瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 “新版灰鸽子”的一些特点及手工查杀举例

12345678»   4  /  27  页   跳转

“新版灰鸽子”的一些特点及手工查杀举例

【回复“baohe”的帖子】
收了先.
谢谢.

我晕啊,帮助文件全是英文的呀。
啥都看不懂,我是英文盲哦。
gototop
 

【回复“baohe”的帖子】一个字‘好’!

哎,到现在还没有那到新鸽子样本,不知您是否有往Qoo论坛扔一个?

PS:好久没去他那了。- -``
gototop
 

版主  救救我呀.我一开机实时监控就提示有病毒且病毒来源本机.
每次用瑞星杀毒都有Backdoor.Gpigeon.shg 木马病毒。每次手动都能杀(删除)。但每次启动后又有了。请问怎样彻底清除呢?谢谢了!!!
防火墙也提示有木马 今天杀掉了.第二天一开机又有
救我 看是不是中的灰鸽子呀?
很急

附件附件:

下载次数:0
文件类型:image/pjpeg
文件大小:
上传时间:2005-9-11 22:36:07
描述:



gototop
 

有样本吗?我想送给KILL分析.
gototop
 

引用:
【云淡清风夜未央的贴子】版主  救救我呀.我一开机实时监控就提示有病毒且病毒来源本机.
每次用瑞星杀毒都有Backdoor.Gpigeon.shg 木马病毒。每次手动都能杀(删除)。但每次启动后又有了。请问怎样彻底清除呢?谢谢了!!!
防火墙也提示有木马 今天杀掉了.第二天一开机又有
救我 看是不是中的灰鸽子呀?
很急
...........................
和我说的吗?
啊啊 我很菜 样本就在图这呀
gototop
 

【回复“花落花又开”的帖子】已经“扔”了——“Qoo酷儿:你要的鸽子”http://www.anti-vir.cn/bbs/read.php?tid=966&fpage=2
gototop
 

【回复“云淡清风夜未央”的帖子】
你这个鸽子是2005
gototop
 

【回复“CAJINCHEN”的帖子】
到“安全中国”去找。我发到那里了。
gototop
 

引用:
【baohe的贴子】【回复“云淡清风夜未央”的帖子】
你这个鸽子是2005
...........................

老大.怎么处理?急急急
Logfile of HijackThis v1.99.1
Scan saved at 23:15:16, on 2005-9-11
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
E:\瑞星\防火墙\Rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\3721\Dlaccel\YDownloader.exe
E:\瑞星\RAV\RAVTIMER.EXE
E:\瑞星\RAV\RAVMON.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\Program Files\Messenger\msmsgs.exe
E:\MSN Shell\MSNShell\BIN\MSNShell.exe
C:\WINDOWS\System32\nvsvc32.exe
E:\瑞星\RAV\CCENTER.EXE
E:\瑞星\RAV\Ravmond.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
E:\瑞星\RAV\RavStub.exe
C:\WINDOWS\explorer.exe
E:\QQ\QQ1\qq\TIMPlatform.exe
E:\瑞星\防火墙\Rfw\rfwmain.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\QQ\QQ1\qq\QQ.exe
E:\QQ\QQ1\qq\QQ.exe
E:\新建文件夹 (2)\155847200541134207\HijackThis.exe

O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v5.dll
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F57} - C:\WINDOWS\System32\THUNDE~2.DLL (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\ar40chs\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - E:\QQ\QQ1\qq\QQIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: InsIII - {DDDE2452-AF9E-4577-AE6C-465DBCB54D49} - C:\WINDOWS\System32\obdc16tg.dll
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\yisou\yisoub.dll
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - E:\金山快译\IEBand.dll
O3 - Toolbar: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\Program Files\yisou\yisou.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTimer] E:\瑞星\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RfwMain] "E:\瑞星\防火墙\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [CApp] C:\WINDOWS\System32\capp.exe
O4 - HKLM\..\Run: [RavMon] E:\瑞星\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [迅雷4] E:\迅雷4\迅雷4\TDUpdate.exe
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] rem RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSNShell] E:\MSN Shell\MSNShell\BIN\MSNShell.exe autorun
O8 - Extra context menu item: !搜一搜 - res://C:\Program Files\yisou\yisou.dll/232
O8 - Extra context menu item: &使用下载加速专家下载 - C:\Program Files\3721\Dlaccel\geturl.htm
O8 - Extra context menu item: &使用迅雷下载 - E:\迅雷4\迅雷4\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - E:\迅雷4\迅雷4\getAllurl.htm
O8 - Extra context menu item: Google 搜索(&G) - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: 反向链接 - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://E:\office\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\QQ\QQ1\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\QQ\QQ1\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\QQ\QQ1\qq\SendMMS.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - E:\BT\BitSpirit\bsurl.htm
O8 - Extra context menu item: 类似网页 - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: 翻译英文字词(&T) - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: 豪杰超级解霸V8实时播放 - e:\Herosoft\HeroV8\MPURLGET.HTM
O9 - Extra button: 迅雷 - {1FBA04EE-3024-11D2-8F1F-000019796948} - E:\迅雷4\迅雷4\Thunder.exe
O9 - Extra 'Tools' menuitem: 迅雷 - {1FBA04EE-3024-11D2-8F1F-000019796948} - E:\迅雷4\迅雷4\Thunder.exe
O9 - Extra button: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - e:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - e:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\QQ\QQ1\qq\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - E:\QQ\QQ1\qq\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\QQ\QQ1\qq\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - E:\QQ\QQ1\qq\QQIEHelper.dll
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} (V3ProX Control) - http://origin-www.ahn.com.cn/aspservice/plugin/myv3.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - http://bar.baidu.com/update/IESearch.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{73E73E46-E98F-41DD-A846-6EF17DFDE820}: NameServer = 202.103.96.68 202.103.100.66
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\Exploer.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - E:\瑞星\防火墙\Rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - E:\瑞星\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\瑞星\RAV\Ravmond.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe



gototop
 

【回复“云淡清风夜未央”的帖子】
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\Exploer.exe
灰鸽子2005

查杀见:http://forum.ikaka.com/topic.asp?board=28&artid=6202404
gototop
 
12345678»   4  /  27  页   跳转
页面顶部
Powered by Discuz!NT