瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 〓我中了灰鸽子 请高手来99我啊,好像是变种〓

1   1  /  1  页   跳转

〓我中了灰鸽子 请高手来99我啊,好像是变种〓

〓我中了灰鸽子 请高手来99我啊,好像是变种〓

开机的时候报:

病毒    2005-10-01 08:39:09    发现病毒在文件C:\WINDOWS\winrom.DLL中    Win32.Hack.Huigezi.c.871424    处理成功(操作:删除)   

病毒    2005-10-01 08:39:13    发现病毒在文件C:\WINDOWS\svchost.DLL中    Win32.Hack.Huigezi.bv.868864    处理成功(操作:删除)   

我用杀毒软件杀,但是能查到不能杀!

我又用 HijackThis1991zww 扫了一遍

HijackThis_815汉化版扫描日志 V1.99.1
保存于      9:09:39, 日期 2005-10-1
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\KAV2005\KWatch.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\KAV2005\KAVStart.exe
C:\PROGRA~1\SkyNet\FireWall\pfw.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
E:\WinXP\内存扫把V1.94\ram.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\KAV2005\KPfwSvc.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wuauclt.exe
E:\WinXP\Maxthon\Maxthon.exe
E:\工具\灰鸽子专杀工具\4842302005817230232\HijackThis1991zww.exe

O1 - Hosts: 61.145.121.115 www.ip138.com
O1 - Hosts: 218.83.153.138 free.ys168.com
O1 - Hosts: 219.133.38.84 my.qq.com
O1 - Hosts: 219.129.239.55 qq.72g.com
O1 - Hosts: 218.64.80.15 zxm.jxncmu.com
O1 - Hosts: 219.129.216.115 www.zcmu.com
O1 - Hosts: 202.108.42.153 xy2.163.com
O1 - Hosts: 61.129.47.173 www.52592.com
O1 - Hosts: 61.152.94.181 www.07a.net
O1 - Hosts: 218.64.80.14 mm.155mu.com
O1 - Hosts: 61.145.126.157 www.yusesky.com
O1 - Hosts: 61.142.254.217 tcpdy.anyp.cn
O1 - Hosts: 61.172.193.28 vod2.gamesoft.com.cn
O1 - Hosts: 218.56.133.54 zez.cn
O1 - Hosts: 202.110.102.130 cncwoool.008.net
O1 - Hosts: 202.107.247.43 www.51dy.com
O1 - Hosts: 61.145.119.80 www.showgood.tv
O1 - Hosts: 202.102.234.147 py.zzip.com.cn
O1 - Hosts: 61.142.254.217 tcpdy.anyp.cn
O1 - Hosts: 220.189.255.203 www.klvod.com
O1 - Hosts: 218.74.123.3 bbs.10bei.com
O1 - Hosts: 61.152.95.157 www.51y.com
O1 - Hosts: 218.206.194.66 www.ssvod.com
O1 - Hosts: 218.28.143.202 www.vod.ha.cn
O1 - Hosts: 61.233.75.61 vod.cttstar.com
O1 - Hosts: 222.174.34.147 hnnn.net
O1 - Hosts: 61.129.47.173 www.52592.com
O1 - Hosts: 218.28.6.227 www.valr.net.cn
O1 - Hosts: 202.104.237.241 www.gz126.cn
O1 - Hosts: 211.98.192.25 www.cttha.com
O1 - Hosts: 210.22.202.69 www.e898.net
O1 - Hosts: 218.85.132.63 www.214game.com
O1 - Hosts: 218.87.241.202 bbs.91886.com
O1 - Hosts: 61.138.6.98 www.9tgame.com
O1 - Hosts: 211.151.229.95 db.wowar.com
O1 - Hosts: 61.129.49.160 bbs.17ez.com
O1 - Hosts: 222.174.176.72 www.ggame8.com
O1 - Hosts: 60.191.12.130 www.520yx.com
O1 - Hosts: 218.75.93.203 www.kk91.com
O1 - Hosts: 61.129.33.141 www.pk263.cn
O1 - Hosts: 61.155.39.152 xy2.yezizhu.com
O1 - Hosts: 210.224.161.19 bbs.t2bbs.com
O1 - Hosts: 210.51.190.238 www.nan11nan.com
O1 - Hosts: 219.146.57.230 www.qjsf.net
O1 - Hosts: 218.83.155.66 game.jhoncn.com
O1 - Hosts: 220.168.199.45 www.kkwww.com
O1 - Hosts: 222.36.42.212 www.5igames.net
O1 - Hosts: 222.132.76.230 www.273100.net
O1 - Hosts: 211.142.183.40 www.myou.net
O1 - Hosts: 210.51.190.238 www.nan11nan.com
O1 - Hosts: 220.231.5.15 cnc.hotmoto.com
O1 - Hosts: 61.129.55.228 www.ali213.net
O1 - Hosts: 218.66.37.46 www.game220.com
O1 - Hosts: 210.74.232.169 www.gamehome.cc
O1 - Hosts: 61.129.45.85 www.yxbar.net
O1 - Hosts: 61.53.239.252 noyes.cn
O1 - Hosts: 60.208.73.45 www.youxizhe.com
O1 - Hosts: 218.28.143.178 www.wztt.com
O1 - Hosts: 61.157.96.3 www.yooq.com
O1 - Hosts: 61.53.44.35 wow.cn-game.net
O1 - Hosts: 221.230.31.10 www.snowyy.com
O1 - Hosts: 61.152.105.33 www.wowch.net
O1 - Hosts: 61.55.138.127 www.ttdown.com
O1 - Hosts: 219.148.120.138 www.366tian.net
O1 - Hosts: 61.163.238.60 www.ayxz.com
O1 - Hosts: 219.238.233.238 www.ikaka.com
O1 - Hosts: 222.85.127.178 www.tldown.com
O1 - Hosts: 211.98.110.67 www.111222.cn
O1 - Hosts: 218.83.153.138 ys168.com
O1 - Hosts: 221.14.150.132 www.3800cc.com
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-

1D9571695F55} - C:\WINDOWS\system32\xunleibho_v5.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} -

E:\WinXP\Tencent\QQIEHelper.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} -

C:\PROGRA~1\Yahoo!\Assistant\Assist\YDragSearch.dll (file missing)
O4 - 启动项HKLM\\Run: [KavStart] "C:\KAV2005\KAVStart.exe" -startup
O4 - 启动项HKLM\\Run: [SKYNET Personal FireWall] C:\PROGRA~1

\SkyNet\FireWall\pfw.exe
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32

\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep

0 -k
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common

Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: 内存扫把.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions

present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions

present
O8 - IE右键菜单中的新增项目: &使用迅雷下载 -

E:\WinXP\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 -

E:\WinXP\Thunder\getAllurl.htm
O8 - IE右键菜单中的新增项目: 使用Kugoo下载 - E:\WinXP\KuGoo2

\KugooDownX.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 -

E:\WinXP\Tencent\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 -

E:\WinXP\Tencent\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 -

E:\WinXP\Tencent\SendMMS.htm
O9 - 浏览器额外的按钮: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-

E800A446447A} - E:\WinXP\浩方对战平台\GameClient.exe
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} -

E:\WinXP\Tencent\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-

00aa003c157b} - E:\WinXP\Tencent\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-

4983E5A8AFE6} - E:\WinXP\Tencent\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-

45d9-9460-4983E5A8AFE6} - E:\WinXP\Tencent\QQIEHelper.dll
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-

00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-

11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{FA451555-89CB-44B0-944B-

D955362D1579}: NameServer = 211.98.192.3 61.233.73.3
O23 - NT 服务: Crypkey License - Kenonic Controls Ltd. -

C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - NT 服务: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner -

C:\WINDOWS\winrom.exe
O23 - NT 服务: Kingsoft Personal Firewall Service (KPfwSvc) - Kingsoft

Corporation - C:\KAV2005\KPfwSvc.EXE
O23 - NT 服务: Kingsoft Antivirus KWatch Service (KWatchSvc) - Kingsoft

Corporation - C:\KAV2005\KWatch.EXE
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA

Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - NT 服务: system - Unknown owner - C:\WINDOWS\svchost.exe


请高手帮帮我啊!
3Q了啊!
最后编辑2005-10-01 09:21:35
分享到:
gototop
 

O23 - NT 服务: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\winrom.exe
O23 - NT 服务: system - Unknown owner - C:\WINDOWS\svchost.exe
这两个都是
看下面的帖子杀吧
http://forum.ikaka.com/topic.asp?board=28&artid=6202404
gototop
 

谢谢了
3Q3Q
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT