beep.sys/Trojan.NtRootKit.1192,msplugplay 1005.sys/BackDoor.Pigeon.13201等1

beep.sys/Trojan.NtRootKit.1192,msplugplay 1005.sys/BackDoor.Pigeon.13201等1

endurer 原创 2008-06-24 第1

一位网友反映说他的电脑最近经常弹出广告窗口,有时反应很慢,运行程序就重启,请偶帮忙检修。

下载 pe_xscan 扫描 log 并分析,发现如下可疑项:

pe_xscan 08-04-26 by Purple Endurer 
2008-5-22 12:36:54 
Windows XP Service Pack 2(5.1.2600) 
MSIE:6.0.2900.2180 
管理员用户组 
正常模式 

[System Process]  0 
   2008-5-17 12:41:36 
   2008-5-17 12:43:11 
   2008-5-17 12:40:57 
   2008-5-17 12:41:7 
   2008-5-17 12:40:19 
   2008-5-17 12:40:9 
   2008-5-13 11:57:3 
   2008-5-17 12:41:17 
   2008-5-13 11:57:14 
   2008-5-13 11:57:25 
   2008-5-13 11:55:45 
   2008-5-13 11:56:35 
   2008-5-13 11:55:3 
   2008-5-13 11:54:52 
   2008-5-13 11:54:47 
C:/WINDOWS/System32/winlogon.exe 816  2004-8-17 4:0:0  Microsoft(R) Windows(R) Operating System  5.1.2600.2180  Windows NT Logon Application  (C) Microsoft Corporation. All rights reserved.  5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)  Microsoft Corporation ?  winlogon  WINLOGON.EXE 
   2004-8-8 11:53:32 
   2004-8-8 11:53:55 
  
C:/WINDOWS/System32/SVCHOST.EXE 1048  2004-8-17 4:0:0  Microsoft? Windows? Operating System  5.1.2600.2180  Generic Host Process for Win32 Services  ? Microsoft Corporation. All rights reserved.  5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)  Microsoft Corporation ?  svchost.exe  svchost.exe 
   2008-5-13 11:53:20 
C:/WINDOWS/System32/SVCHOST.EXE 284  2004-8-17 4:0:0  Microsoft? Windows? Operating System  5.1.2600.2180  Generic Host Process for Win32 Services  ? Microsoft Corporation. All rights reserved.  5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)  Microsoft Corporation ?  svchost.exe  svchost.exe 
   2004-8-7 20:0:0  Microsoft(R) Windows(R) Operating System  6.6.3791.1831  Background Intelligent Transfer Services  (C) Microsoft Corporation. All rights reserved.  6.6.3791.1832  Microsoft Corporation   qmgr32.dll  qmgr32.dll 
C:/WINDOWS/System32/SVCHOST.EXE 1148  2004-8-17 4:0:0  Microsoft? Windows? Operating System  5.1.2600.2180  Generic Host Process for Win32 Services  ? Microsoft Corporation. All rights reserved.  5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)  Microsoft Corporation ?  svchost.exe  svchost.exe 
   2004-8-7 20:0:0 
 1340  2008-5-13 11:53:6 
   2004-8-8 11:53:32 
   2004-8-8 11:53:55 
C:/WINDOWS/System32/SVCHOST.EXE 1432  2004-8-17 4:0:0  Microsoft? Windows? Operating System  5.1.2600.2180  Generic Host Process for Win32 Services  ? Microsoft Corporation. All rights reserved.  5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)  Microsoft Corporation ?  svchost.exe  svchost.exe 
   2004-8-8 11:53:32 
   2004-8-8 11:53:55 
C:/Program Files/Internet Explorer/iexplore.exe  2424  2006-4-8 17:41:16  Microsoft(R) Windows(R) Operating System  6.00.2900.2180  Internet Explorer  (C) Microsoft Corporation. All rights reserved.  6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)  Microsoft Corporation ?  iexplore  IEXPLORE.EXE 
   2004-8-8 11:53:32 
   2004-8-8 11:53:55 
   2008-5-22 4:6:6 
   2008-5-22 4:7:2 ?  1.0.9.1 ? ?  1.0.9.1 ? ?  cpush.dll  cpush.dll 
   2004-8-8 11:54:5 
   2004-8-8 11:53:24 
   2008-6-16 11:30:0  ati Module  1, 0, 0, 0  ati Module  Copyright 2007  1, 0, 0, 0  明勋科技有限公司   ati  ati.DLL 
   2004-8-8 11:53:42 
   2004-8-8 11:53:27 
   2004-8-8 11:53:40 
   2004-8-8 11:53:25 
   2004-8-8 11:53:15 
   2004-8-8 11:54:7 
   2004-8-8 11:53:30 
   2004-8-8 11:53:35 
   2008-5-22 4:5:59   3, 4, 4, 0   Copyright 2008  3, 4, 4, 0     
C:/WINDOWS/Explorer.EXE 3592  2004-8-17 4:0:0  Microsoft(R) Windows(R) Operating System  6.00.2900.2180  Windows Explorer  (C) Microsoft Corporation. All rights reserved.  6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)  Microsoft Corporation ?  explorer  EXPLORER.EXE 
   2004-8-8 11:53:32 
   2004-8-8 11:53:55 
   2004-8-8 11:53:15 
   2004-8-8 11:53:24 
   2004-8-8 11:53:25 
   2004-8-8 11:53:27 
   2004-8-8 11:53:30 
   2004-8-8 11:53:35 
   2004-8-8 11:53:40 
   2004-8-8 11:53:42 
   2004-8-8 11:54:5 
   2004-8-8 11:54:7 
   2008-5-13 11:54:47 
   2008-5-13 11:54:52 
   2008-5-13 11:55:3 
   2008-5-13 11:55:45 
   2008-5-13 11:56:35 
   2008-5-13 11:57:3 
   2008-5-13 11:57:14 
   2008-5-13 11:57:25 
   2008-5-17 12:40:9 
   2008-5-17 12:40:19 
   2008-5-17 12:40:57 
   2008-5-17 12:41:7 
   2008-5-17 12:41:17 
   2008-5-17 12:41:36 
   2008-5-17 12:43:11 
D:/QQ2006/QQ.exe  2536  2008-2-19 7:15:25  QQ  7,1,644,1777  QQ  Copyright (C) 1998 - 2007 TENCENT Inc. All Rights Reserved  7,1,644,1777  TENCENT   COMQQD  QQ.exe 
   2004-8-8 11:53:32 
   2004-8-8 11:53:55 
   2004-8-8 11:53:15 
   2004-8-8 11:53:24 
   2004-8-8 11:53:25 
   2004-8-8 11:53:27 
   2004-8-8 11:53:30 
   2004-8-8 11:53:35 
   2004-8-8 11:53:40 
   2004-8-8 11:53:42 
   2004-8-8 11:54:5 
   2004-8-8 11:54:7 
D:/QQ2006/TXPlatform.exe 2568  2008-1-4 9:10:35  TM2008  1, 0, 170, 201  TM2008  Copyright (C) 1998-2007 TENCENT Inc. All Rights Reserved  1, 0, 170, 0  Tencent ?   
   2008-5-17 12:43:11 
   2008-5-17 12:41:36 
   2008-5-17 12:41:17 
   2008-5-17 12:41:7 
   2008-5-17 12:40:57 
   2008-5-17 12:40:19 
   2008-5-17 12:40:9 
   2008-5-13 11:57:25 
   2008-5-13 11:57:14 
   2008-5-13 11:57:3 
   2008-5-13 11:55:45 
   2008-5-13 11:56:35 
   2008-5-13 11:55:3 
   2008-5-13 11:54:52 
   2008-5-13 11:54:47 
O2 - BHO CAdLogic Object - {11F09AFD-75AD-4E51-AB43-E09E9351CE16} -
O2 - BHO - {14698742-2059-3025-9058-954023874141} -
O2 - BHO - {1AB1F65A-964F-4AE7-B254-05146A0E602E} -
O2 - BHO - {22596546-2036-9451-6058-658402589722} -
O2 - BHO - {2B69874A-C58C-458D-69F0-698F874E41B2} -
O2 - BHO - {2D698451-2015-6358-9871-2015987452D2} -
O2 - BHO - {35671234-7890-ABCD-CDEF-567801237653} -
O2 - BHO - {37AC9076-C898-B098-D098-A18319080973} -
O2 - BHO Info cache - {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} -
O2 - BHO - {4629FF4F-ACDB-5C90-A098-FACB3456A264} -
O2 - BHO - {4A698102-5904-AFD0-20DF-CD1A65829CA4} -
O2 - BHO - {50940F85-F015-14F1-A05F-F69858AC6D05} -
O2 - BHO - {528DF602-9541-A985-210A-984A698C6F25} -
O2 - BHO - {55694105-5108-9405-3695-954187462155} -
O2 - BHO - {5A069845-2036-6084-9054-6087502480A5} -
O2 - BHO - {5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5} -
O2 - BHO - {5C648541-1025-9650-9057-6541258720C5} -
O2 - BHO - {5E091341-6715-2098-51F0-178367AE53E5} -
O2 - BHO - {5FD45A54-9875-698F-E56E-65102358FDF5} -
O2 - BHO - {6319A1F1-9410-9654-3201-345FFA349136} -
O2 - BHO - {6A041F13-A111-12A3-B0CF-F99818AA68A6} -
O2 - BHO - {7319A1F1-9410-9654-3201-345FFA349137} -
O2 - BHO - {7C8D1401-A58D-A81C-CD24-A5915C4517C7} -
O2 - BHO - {81954FAC-1023-154F-895A-1458258AD818} -
O2 - BHO - {9490415F-65F8-B5C5-D8BA-9405FB120549} -
O2 - BHO Surfer Class - {986488AF-13D5-9DDF-4FEF-9FB88698CFC1} -
O2 - BHO - {AA59145F-315D-BC23-AC1F-145DF81A34AA} -
O4 - HKLM/../Run: [wallpaper]
O4 - HKLM/../Run: [HBmhly] 
O4 - HKLM/../Run: [WinSysW]
O4 - HKLM/../Policies/Explorer/Run: [kcomd]
O4 - Global Startup:  -> Invalid lnk file 
O20 - AppInit_DLLs =,,
O21 - SSODL - midimapwd(-) - {4F4F0064-71E0-4f0d-0018-708476C7815F} =
O21 - SSODL - midimapgj(-) - {4F4F0064-71E0-4f0d-0003-708476C7815F} =
O21 - SSODL - midimapqhx(-) - {4F4F0064-71E0-4f0d-0027-708476C7815F} =
O23 - 服务: 2j9raw (2j9raw) -   1, 0, 0, 1  File System Driver  (C) Microsoft Corporation. All rights reserved.  1, 0, 0, 1     (引导) 
O23 - 服务: 5dinlqohl (5dinlqohl) - (引导) 
O23 - 服务: acpidisk (acpidisk) - 2008-5-22 4:9:9(自动) 
O23 - 服务: apcdli (apcdli) - 2008-6-13 8:59:44(自动) 
O23 - 服务: Beep () - 2004-8-17 4:0:0(系统) 
O23 - 服务: bbzxuu (bbzxuu) -(手动) 
O23 - 服务: bcvnsvc (Visual Studio Analyzer Remote bridge Helper Service) - C:/WINDOWS/System32/svchost.exe -k bcvnsvc -> 2004-8-7 20:0:0  Microsoft(R) Windows(R) Operating System  6.6.3791.1831  Background Intelligent Transfer Services  (C) Microsoft Corporation. All rights reserved.  6.6.3791.1832  Microsoft Corporation   qmgr32.dll  qmgr32.dll(自动) 
O23 - 服务: EagleNT (EagleNT) -(手动) 
O23 - 服务: HBKernel (HBKernel Driver) - (引导) 
O23 - 服务: hjdmc (hjdmc) - (引导) 
O23 - 服务: MSPlugPlay (Windows Plug and Play) - C:/WINDOWS/System32/svchost.exe -k MSPlugPlay -> 2004-8-7 20:0:0(自动) 
O23 - 服务: nesepi (nesepi) - 2007-12-15 11:49:15  sys 应用程序  1, 0, 1, 3  sys 应用程序  版权所有 (C) 2006  1, 0, 1, 3  北京三七二一科技有限公司 ?  sys  sys.exe(引导) 
O23 - 服务: ntptdb (ntptdb) - 2008-6-13 9:32:38(自动) 
O23 - 服务: upudpkok (upudpkok) - 2008-5-22 4:5:59(自动) 
O23 - 服务: windowsupdata (windowsupdata) - 2008-5-16 13:53:27(自动) 
O24 - ShlExecHook: [5] - {55694105-5108-9405-3695-954187462155} =
O24 - ShlExecHook: [6] - {6A041F13-A111-12A3-B0CF-F99818AA68A6} =
O24 - ShlExecHook: [5] - {5C648541-1025-9650-9057-6541258720C5} = 2004-8-8 11:53:15 
O24 - ShlExecHook: [4] - {4629FF4F-ACDB-5C90-A098-FACB3456A264} =
O24 - ShlExecHook: [2] - {2D698451-2015-6358-9871-2015987452D2} = 2004-8-8 11:53:24 
O24 - ShlExecHook: [5] - {5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5} = 2004-8-8 11:53:25 
O24 - ShlExecHook: [5] - {50940F85-F015-14F1-A05F-F69858AC6D05} = 2004-8-8 11:53:27 
O24 - ShlExecHook: [5] - {5FD45A54-9875-698F-E56E-65102358FDF5} = 2004-8-8 11:53:30 
O24 - ShlExecHook: [9] - {9490415F-65F8-B5C5-D8BA-9405FB120549} = 2004-8-8 11:53:32 
O24 - ShlExecHook: [7] - {7C8D1401-A58D-A81C-CD24-A5915C4517C7} =
O24 - ShlExecHook: [7] - {7319A1F1-9410-9654-3201-345FFA349137} = 2004-8-8 11:53:35 
O24 - ShlExecHook: [1] - {14698742-2059-3025-9058-954023874141} =
O24 - ShlExecHook: [3] - {35671234-7890-ABCD-CDEF-567801237653} =
O24 - ShlExecHook: [5] - {528DF602-9541-A985-210A-984A698C6F25} = 2004-8-8 11:53:40 
O24 - ShlExecHook: [4] - {4A698102-5904-AFD0-20DF-CD1A65829CA4} = 2004-8-8 11:53:42 
O24 - ShlExecHook: [2] - {22596546-2036-9451-6058-658402589722} =
O24 - ShlExecHook: [8] - {81954FAC-1023-154F-895A-1458258AD818} =
O24 - ShlExecHook: [5] - {5A069845-2036-6084-9054-6087502480A5} =
O24 - ShlExecHook: [A] - {AA59145F-315D-BC23-AC1F-145DF81A34AA} =
O24 - ShlExecHook: [] - {1AB1F65A-964F-4AE7-B254-05146A0E602E} =
O24 - ShlExecHook: [3] - {37AC9076-C898-B098-D098-A18319080973} = 2004-8-8 11:53:55 
O24 - ShlExecHook: [2] - {2B69874A-C58C-458D-69F0-698F874E41B2} = 2004-8-8 11:54:5 
O24 - ShlExecHook: [5] - {5E091341-6715-2098-51F0-178367AE53E5} = 2004-8-8 11:54:7 
O24 - ShlExecHook: [6] - {6319A1F1-9410-9654-3201-345FFA349136} =
O24 - ShlExecHook: [MICROSOFT] - {28766E1C-74B0-4417-8C75-F12AE309EF35} = 2008-5-13 11:54:47 
O24 - ShlExecHook: [MICROSOFT] - {17DFD111-BF3A-4CB4-ADB0-88FCBFE69821} = 2008-5-13 11:54:52 
O24 - ShlExecHook: [MICROSOFT] - {45AADFAA-DD36-42AB-83AD-0521BBF58C24} = 2008-5-13 11:55:3 
O24 - ShlExecHook: [MICROSOFT] - {1E51C0FD-EE36-434B-AD2A-FD1FF3731C38} =
O24 - ShlExecHook: [MICROSOFT] - {6E6CA8A1-81BC-4707-A54C-F4903DD70BAD} = 2008-5-13 11:55:45 
O24 - ShlExecHook: [MICROSOFT] - {84143967-B645-4BFF-B873-DA1DC886E9A7} =
O24 - ShlExecHook: [MICROSOFT] - {8C41B7F7-3168-400D-A702-0E7EFE0BA304} = 2008-5-13 11:56:35 
O24 - ShlExecHook: [MICROSOFT] - {F99DEFDD-200B-4410-B572-E90883D527D2} = 2008-5-13 11:57:3 
O24 - ShlExecHook: [MICROSOFT] - {461D2AB4-29A5-45C2-9134-D52272D3DE38} = 2008-5-13 11:57:14 
O24 - ShlExecHook: [MICROSOFT] - {841529CB-7F77-4B99-A895-B5441E0D302F} = 2008-5-13 11:57:25 
O24 - ShlExecHook: [MICROSOFT] - {189F087F-4378-405F-85FA-37D955AD7A8C} = 2008-5-17 12:40:9 
O24 - ShlExecHook: [MICROSOFT] - {DC3D30AE-0380-4151-8934-EE98A34B0370} = 2008-5-17 12:40:19 
O24 - ShlExecHook: [F] - {4F4F0064-71E0-4f0d-0018-708476C7815F} =
O24 - ShlExecHook: [MICROSOFT] - {C0595A7E-2E2F-4B34-A83A-019270A0A464} = 2008-5-17 12:40:57 
O24 - ShlExecHook: [MICROSOFT] - {28EB3777-3E23-4E72-8449-A992D09D24C3} = 2008-5-17 12:41:7 
O24 - ShlExecHook: [MICROSOFT] - {A9895933-6636-4281-BC58-EE6DE2AF96E3} = 2008-5-17 12:41:17 
O24 - ShlExecHook: [MICROSOFT] - {011DB9B9-44B4-44D9-B17E-BC7608F2E549} = 2008-5-17 12:41:36 
O24 - ShlExecHook: [F] - {4F4F0064-71E0-4f0d-0003-708476C7815F} =
O24 - ShlExecHook: [F] - {4F4F0064-71E0-4f0d-0027-708476C7815F} =
O24 - ShlExecHook: [MICROSOFT] - {EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6} = 2008-5-17 12:43:11
O26 - IFEO: DrvAnti.exe -> ntsd -d 

(未完待续)

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值