前几天中了灰鸽子.试着去删除.不知道现在还有没有残留.特扫描完传上来.请大侠们帮小弟看看!!


谢谢!!
--------------------------系统环境-------------------------
检测日期: 2006-12-8 14:15
Windows: Microsoft Windows XP
ServicePack: Service Pack 2
Update: 2600.xpsp_sp2_gdr.050301-1519
Internet Explorer: 6.0.2900.2180
-----------------------网络基础安全测试--------------------
密码安全检测:已经设置了管理员密码,建议:将密码复杂度和长度提高!
网络漏洞检测:存在IPC$空连接,但已经禁止匿名访问,安全!
服务名称 是否运行 描述
RemoteRegistry [已停止] [说明:这个服务可能被利用远程操作注册表]
Windows Time [运行中] [说明:这个服务可能被黑客利用来启动木马]
Telnet [已停止] [说明:这个服务可能被黑客登录到您计算机]
Messenger [已停止] [说明:这个服务常被广告商用来发垃圾广告]
Server [运行中] [说明:如果你的电脑不用局域网中,可以关闭]
建议在[控制面板]-[管理工具]-[服务]中,找到这些服务关闭并设置为[禁用].
-----------------------计算机网络端口----------------------
协议 端口号 端口类型
TCP 135 微软DCE RPC end-point mapper服务
TCP 6059 未知类型
TCP 1026 未知类型
TCP 139 微软Netbios Name服务(用于文件及打印机共享)
TCP 139 微软Netbios Name服务(用于文件及打印机共享)
TCP 139 微软Netbios Name服务(用于文件及打印机共享)
TCP 1125 未知类型
TCP 1126 未知类型
TCP 1128 未知类型
TCP 1129 未知类型
TCP 500 Internet密钥交换
TCP 1028 KiLo,SubSARI
TCP 1083 未知类型
TCP 4500 sae-urn
TCP 123 未知类型
TCP 1107 未知类型
TCP 1121 未知类型
TCP 1123 未知类型
TCP 123 未知类型
TCP 137 未知类型
TCP 138 未知类型
--------------------计算机系统组件体检----------------------
[编号:0]
[名称:\SystemRoot\System32\smss.exe]
[类型:运行进程]
[内容:未知]
[编号:1]
[名称:\??\C:\WINDOWS\system32\winlogon.exe]
[类型:运行进程]
[内容:未知]
[编号:2]
[名称:C:\WINDOWS\system32\services.exe]
[类型:运行进程]
[内容:Microsoft(R) Windows(R) Operating System (C) Microsoft Corporation. All rights reserved.]
[编号:3]
[名称:C:\WINDOWS\system32\lsass.exe]
[类型:运行进程]
[内容:Microsoft? Windows? Operating System ? Microsoft Corporation. All rights reserved.]
[编号:4]
[名称:C:\WINDOWS\system32\svchost.exe]
[类型:运行进程]
[内容:Microsoft? Windows? Operating System ? Microsoft Corporation. All rights reserved.]
[编号:5]
[名称:d:\Program Files\Rising\Rav\CCenter.exe]
[类型:运行进程]
[内容:Rising Antivirus Software Copyright Rising 2002]
[编号:6]
[名称:C:\WINDOWS\System32\svchost.exe]
[类型:运行进程]
[内容:Microsoft? Windows? Operating System ? Microsoft Corporation. All rights reserved.]
[编号:7]
[名称:d:\Program Files\Rising\Rav\Ravmond.exe]
[类型:运行进程]
[内容:Rising Antivirus Software Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:8]
[名称:d:\program files\rising\rfw\rfwsrv.exe]
[类型:运行进程]
[内容:Rising Personal FireWall 2006 Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:9]
[名称:C:\WINDOWS\system32\spoolsv.exe]
[类型:运行进程]
[内容:Microsoft? Windows? Operating System ? Microsoft Corporation. All rights reserved.]
[编号:10]
[名称:d:\Program Files\Rising\Rav\RavStub.exe]
[类型:运行进程]
[内容:RavStub Application Copyright (c) 1998-2005 Rising Corp.]
[编号:11]
[名称:C:\WINDOWS\SYSTEM32\RUNDLL32.EXE]
[类型:运行进程]
[内容:Microsoft(R) Windows(R) Operating System (C) Microsoft Corporation. All rights reserved.]
[编号:12]
[名称:C:\WINDOWS\Explorer.EXE]
[类型:运行进程]
[内容:Microsoft(R) Windows(R) Operating System (C) Microsoft Corporation. All rights reserved.]
[编号:13]
[名称:C:\WINDOWS\system32\svchost.exe]
[类型:运行进程]
[内容:Microsoft? Windows? Operating System ? Microsoft Corporation. All rights reserved.]
[编号:14]
[名称:d:\program files\rising\rfw\RfwMain.exe]
[类型:运行进程]
[内容:Rising Personal FireWall 2006 Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:15]
[名称:C:\Program Files\Common Files\Real\Update_OB\realsched.exe]
[类型:运行进程]
[内容:RealPlayer (32-bit) Copyright ? RealNetworks, Inc. 1995-2004]
[编号:16]
[名称:C:\WINDOWS\VM303_STI.EXE]
[类型:运行进程]
[内容:BIGDOG Copyright (C) 2004 Vimicro Corporation]
[编号:17]
[名称:D:\Program Files\Rising\Rav\RavTask.exe]
[类型:运行进程]
[内容:Rising Antivirus Software Copyright (c) 1998-2006 Rising Corp.]
[编号:18]
[名称:D:\Program Files\Rising\Rav\Ravmon.exe]
[类型:运行进程]
[内容:Rising Anti-Virus Monitor Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:19]
[名称:C:\WINDOWS\system32\ctfmon.exe]
[类型:运行进程]
[内容:Microsoft? Windows? Operating System ? Microsoft Corporation. All rights reserved.]
[编号:20]
[名称:D:\Program Files\完美卸载V2006 完整版\MainCon.exe]
[类型:运行进程]
[内容:完美卸载V2006 主控制台 版权所有 (C) 2005]
[编号:21]
[名称:D:\Program Files\Rising\Rav\rav.exe]
[类型:运行进程]
[内容:Rising Antivirus Software Copyright (c) 1998-2006 Rising Corp.]
[编号:22]
[名称:D:\Program Files\完美卸载V2006 完整版\SysRepairer.exe]
[类型:运行进程]
[内容:完美卸载系统修复工具 版权所有 (C) 2005]
[编号:23]
[名称:D:\Program Files\完美卸载V2006 完整版\SysSec.exe]
[类型:运行进程]
[内容:完美卸载V2006-ChinaHijackThis 版权所有 (C) 2006]
[编号:24]
[分隔符:---------------------------------------------------------------------]
[编号:25]
[名称:d:\Program Files\Rising\Rav\BWList.dll]
[类型:已加载DLL]
[内容:BWList Dynamic Link Library Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:26]
[名称:d:\Program Files\Rising\Rav\RsCommX.dll]
[类型:已加载DLL]
[内容:rising RsCommX Copyright ? 2002]
[编号:27]
[名称:d:\Program Files\Rising\Rav\RsPPsys.dll]
[类型:已加载DLL]
[内容:RSPPSYS Dynamic Link Library Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:28]
[名称:d:\Program Files\Rising\Rav\RSAPPMGR.DLL]
[类型:已加载DLL]
[内容:Rising AntiVirus 2006 Copyright ? 2004 - 2005]
[编号:29]
[名称:d:\Program Files\Rising\Rav\CfgDll.dll]
[类型:已加载DLL]
[内容:Rising AntiVirus 2006 Copyright ? 2004 - 2006]
[编号:30]
[名称:d:\Program Files\Rising\Rav\RSCOMMON.DLL]
[类型:已加载DLL]
[内容:Rising Antivirus Software Copyright (c) 1998-2006 Rising Corp.]
[编号:31]
[名称:d:\Program Files\Rising\Rav\RsLog.dll]
[类型:已加载DLL]
[内容:RsLog Dynamic Link Library Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:32]
[名称:d:\Program Files\Rising\Rav\HOOKSYS.dll]
[类型:已加载DLL]
[内容:HOOKSYS Dynamic Link Library Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:33]
[名称:d:\Program Files\Rising\Rav\Scanner.dll]
[类型:已加载DLL]
[内容:Rising RsScanner Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:34]
[名称:d:\Program Files\Rising\Rav\libload.dll]
[类型:已加载DLL]
[内容:rising libload Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:35]
[名称:d:\Program Files\Rising\Rav\VirusLib.dll]
[类型:已加载DLL]
[内容:Rising VirusLib Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:36]
[名称:d:\Program Files\Rising\Rav\regmon.dll]
[类型:已加载DLL]
[内容: regmon Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:37]
[名称:d:\Program Files\Rising\Rav\HookWeb.dll]
[类型:已加载DLL]
[内容:rising HookWeb Copyright ? 2004]
[编号:38]
[名称:d:\Program Files\Rising\Rav\MemMon.dll]
[类型:已加载DLL]
[内容:北京瑞星 MemMon Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:39]
[名称:d:\Program Files\Rising\Rav\expscan.dll]
[类型:已加载DLL]
[内容:ExpScan Dynamic Link Library Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:40]
[名称:d:\Program Files\Rising\Rav\mPorts.dll]
[类型:已加载DLL]
[内容:Personal Firewall Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:41]
[名称:d:\Program Files\Rising\Rav\MailMon.dll]
[类型:已加载DLL]
[内容:mailmon Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:42]
[名称:d:\Program Files\Rising\Rav\SpamEng.dll]
[类型:已加载DLL]
[内容: SpamEng Dynamic Link Library Copyright (C) 2004]
[编号:43]
[名称:d:\Program Files\Rising\Rav\engine.dll]
[类型:已加载DLL]
[内容:rising engine Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:44]
[名称:d:\Program Files\Rising\Rav\PostTrt.dll]
[类型:已加载DLL]
[内容:Rising PostTrt Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:45]
[名称:d:\Program Files\Rising\Rav\UnExe.dll]
[类型:已加载DLL]
[内容:rising UnExe Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:46]
[名称:d:\Program Files\Rising\Rav\ScanExec.dll]
[类型:已加载DLL]
[内容:rising ScanExec Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:47]
[名称:d:\Program Files\Rising\Rav\ScanEx.dll]
[类型:已加载DLL]
[内容:Rising ScanEX Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:48]
[名称:d:\Program Files\Rising\Rav\RSUnpack.dll]
[类型:已加载DLL]
[内容:Rising RSUnpack Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:49]
[名称:d:\Program Files\Rising\Rav\ExtFile.dll]
[类型:已加载DLL]
[内容:rising extFile Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]
[编号:50]
[名称:d:\Program Files\Rising\Rav\NvFile.dll]
[类型:已加载DLL]
[内容:rising NVFile Copyright(c) 1998-2006 Beijing Rising Technology Corporation Limited]