瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 【求助】电脑中了灰鸽子,求彻底杀毒方法!
eeeeee111 - 2005-11-24 8:46:00
详细内容2005-11-23 21:59:48, >>D:\Program Files\Internet Explorer\IEXPLORE.EXE ->Backdoor.Gpigeon.snz
详细内容2005-11-23 21:59:48, Server.exe>>D:\WINDOWS\Server.exe ->Backdoor.Gpigeon.snz

开机器的时候老是出现这个,有 彻底的杀毒方法吗?求达人赐教~~ 55555
神无 - 2005-11-24 8:49:00
http://forum.ikaka.com/topic.asp?board=28&artid=6979213一楼附件工具扫个日志上来看看.
病毒新手 - 2005-11-24 8:57:00
D:\WINDOWS\Server.exe
鸽子。。杀!~
eeeeee111 - 2005-11-24 8:59:00
每次都杀啊,就是不能彻底杀掉,求解决方法~
玻璃钢耗子 - 2005-11-24 9:01:00
瑞星不出灰鸽子专杀了吗?
神无 - 2005-11-24 9:01:00
请到一楼地址附件里的工具扫个日志上来
eeeeee111 - 2005-11-24 9:05:00
什么工具?具体点。。。。谢谢
BlackStone - 2005-11-24 9:07:00
用Autoruns保存一个日志发上来
日志保存方法:选择File->Save菜单项
保存日志时注意选择Options->Hide Microsoft Entries菜单项(设置了这项后点工具栏的刷新按钮)

工具的下载、使用参考http://forum.ikaka.com/topic.asp?board=28&artid=7318038第14楼
神无 - 2005-11-24 9:08:00
http://forum.ikaka.com/topic.asp?board=28&artid=6979213这个地址一楼有个附件,里面的就是扫描工具,你把它下载到自己是电脑,扫个日志上来.

附件: 5220982005112490828.bmp
eeeeee111 - 2005-11-24 9:13:00
扫描日志~

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      9:11:31, 日期 2005-11-24
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\dllhost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\inetsrv\inetinfo.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRAM FILES\RISING\RAV\RavStub.exe
D:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\WINDOWS\System32\dmadmin.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\rising\Rfw\RfwMain.exe
d:\program files\rising\rfw\rfwsrv.exe

R3 - URLSearchHook: MyURLSearchHook Class - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - D:\PROGRA~1\P4P\Toolbar.dll (file missing)
O1 - Hosts: 218.83.153.7 share.greedland.net
O1 - Hosts: 210.41.224.136 www.cuit.edu.cn
O1 - Hosts: 218.204.251.19 zm.mycng.cn
O1 - Hosts: 61.129.93.115 www.wowchina.com
O1 - Hosts: 61.152.145.35 www.1t1t.com
O1 - Hosts: 61.183.15.95 www.mop.com
O1 - Hosts: 64.233.189.104 www.google.com
O1 - Hosts: 219.239.89.45 www.enet.com.cn
O1 - Hosts: 218.10.216.131 bbs1.btbbt.com
O1 - Hosts: 203.90.128.75 www.lovemgc.com
O1 - Hosts: 61.152.145.79 bbs3.btbbt.com
O1 - Hosts: 218.199.102.216 bbs.5qzone.net
O1 - Hosts: 218.7.69.214 bbs.lovemgc.com
O1 - Hosts: 61.129.90.159 wowsearch.92wy.com
O1 - Hosts: 211.161.159.90 bt2.btchina.net
O1 - Hosts: 220.181.27.5 www.baidu.com
O1 - Hosts: 61.152.188.174 www.wfbrood.com
O1 - Hosts: 219.136.244.102 www.pconline.com.cn
O1 - Hosts: 61.152.107.141 to.gamigo.com.cn
O1 - Hosts: 218.92.50.27 comic.ktxp.com
O1 - Hosts: 219.129.20.134 www.qq163.com
O1 - Hosts: 219.238.237.140 fairyland.aijoy.com
O1 - Hosts: 202.85.22.10 bbs.100free.net
O1 - Hosts: 202.85.22.10 100free.net
O1 - Hosts: 202.85.22.10 www.100free.net
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - D:\WINDOWS\system32\xunleibho_v4.dll
O2 - BHO: 搜索助手 - {04844102-FC0B-4f44-9E93-0C4293BB5E80} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SohuDAIEHelper - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - D:\Program Files\P4P\sodaie.dll (file missing)
O2 - BHO: TeachingHandler - {31EBA2E2-58B2-4980-9C41-F12F5F1422C5} - D:\PROGRA~1\COLLEG~1\TEACHI~1\tphandle.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\Program Files\Tencent\qq\QQIEHelper.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - D:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: Infofo 工具栏 - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\Program Files\Infofo Bar\infofobar.dll (file missing)
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - D:\PROGRA~1\YiSou\yisoub.dll
O3 - IE工具栏增项: 博采 - {4DA2EE61-6399-4C39-AEB9-0D990E610D29} - D:\WINDOWS\system32\BOCAIT~1.DLL (file missing)
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - IE工具栏增项: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - D:\Program Files\YiSou\yisou.dll (file missing)
O3 - IE工具栏增项: 捜狗直通车 - {DBBB7978-AF21-4EF4-9AD1-B2F4BC75696C} - D:\PROGRA~1\P4P\Toolbar.dll (file missing)
O3 - IE工具栏增项: Infofo 工具栏 - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\Program Files\Infofo Bar\infofobar.dll (file missing)
O4 - 启动项HKLM\\Run: [RavTimer] D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [RavMon] D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [PHIME2002A] D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [PHIME2002ASync] D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\Program Files\Tencent\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\Program Files\Tencent\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\Program Files\Tencent\qq\SendMMS.htm
O8 - IE右键菜单中的新增项目: 用比特精灵下载(&B) - D:\Program Files\BitSpirit\bsurl.htm
O9 - 浏览器额外的按钮: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\j2re1.4.2_09\bin\npjpi142_09.dll
O9 - 浏览器额外的“工具”菜单项: Sun Java 控制台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\j2re1.4.2_09\bin\npjpi142_09.dll
O9 - 浏览器额外的按钮: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - G:\浩方对战平台优化版\GameClient.exe
O9 - 浏览器额外的按钮: Infofo 工具栏 - {8507326C-B5C1-4559-BB91-0919E753836F} - C:\Program Files\Infofo Bar\infofobar.dll (file missing)
O9 - 浏览器额外的“工具”菜单项: Infofo 工具栏 - {8507326C-B5C1-4559-BB91-0919E753836F} - C:\Program Files\Infofo Bar\infofobar.dll (file missing)
O9 - 浏览器额外的按钮: SoQ - {8F67DCF3-B1DF-4A39-A787-3775784BF737} - http://www.soq.com (file missing)
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\qq\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\qq\QQ.EXE
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\qq\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\Program Files\Tencent\qq\QQIEHelper.dll
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} (PowerPlayer Control) - http://www.ppstream.com/bin/powerplayer.cab
O16 - DPF: {9675ABBF-8D0B-4956-868C-934B5A7928D4} (Npv Control) - https://nprotect.lineage2.com.cn/nprotect/nprotect2004/ncsoft/npv.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9F75970E-7410-4A30-9CE4-AAE849A6ABBF}: NameServer = 61.139.2.69
O20 - AppInit_DLLs: D:\WINDOWS\system32\SoDAHK.DLL
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - NT 服务: P4P Service - Unknown owner - (no file)
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - NT 服务:   - Unknown owner - D:\WINDOWS\Server.exe
病毒新手 - 2005-11-24 9:15:00
O23 - NT 服务:   - Unknown owner - D:\WINDOWS\Server.exe
就是这个啊,鸽子!~杀~~
杀查方法详见:
http://forum.ikaka.com/topic.asp?board=28&artid=6202404
http://forum.ikaka.com/topic.asp?board=28&artid=6882330
eeeeee111 - 2005-11-24 9:19:00
晕,谁有彻底的解决办法吗?不想天天杀。。。求高人~
病毒新手 - 2005-11-24 9:20:00
修复:

R3 - URLSearchHook: MyURLSearchHook Class - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - D:\PROGRA~1\P4P\Toolbar.dll (file missing)
O1 - Hosts: 218.83.153.7 share.greedland.net
O1 - Hosts: 210.41.224.136 www.cuit.edu.cn
O1 - Hosts: 218.204.251.19 zm.mycng.cn
O1 - Hosts: 61.129.93.115 www.wowchina.com
O1 - Hosts: 61.152.145.35 www.1t1t.com
O1 - Hosts: 61.183.15.95 www.mop.com
O1 - Hosts: 64.233.189.104 www.google.com
O1 - Hosts: 219.239.89.45 www.enet.com.cn
O1 - Hosts: 218.10.216.131 bbs1.btbbt.com
O1 - Hosts: 203.90.128.75 www.lovemgc.com
O1 - Hosts: 61.152.145.79 bbs3.btbbt.com
O1 - Hosts: 218.199.102.216 bbs.5qzone.net
O1 - Hosts: 218.7.69.214 bbs.lovemgc.com
O1 - Hosts: 61.129.90.159 wowsearch.92wy.com
O1 - Hosts: 211.161.159.90 bt2.btchina.net
O1 - Hosts: 220.181.27.5 www.baidu.com
O1 - Hosts: 61.152.188.174 www.wfbrood.com
O1 - Hosts: 219.136.244.102 www.pconline.com.cn
O1 - Hosts: 61.152.107.141 to.gamigo.com.cn
O1 - Hosts: 218.92.50.27 comic.ktxp.com
O1 - Hosts: 219.129.20.134 www.qq163.com
O1 - Hosts: 219.238.237.140 fairyland.aijoy.com
O1 - Hosts: 202.85.22.10 bbs.100free.net
O1 - Hosts: 202.85.22.10 100free.net
O1 - Hosts: 202.85.22.10 www.100free.net
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - D:\WINDOWS\system32\xunleibho_v4.dll
O2 - BHO: 搜索助手 - {04844102-FC0B-4f44-9E93-0C4293BB5E80} - (no file)
O2 - BHO: SohuDAIEHelper - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - D:\Program Files\P4P\sodaie.dll (file missing)
O2 - BHO: Infofo 工具栏 - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\Program Files\Infofo Bar\infofobar.dll (file missing)
O3 - IE工具栏增项: 博采 - {4DA2EE61-6399-4C39-AEB9-0D990E610D29} - D:\WINDOWS\system32\BOCAIT~1.DLL (file missing)

病毒新手 - 2005-11-24 9:21:00
http://forum.ikaka.com/topic.asp?board=28&artid=6202404
http://forum.ikaka.com/topic.asp?board=28&artid=6882330
这两个帖子写的很详细了,仔细看看!~
病毒新手 - 2005-11-24 9:31:00
【回复“eeeeee111”的帖子】
那说个简单点的,进安全模式,显示所有文件,把隐藏系统文件的钩去掉,找到D:\WINDOWS\Server.exe文件删除,
在去注册表里找到它生成的服务,把它删掉就行了。。
O23 - NT 服务:   - Unknown owner - D:\WINDOWS\Server.exe
这个服务好象没名字。。。。
小笼包 - 2005-11-24 10:09:00
我也中了,帮忙看一下,谢了。


HijackThis_zww汉化版扫描日志 V1.99.1
保存于      :10:06, 日期 2005-11-24
操作系统:  Windows XP  (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 (6.00.2600.0000)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\eEBAPI\SAgent2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
E:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\JJOL\IME\JJSvr.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Jedi\LOCALS~1\Temp\Rar$EX00.973\HijackThis1991zww.exe

O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - E:\PROGRA~1\FLASHGET\jccatch.dll
O3 - IE工具栏增项: (no name) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - (no file)
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - E:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [NvCplDaemon] rem  RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - 启动项HKLM\\Run: [SysExplr] rem  E:\HEROSOFT\SYSEXPLR.EXE
O4 - 启动项HKLM\\Run: [Super Rabbit SRRestore] rem  E:\PROGRA~1\SUPERR~1\MAGICSET\SRRest.exe /autosave
O4 - 启动项HKLM\\Run: [EPSON Stylus C41 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C41 Series" /O6 "USB001" /M "Stylus C41"
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - 启动项HKLM\\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - 启动项HKLM\\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - E:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - E:\Program Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - 浏览器额外的按钮: NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - C:\WINDOWS\System32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: &NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - C:\WINDOWS\System32\shdocvw.dll
O9 - 浏览器额外的按钮: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm (file missing)
O9 - 浏览器额外的按钮: (no name) - {BF1F4A1A-BDCD-43ac-9D17-261D2C197AB8} - http://assistant.3721.com/uninstall.htm (file missing)
O9 - 浏览器额外的“工具”菜单项: 卸载网络实名 - {BF1F4A1A-BDCD-43ac-9D17-261D2C197AB8} - http://assistant.3721.com/uninstall.htm (file missing)
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm (file missing)
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm (file missing)
O11 - Options group: [!CNS]  网络实名
O16 - DPF: {1AF783BD-BFC0-48A2-816E-A667B2BC69E9} (CHtmlClientView Object) - http://zdc.zol.com.cn/Ip1HtmlClientView.dll
O16 - DPF: {1F831FA1-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://E:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1132791653730
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday 控件) - file://E:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {A2C271DF-91C3-11D5-9FA6-860301900128} (PPlayerX Control) - http://ad4.sina.com.cn/ads/test/av/pplayer.cab
O16 - DPF: {AE563722-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://E:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview 控件) - file://E:\Program Files\AutoCAD 2002\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{AFD1C383-CE70-430A-8CEF-DC35ECC3F4C5}: NameServer = 61.144.56.101 202.96.128.86
O23 - NT 服务: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\eEBAPI\SAgent2.exe
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - NT 服务: Print Spooler Desktop Sharing (PriSpds) - Unknown owner - C:\WINDOWS\PrintSpooler.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe

病毒新手 - 2005-11-24 10:15:00
O23 - NT 服务: Print Spooler Desktop Sharing (PriSpds) - Unknown owner - C:\WINDOWS\PrintSpooler.exe
鸽子。!~
杀查方法详见帖子:
http://forum.ikaka.com/topic.asp?board=28&artid=6202404
http://forum.ikaka.com/topic.asp?board=28&artid=6882330


仔细看看会有帮助的!~

你要懒的看,我在这里说说。
先停掉Print Spooler Desktop Sharing (PriSpds)这个服务,
服务名字可能是(priSpds),然后显示所有文件,把隐藏系统文件的钩去掉,找到C:\WINDOWS\PrintSpooler.exe文件,删除!~
去注册表里,找到prispds这个服务,删掉就好了。。

naming - 2005-11-24 11:32:00
微点主动防御软件对新病毒,黑客攻击,木马特别是针对灰鸽子这样变种多的病毒很有效果,建议有这样问题的朋友不仿去下下来装看看,
www.micropoint.com.cn
小笼包 - 2005-11-24 13:31:00
to 病毒新手,谢谢了,杀了,瑞星查 不到病毒了,但上网的时候还是遇到攻击。
1
查看完整版本: 【求助】电脑中了灰鸽子,求彻底杀毒方法!