8}: NameServer = 202.99.224.67 202.99.224.68
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: McAfee WSC Integration (McDetect.exe) - Unknown owner - c:\program files\mcafee.com\agent\mcdetect.exe (file missing)
O23 - NT 服务: McAfee Task Scheduler (McTskshd.exe) - Unknown owner - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe (file missing)
O23 - NT 服务: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - NT 服务: McAfee Personal Firewall Service (MpfService) - Unknown owner - C:\PROGRA~1\McAfee.com\Personal Firewall\MpfService.exe (file missing)
O23 - NT 服务: MSSQL$SONY_MEDIAMGR - Unknown owner - G:\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - NT 服务: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - NT 服务: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - g:\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - g:\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - G:\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - G:\Rising\Rav\Ravmond.exe
O23 - NT 服务: SQLAgent$SONY_MEDIAMGR - Unknown owner - G:\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
O23 - NT 服务: StarWind iSCSI Service (StarWindService) - Rocket Division Software - G:\Alcohol 120\StarWind\StarWindService.exe
我觉得017项是木马残留在注册表中的键值,另外请大家给我说说loaddriver.exe是什么木马文件啊,在瑞星的病毒名称中查不到啊