极速漂移 - 2006-9-16 18:30:00
我的瑞星升级到最新版本啦! 但每次开电脑后扫毒都显示这个病毒:
Backdoor.Gpigeon.fkt 清除成功 手动扫描 IEXPLORE.EXE>>C:\program files\internet explorer\IEXPLORE.EXE 本机

轩辕小聪 - 2006-9-16 18:36:00
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载System Repair Engineer 2.0.21.505(RC2)导出全部日志。
极速漂移 - 2006-9-16 19:37:00
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINXP\System32\CTFMON.EXE> [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><rem C:\WINXP\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><C:\WINXP\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><C:\WINXP\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<CTStartup><rem C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run> []
<TkBellExe><rem "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> []
<NVMixerTray><rem "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"> []
<ff><rem kjh.exe> []
<helper.dll><C:\WINXP\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32> []
<YLive.exe><rem C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> [ ]
<yassistse><rem "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"> [Yahoo!]
<DAEMON Tools-1033><"C:\Program Files\D-Tools\daemon.exe" -lang 1033> [DAEMON'S HOME]
<RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<StormCodec_Helper><rem "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti> []
<NvCplDaemon><rem RUNDLL32.EXE C:\WINXP\System32\NvCpl.dll,NvStartup> [NVIDIA Corporation]
<nwiz><rem nwiz.exe /install> []
<NvMediaCenter><rem RUNDLL32.EXE C:\WINXP\System32\NvMcTray.dll,NvTaskbarInit> [NVIDIA Corporation]
<RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
<ff><kjh.exe> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [Microsoft Corporation]
<Userinit><C:\WINXP\system32\userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{B48F6409-4740-475B-A474-651F54CCE460}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.Dll> []
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINXP\downlo~1\CnsHook.dll> [北京三七二一科技有限公司]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINXP\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<SysTime><C:\PROGRA~1\WinKld\WinKld.dll> []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\reset5]
<WinlogonNotify: reset5><reset5.dll> []
==================================
启动文件夹
服务
[InstallDriver Table Manager / IDriverT]
<C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe><Macrovision Corporation>
[IMAPI CD-Burning COM Service / ImapiService]
<C:\WINXP\System32\imapi.exe><Microsoft Corporation>
[JMediaService / JMediaService]
<C:\WINXP\System32\rundll32.exe C:\PROGRA~1\MMSASS~1\MMSSVER.DLL,Service><N/A>
[NVIDIA Display Driver Service / NVSvc]
<C:\WINXP\System32\nvsvc32.exe><NVIDIA Corporation>
[Reset 5 / Reset 5]
<C:\WINXP\system32\srvany.exe><N/A>
[Rising Proxy Service / RfwProxySrv]
<c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService]
<c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter]
<C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[StdService / StdService]
<C:\WINXP\System32\rundll32.exe C:\WINXP\System32\STDSVER.DLL,Service><N/A>
[Windows svchost / Windows svchost]
<C:\Program Files\Common Files\Microsoft Shared\MSINFO\svchost.exe><N/A>
newcenturymoon - 2006-9-16 19:46:00
双击我的电脑,工具,文件夹选项,查看,单击选取"显示隐藏文件或文件夹"清除"隐藏受保护的操作系统文件(推荐)"复选框。在提示确定更改时,单击“是”,清除“隐藏已知文件类型的扩展名
开始 运行 输入 services.msc 找到Reset 5,Windows svchost双击 停止并且将启动类型改为 已禁用
开始 运行 输入regedit 分别展开HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services(X代表任意,比如1,2 ,3……)
查找Windows svchost 目录,查到的清删除整个目录
重启计算机
显示所有文件并且显示隐藏的系统文件
删除如下文件C:\Program Files\Common Files\Microsoft Shared\MSINFO\svchost.exe
C:\WINXP\system32\srvany.exe
极速漂移 - 2006-9-17 0:10:00
真是非常感谢!按你的办法处理现在瑞星和听诊器都没有发现灰鸽子啦.
不过我查找不到Windows svchost 目录和C:\Program Files\Common Files\Microsoft Shared\MSINFO\svchost.exe,这个有问题吗?
© 2000 - 2026 Rising Corp. Ltd.