瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 求救~~帮忙看一下日志和杀毒结果,谢谢

1   1  /  1  页   跳转

求救~~帮忙看一下日志和杀毒结果,谢谢

求救~~帮忙看一下日志和杀毒结果,谢谢

用瑞星杀毒显示中了灰鸽子,结果如下:
病毒名称    处理结果    发现日期    扫描方式    路径    文件    病毒来源
Backdoor.Gpigeon.sqi    发现病毒    05-10-12 10:10    快捷扫描    C:\WINDOWS    20050819.exe    本机
Backdoor.Gpigeon.oc    发现病毒    05-10-12 10:12    快捷扫描    C:\WINDOWS    G_Server.DLL    本机
Backdoor.Gpigeon.oc    发现病毒    05-10-12 10:12    快捷扫描    C:\WINDOWS    G_Server.exe>>Unpack    本机
Backdoor.Gpigeon.lb    发现病毒    05-10-12 10:15    快捷扫描    C:\WINDOWS    runllyKey1.DLL    本机
Trojan.PSW.QQRobber.ad    发现病毒    05-10-12 10:18    快捷扫描    C:\WINDOWS\system32    NTdhcp.exe    本机
用日志扫描结果如下:
O17 - HKLM\System\CCS\Services\Tcpip\..\{543FEC00-8534-4804-9486-49B7D668495C}: NameServer = 202.113.112.55
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
怎么也找不到哪个是灰鸽子,各位高手能帮帮忙么,谢谢!
最后编辑2005-10-12 11:25:30
分享到:
gototop
 

先杀毒再说,如果杀净了就OK。
gototop
 

【回复“kkruye”的帖子】瑞星根本就杀不了啊!如果能杀的话,我就不来发帖求助了,呵呵
gototop
 

全部的日志看下
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 10:25:50, on 2005-10-12
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\Explorer.EXE
d:\program files\adobe acrobat5.0\Acrobat\Acrobat.exe
C:\Program Files\Common Files\Adobe\Web\AOM.exe
C:\WINDOWS\system32\conime.exe
D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
D:\PROGRAM FILES\RISING\RAV\RavStub.exe
d:\program files\rising\rav\RAVMON.EXE
d:\program files\rising\rav\RAVTIMER.EXE
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\rising\Rav\Rav.exe
D:\Program Files\Tencent\qq\QQ.exe
D:\Program Files\Tencent\qq\TIMPlatform.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\xuchunjie\灰鸽子&扫描机\HijackThis.exe

O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O3 - Toolbar: 卡卡安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O4 - HKLM\..\Run: [RavTimer] D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [KFW] "D:\Program Files\防火墙\kfw.exe" minimize
O8 - Extra context menu item: 使用搜狗直通车下载 - D:\PROGRA~1\sougou\dl.htm
O8 - Extra context menu item: 使用网际快车下载 - D:\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\qq\SendMMS.htm
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - D:\Program Files\浩方\浩方对战平台\GameClient.exe (file missing)
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{543FEC00-8534-4804-9486-49B7D668495C}: NameServer = 202.113.112.55
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe

gototop
 

没问题,你搜一下手工删吧。安全模式,打开文件的隐藏属性。
gototop
 

【回复“kkruye”的帖子】谢谢了
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT