我的机器日前在查看进程时发现一种木马,显示的图标是一只小狗,文件扩展名为EXE,在WINDOWS\TEMP\,与之并存的还有Perflib_Perfdata_584.dat文件,删除后重启机器仍又出现,小狗的主文件名每次启动都更名,后一个文件倒是不变,用各种反木马软件检测又找不到这个木马。查杀的木马似乎都是一些别的(与上述两个文件不搭边),求助怎样才能将狗打死?
HijackThis_815汉化版扫描日志 V1.99.1
保存于 16:47:20, 日期 2006-12-11
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
D:\Program Files\Rising\AntiSpyware\runiep.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
D:\Program Files\Antiy Labs\Alive\AliveCenter_.exe
D:\Program Files\Microsoft SQL Server\MSSQL$FPP\Binn\sqlservr.exe
D:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
D:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
D:\WINDOWS\system32\WatchClient.exe
D:\WINDOWS\system32\VrvEdp_m.exe
D:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
D:\WINDOWS\system32\vrvsafec.exe
D:\WINDOWS\system32\vrvrf_c.exe
D:\WINDOWS\TEMP\CDD6CC.EXE
D:\Program Files\wnwb\wnwb.exe
D:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\PROGRA~1\IZARC\IZARC.EXE
D:\DOCUME~1\青岛市~1\LOCALS~1\Temp\ARC62\HijackThis1991zww.exe
D:\DOCUME~1\青岛市~1\LOCALS~1\Temp\ARC63\HijackThis1991zww.exe
F2 - REG:system.ini: UserInit=D:\WINDOWS\system32\userinit.exe
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: (no name) - {F156768E-81EF-470C-9057-481BA8380DBA}? - (no file)
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - D:\WINDOWS\system32\KakaTool.dll
O4 - 启动项HKLM\\Run: [PHIME2002ASync] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [OfficeScanNT Monitor] "D:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - 启动项HKLM\\Run: [Antiy Auto Update] D:\Program Files\Antiy Labs\Alive\AliveCenter.exe
O4 - 启动项HKLM\\Run: [runeip] D:\Program Files\Rising\AntiSpyware\runiep.exe
O4 - 启动项HKLM\\RunOnce: [KKDelay] D:\Program Files\rising\AntiSpyware\RunOnce.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: 服务管理器.lnk = D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - C:\Program Files\FLASHGET\jc_link.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - D:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - D:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}? - D:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6}? - D:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的按钮: 访问瑞星网站 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E444}? - http://www.rising.com.cn/?u=RSTB (file missing)
O9 - 浏览器额外的按钮: 访问卡卡社区 - {FF2DE7A6-ECB1-4CBC-9C0E-D92A9E66E445} - http://www.ikaka.com/?u=RSTB (file missing)
O10 - Broken Internet access because of LSP provider 'd:\windows\system32\cdnns.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class) - http://10.1.1.5/officescan/console/ClientInstall/setupini.cab
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - http://10.1.1.5/officescan/console/ClientInstall/setup.cab
O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} ({5DD731E6-D4F0-11D3-BE3F-00105A6FDA50}) - http://ebook.qingdaonews.com/virus/myv3na.cab
O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) - http://10.1.1.5/officescan/console/ClientInstall/RemoveCtrl.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} - http://cache10.itv.mop.com/pCastCtl-1.0.0.88_signed.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{02FC1E54-E50C-445F-96DF-99CEF2A081D6}: NameServer = 210.52.149.2,202.102.134.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{0F172117-CDE2-4A92-9ADD-1FC55E77A4D5}: NameServer = 202.110.193.12
O17 - HKLM\System\CS1\Services\Tcpip\..\{02FC1E54-E50C-445F-96DF-99CEF2A081D6}: NameServer = 210.52.149.2,202.102.134.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{02FC1E54-E50C-445F-96DF-99CEF2A081D6}: NameServer = 210.52.149.2,202.102.134.68
O17 - HKLM\System\CS3\Services\Tcpip\..\{02FC1E54-E50C-445F-96DF-99CEF2A081D6}: NameServer = 210.52.149.2,202.102.134.68
O18 - 列举现有的协议: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - D:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: Sony SPTI Service for DVE (ICDSPTSV) - Intel Corporation - (no file)
O23 - NT 服务: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - NT 服务: NT Data Provider (Mercha2) - Unknown owner - D:\WINDOWS\SYSTEM32\RUN32.EXE (file missing)
O23 - NT 服务: OfficeScanNT 实时扫描 (ntrtscan) - Trend Micro Inc. - D:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - NT 服务: OfficeScanNT 个人防火墙 (OfcPfwSvc) - Trend Micro Inc. - D:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - NT 服务: OfficeScanNT 侦听程序 (tmlisten) - Trend Micro Inc. - D:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - NT 服务: VRVWatchServer - Unknown owner - D:\WINDOWS\system32\WatchClient.exe" -service (file missing)