瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】发现灰鸽子变种,怎么可以删除啊

1   1  /  1  页   跳转

【求助】发现灰鸽子变种,怎么可以删除啊

【求助】发现灰鸽子变种,怎么可以删除啊

今天觉的电脑运行有点慢,进程到了40个,,用WDS优化大师的 系统安全分析工具查看了下端口,,,如下图
我电脑没有装UC软件,,怎么会出现这个


最后编辑2006-02-27 18:14:14
分享到:
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 18:11:39, on 2006-2-27
Platform: Windows 2003 SP1 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 SP1 (6.00.3790.1830)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
d:\Program Files\rising\Rav\CCenter.exe
D:\WINDOWS\System32\svchost.exe
d:\Program Files\rising\Rav\Ravmond.exe
d:\program files\rising\rfw\rfwsrv.exe
d:\Program Files\rising\Rav\RavStub.exe
D:\WINDOWS\system32\cisvc.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\inetsrv\inetinfo.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\svchost.exe
d:\program files\rising\rfw\RfwMain.exe
D:\WINDOWS\System32\svchost.exe
d:\Program Files\rising\Rav\RavTask.exe
d:\Program Files\rising\Rav\Ravmon.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\System32\svchost.exe
F:\Program Files\Wom\Womcc.exe
D:\WINDOWS\system32\conime.exe
F:\软件2\绿色软件\安全工具\ha_hijackthis_1991\HijackThis.exe

O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - D:\WINDOWS\system32\xunleibho_v13.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - F:\Program Files\myshai\PopupBlocker.dll (file missing)
O2 - BHO: AlxTB BHO - {F1FABE79-25FC-46de-8C5A-2C6DB9D64333} - D:\WINDOWS\system32\alxtb1.dll (file missing)
O3 - Toolbar: Alexa - {3CEFF6CD-6F08-4e4d-BCCD-FF7415288C3B} - D:\WINDOWS\system32\SHDOCVW.DLL
O4 - HKLM\..\Run: [RfwMain] "D:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [IMJPMIG8.1] "D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [RavTask] "d:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [MSPY2002] D:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IMEKRMIG6.1] D:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - F:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: Alexa Web Search - http://client.alexa.com/holiday/script/actions/search.htm
O8 - Extra context menu item: Get Alexa Data - http://client.alexa.com/holiday/script/actions/sitedata.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\Program Files\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\Program Files\Tencent\qq\AddEmotion.htm
O15 - Trusted Zone: http://www.microsoft.com (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1118299160677
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1126004229905
O16 - DPF: {7260569F-1D40-4E7F-B95B-2E68D35668B9} (MofileUploadX Control) - http://www.mofile.com/activex/UploadFX.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - https://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38572.997037037
O16 - DPF: {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} (Qzone Media Tools) - http://imgcache.qq.com/qzone/photo/QzoneMediaTools.cab
O16 - DPF: {B1BAA0F2-3317-48E2-A56A-F6D8F96C5E68} (MofileConatct Control) - http://www.mofile.com/activex/MoCon.CAB
O16 - DPF: {E1207373-6721-4AAD-888B-C8C5A0209E17} - http://service.chinavnet.com/zx/VNetInterface/VNetForSP/VnetPlugin.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{A54E2EDD-E932-4BC7-8B30-AC7B0C6B2ED1}: NameServer = 202.96.134.133,202.103.100.206
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - D:\WINDOWS\system32\mbprot.dll
O20 - Winlogon Notify: dimsntfy - D:\WINDOWS\SYSTEM32\dimsntfy.dll
O23 - Service: kavsvc - Unknown owner - F:\软件2\绿色软件\AVP5\AVP5\kavsvc.exe (file missing)
O23 - Service: Macromedia Licensing Service - Unknown owner - D:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PeanuthullCore - 广东网域 - f:\Program Files\PeanutHull3\PhCore.exe
O23 - Service: RapApp - Parallel Technologies, Inc. - (no file)
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - d:\Program Files\rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - d:\Program Files\rising\Rav\Ravmond.exe
gototop
 

看下有没有问题啊  怎么这里没有ALG.EXE进程的呢,,,我进程里有啊,,
gototop
 

D:\WINDOWS\addurl.ini : KAVICHS  (36 bytes)
D:\WINDOWS\AdvConfig.ini : KAVICHS  (36 bytes)
D:\WINDOWS\alcrmv.exe : KAVICHS  (36 bytes)
D:\WINDOWS\alcupd.exe : KAVICHS  (36 bytes)
D:\WINDOWS\AMX.D98 : KAVICHS  (36 bytes)
D:\WINDOWS\batchformat.INI : KAVICHS  (36 bytes)
D:\WINDOWS\BDM.INI : KAVICHS  (36 bytes)
D:\WINDOWS\Blue Lace 16.bmp : KAVICHS  (36 bytes)
D:\WINDOWS\BMate.INI : KAVICHS  (36 bytes)
D:\WINDOWS\bootstat.dat : KAVICHS  (36 bytes)
D:\WINDOWS\cdcache.dll : KAVICHS  (36 bytes)
D:\WINDOWS\Chinese.gpl : KAVICHS  (36 bytes)
D:\WINDOWS\Coffee Bean.bmp : KAVICHS  (36 bytes)
D:\WINDOWS\d3dx.dat : KAVICHS  (36 bytes)
D:\WINDOWS\dgleg.exe : KAVICHS  (36 bytes)
D:\WINDOWS\FastAIT.INI : KAVICHS  (36 bytes)
D:\WINDOWS\FeatherTexture.bmp : KAVICHS  (36 bytes)
D:\WINDOWS\GameLogCore.INI : KAVICHS  (36 bytes)
D:\WINDOWS\Gone Fishing.bmp : KAVICHS  (36 bytes)
D:\WINDOWS\GPInstall.exe : KAVICHS  (36 bytes)
D:\WINDOWS\Greenstone.bmp : KAVICHS  (36 bytes)
D:\WINDOWS\GScript.INI : KAVICHS  (36 bytes)
D:\WINDOWS\iparmor.dat : KAVICHS  (36 bytes)
D:\WINDOWS\IsUn0404.exe : KAVICHS  (36 bytes)
D:\WINDOWS\IsUn0804.exe : KAVICHS  (36 bytes)
D:\WINDOWS\IsUninst.exe : KAVICHS  (36 bytes)
D:\WINDOWS\iun6002.exe : KAVICHS  (36 bytes)
D:\WINDOWS\KPGMaker.INI : KAVICHS  (36 bytes)
D:\WINDOWS\KServerList.bin : KAVICHS  (36 bytes)
D:\WINDOWS\KugooOption.ini : KAVICHS  (36 bytes)
D:\WINDOWS\KugooUser.his : KAVICHS  (36 bytes)
D:\WINDOWS\lanma256.bmp : KAVICHS  (36 bytes)
D:\WINDOWS\lanmannt.bmp : KAVICHS  (36 bytes)
D:\WINDOWS\magct4.INI : KAVICHS  (36 bytes)
D:\WINDOWS\Mkisofs.exe : KAVICHS  (36 bytes)
D:\WINDOWS\mozregistry.dat : KAVICHS  (36 bytes)
D:\WINDOWS\mozver.dat : KAVICHS  (36 bytes)
D:\WINDOWS\ntbtlog.txt : KAVICHS  (36 bytes)
D:\WINDOWS\ODBC.INI : KAVICHS  (36 bytes)
D:\WINDOWS\ODBCINST.INI : KAVICHS  (36 bytes)
D:\WINDOWS\OEWABLog.txt : KAVICHS  (36 bytes)
D:\WINDOWS\php.ini : KAVICHS  (36 bytes)
D:\WINDOWS\php.ini.Zend_Optimizer_bak : KAVICHS  (36 bytes)
D:\WINDOWS\Prairie Wind.bmp : KAVICHS  (36 bytes)
D:\WINDOWS\ProxyThorn.INI : KAVICHS  (36 bytes)
D:\WINDOWS\QQMsgFriendMng.INI : KAVICHS  (36 bytes)
D:\WINDOWS\Rav.inf : KAVICHS  (36 bytes)
D:\WINDOWS\Rav.ini : KAVICHS  (36 bytes)
D:\WINDOWS\RavExt.ini : KAVICHS  (36 bytes)
D:\WINDOWS\RavMon.ini : KAVICHS  (36 bytes)
D:\WINDOWS\RavReboot.INI : KAVICHS  (36 bytes)
D:\WINDOWS\REAL 格式文件压缩至尊(DVD、VCD TO RM) Setup Log.txt : KAVICHS  (36 bytes)
D:\WINDOWS\Rfw.inf : KAVICHS  (36 bytes)
D:\WINDOWS\rfw.ini : KAVICHS  (36 bytes)
D:\WINDOWS\Rhododendron.bmp : KAVICHS  (36 bytes)
D:\WINDOWS\Rising.ini : KAVICHS  (36 bytes)
D:\WINDOWS\River Sumida.bmp : KAVICHS  (36 bytes)
D:\WINDOWS\rmkinsys.SYW : KAVICHS  (36 bytes)
D:\WINDOWS\RSBDBACKUP.DLL : KAVICHS  (36 bytes)
D:\WINDOWS\RsConfig.ini : KAVICHS  (36 bytes)
D:\WINDOWS\rysoft.ico : KAVICHS  (36 bytes)
D:\WINDOWS\Santa Fe Stucco.bmp : KAVICHS  (36 bytes)
D:\WINDOWS\Setup1.exe : KAVICHS  (36 bytes)
D:\WINDOWS\SHYCIS.SYW : KAVICHS  (36 bytes)
D:\WINDOWS\SJNOsys.inf : KAVICHS  (36 bytes)
D:\WINDOWS\Soap Bubbles.bmp : KAVICHS  (36 bytes)
D:\WINDOWS\SOUNDMAN.EXE : KAVICHS  (36 bytes)
D:\WINDOWS\ST6UNST.EXE : KAVICHS  (36 bytes)
D:\WINDOWS\svchost.exe_被屏蔽木马 : KAVICHS  (36 bytes)
D:\WINDOWS\svr.dat : KAVICHS  (36 bytes)
D:\WINDOWS\system.ini : KAVICHS  (36 bytes)
D:\WINDOWS\TDebugerConfig.ini : KAVICHS  (36 bytes)
D:\WINDOWS\test.ini : KAVICHS  (36 bytes)
D:\WINDOWS\uddiadm.msp : KAVICHS  (36 bytes)
D:\WINDOWS\uddidb.msp : KAVICHS  (36 bytes)
D:\WINDOWS\uddisp.exe : KAVICHS  (36 bytes)
D:\WINDOWS\uddiweb.msp : KAVICHS  (36 bytes)
D:\WINDOWS\uninst.exe : KAVICHS  (36 bytes)
D:\WINDOWS\UNWISE.EXE : KAVICHS  (36 bytes)
D:\WINDOWS\updatesr.ini : KAVICHS  (36 bytes)
D:\WINDOWS\vb.ini : KAVICHS  (36 bytes)
D:\WINDOWS\vbaddin.ini : KAVICHS  (36 bytes)
D:\WINDOWS\VIP.INI : KAVICHS  (36 bytes)
D:\WINDOWS\win.ini : KAVICHS  (36 bytes)
D:\WINDOWS\WindowsUpdate.log : KAVICHS  (36 bytes)
D:\WINDOWS\Wininit.ini : KAVICHS  (36 bytes)
D:\WINDOWS\winzips32.ini : KAVICHS  (36 bytes)
D:\WINDOWS\WORDPAD.INI : KAVICHS  (36 bytes)
D:\WINDOWS\xtenc.dll : KAVICHS  (36 bytes)
D:\WINDOWS\xtractor.exe : KAVICHS  (36 bytes)
D:\WINDOWS\Ying-UnInstall.exe : KAVICHS  (36 bytes)
D:\WINDOWS\Zapotec.bmp : KAVICHS  (36 bytes)
D:\WINDOWS\_default.pif : KAVICHS  (36 bytes)
D:\WINDOWS\_delis32.ini : KAVICHS  (36 bytes)
D:\WINDOWS\极品飞车6 Setup Log.txt : KAVICHS  (36 bytes)
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT