瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了Binder.Gpigeon.b,哪位高手帮我看一下日志

1   1  /  1  页   跳转

[求助] 中了Binder.Gpigeon.b,哪位高手帮我看一下日志

中了Binder.Gpigeon.b,哪位高手帮我看一下日志

Logfile of HijackThis v1.99.1
Scan saved at 10:09:22, on 2009-10-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
d:\Rising\Rav\CCENTER.EXE
C:\windows\System32\svchost.exe
d:\Rising\Rav\RavTask.exe
d:\Rising\Rav\RavMonD.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
d:\Rising\Rav\rsnetsvr.exe
D:\My Documents\360safe\safemon\360Tray.exe
C:\Program Files\360Safebox\safeboxTray.exe
C:\windows\system32\RUNDLL32.EXE
D:\Rising\Rav\RsTray.exe
C:\windows\system32\ctfmon.exe
E:\Program Files\PPStream\ppsap.exe
F:\Program Files\Java\jre6\bin\jqs.exe
C:\windows\system32\nvsvc32.exe
d:\Rising\Rav\ScanFrm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\windows\system32\conime.exe
D:\Tencent\QQ\QQ.exe
D:\Tencent\QQ\TXPlatform.exe
d:\Rising\Rav\rsmain.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX69.703\HijackThis.exe
O2 - BHO: QvodExtend - {53AC8551-0DE0-4606-8A1E-A51AF20ADD60} - D:\Program Files\QvodPlayer\QvodExtend.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: SafeMon Class - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} - D:\My Documents\360safe\safemon\safemon.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - F:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [360Safetray] "D:\My Documents\360safe\safemon\360Tray.exe" /start
O4 - HKLM\..\Run: [360Safebox] "C:\Program Files\360Safebox\safeboxTray.exe" /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RavTray] "d:\Rising\Rav\RsTray.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [PPS Accelerator] E:\Program Files\PPStream\ppsap.exe
O8 - Extra context menu item: 使用电驴下载 - E:\Program Files\easyMule\IE2EM.htm
O8 - Extra context menu item: 使用迅雷下载 - d:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: 使用迅雷下载全部链接 - d:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ表情 - D:\Tencent\QQ\AddEmotion.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B1AB009-4F97-4EFC-B608-8B07936F5BE5}: NameServer = 219.150.32.132 219.146.0.130
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: Webcam - {3F991DE0-A6A8-40ED-4B87-293AEDB29489} - (no file)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - F:\Program Files\Java\jre6\bin\jqs.exe" -service -config "F:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: Rav Process Communication Center (RavCCenter) - Beijing Rising Information Technology Co., Ltd. - d:\Rising\Rav\CCENTER.EXE
O23 - Service: Rising RavTask Manager (RavTask) - Unknown owner - d:\Rising\Rav\RavTask.exe" RavTask (file missing)
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Information Technology Co., Ltd. - d:\Rising\Rav\RavMonD.exe
O23 - Service: Rising Scan Service (RsScanSrv) - Beijing Rising Information Technology Co., Ltd. - d:\Rising\Rav\ScanFrm.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) )
分享到:
gototop
 

回复:中了Binder.Gpigeon.b,哪位高手帮我看一下日志

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\windows\system32\GameMon.des.exe (file missing)

杀软把它清除了,没事了..
PM偶时请附上求助贴的地址...
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT