瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 灰鸽子侵袭,请各位帮忙看看日志

1   1  /  1  页   跳转

灰鸽子侵袭,请各位帮忙看看日志

灰鸽子侵袭,请各位帮忙看看日志

Logfile of HijackThis v1.99.1
Scan saved at 20:57:21, on 2005-7-6
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\conime.exe
d:\program files\rising\rav\RAVMON.EXE
D:\Program Files\Sandai Technologies Inc\ThunderMini\ThunderMini.exe
D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\racer-henan-cnc\racer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
D:\Program Files\Maxthon\Maxthon.exe
C:\Program Files\racer-henan-cnc\RacerKp.exe
D:\hijackthis\HijackThis.exe

O1 - Hosts: 202.100.222.24 www1.tianyaclub.com
O1 - Hosts: 211.161.159.90 bt2.btchina.net
O1 - Hosts: 61.129.102.149 www.ttdown.com
O1 - Hosts: 202.108.250.209 post.baidu.com
O1 - Hosts: 218.22.24.230 www.52design.com
O1 - Hosts: 202.101.62.21 www.cgercn.com
O1 - Hosts: 60.31.184.137 asksea.blogdriver.com
O1 - Hosts: 61.135.150.230 alumni.chinaren.com
O1 - Hosts: 61.172.250.80 www.arting365.com
O1 - Hosts: 162.105.204.150 bbs.pku.edu.cn
O1 - Hosts: 61.135.150.230 alumni.chinaren.com
O1 - Hosts: 199.181.132.244 espn.go.com
O1 - Hosts: 61.153.17.33 www.cnool.net
O1 - Hosts: 60.191.132.102 www.1110.net
O1 - Hosts: 202.181.231.211 dijanet.hk.st
O1 - Hosts: 61.49.22.13 www.blogdriver.com
O1 - Hosts: 166.111.77.2 dns.ime.tsinghua.edu.cn
O1 - Hosts: 218.97.136.66 www.photoshopcn.com
O1 - Hosts: 218.97.136.66 www.photoshopcn.com
O1 - Hosts: 61.152.107.126 bbs.zingking.com
O1 - Hosts: 61.152.108.101 www.qqoo.net
O1 - Hosts: 61.144.25.114 www.southcn.com.cn
O1 - Hosts: 210.51.168.43 www.0304.com.cn
O1 - Hosts: 168.160.224.36 www.ddc.com.cn
O1 - Hosts: 61.156.238.101 www.haha365.com
O1 - Hosts: 211.152.32.55 www.bol.com.cn
O1 - Hosts: 202.108.158.250 www.51kedou.com
O1 - Hosts: 220.194.60.202 www.thebeijingnews.com
O1 - Hosts: 64.236.16.20 www.cnn.com
O1 - Hosts: 211.151.90.54 bbs.gter.net
O1 - Hosts: 218.28.14.38 www.zzsi.com
O1 - Hosts: 202.100.222.28 liumangyan.tianyablog.com
O1 - Hosts: 61.135.153.184 book.sina.com.cn
O1 - Hosts: 61.135.153.184 book.sina.com.cn
O1 - Hosts: 202.100.222.28 anbon.tianyablog.com
O1 - Hosts: 219.232.48.108 www.yannan.cn
O1 - Hosts: 202.106.185.238 tech.sina.com.cn
O1 - Hosts: 218.108.245.69 www.5d.cn
O1 - Hosts: 60.191.132.102 www.1110.net
O1 - Hosts: 60.191.10.4 www.zrit.com
O1 - Hosts: 202.106.185.238 tech.sina.com.cn
O1 - Hosts: 202.106.184.192 supergirl.sina.com.cn
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v4.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: viviband - {15DDE989-CD45-4561-BF99-D22C0D5C2B85} - C:\WINDOWS\Downlo~1\vivimin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: 新浪ViVi收藏夹 - {15DDE989-CD45-4561-BF99-D22C0D5C2B85} - C:\WINDOWS\Downlo~1\vivimin.dll
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - d:\Program Files\BitComet\BitCometBar\BitCometBar0.1.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [thunder_mini] D:\Program Files\Sandai Technologies Inc\ThunderMini\ThunderMini.exe
O4 - HKLM\..\Run: [RavTimer] D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: 河南网通宽带用户客户端.lnk = C:\Program Files\racer-henan-cnc\racer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &使用迷你迅雷下载 - D:\Program Files\Sandai Technologies Inc\ThunderMini\geturl.htm
O8 - Extra context menu item: 反向链接 - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 收藏此页到新浪ViVi - http://vivi.sina.com.cn/collect/click.php?agent=viviband
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\qq\SendMMS.htm
O8 - Extra context menu item: 类似网页 - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://www.3721.com/assistant30/jinshan.htm (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=Http://www.microsoft.com/china/windowsxp
O16 - DPF: {15DDE989-CD45-4561-BF99-D22C0D5C2B85} (新浪ViVi收藏夹) - http://vivi.sina.com.cn/control/vivi.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {48FE89A0-486C-48DF-9DEC-BED22BDC6057} (XIsOro Control) - http://www.sinago.com/download/OroCheck.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1110644005860
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: pdfFactory Pro Dispatcher v2 - Unknown owner - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /service (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe

最后编辑2005-07-06 21:29:11
分享到:
gototop
 

O23 - Service: pdfFactory Pro Dispatcher v2 - Unknown owner - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /service (file missing)
这项是灰鸽子。

O3 - Toolbar: (no name) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - (no file)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O23 - Service: pdfFactory Pro Dispatcher v2 - Unknown owner - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /service (file missing)

在安全摸试下修复上面几项)(如果你清楚某项是安全的,可以不处理)
,将隐藏的文件不隐藏。找到下面几项C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /service把它删除。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT