瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】电脑中了灰鸽子,求彻底杀毒方法!

12   2  /  2  页   跳转

【求助】电脑中了灰鸽子,求彻底杀毒方法!

O23 - NT 服务:   - Unknown owner - D:\WINDOWS\Server.exe
就是这个啊,鸽子!~杀~~
杀查方法详见:
http://forum.ikaka.com/topic.asp?board=28&artid=6202404
http://forum.ikaka.com/topic.asp?board=28&artid=6882330
gototop
 

晕,谁有彻底的解决办法吗?不想天天杀。。。求高人~
gototop
 

修复:

R3 - URLSearchHook: MyURLSearchHook Class - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - D:\PROGRA~1\P4P\Toolbar.dll (file missing)
O1 - Hosts: 218.83.153.7 share.greedland.net
O1 - Hosts: 210.41.224.136 www.cuit.edu.cn
O1 - Hosts: 218.204.251.19 zm.mycng.cn
O1 - Hosts: 61.129.93.115 www.wowchina.com
O1 - Hosts: 61.152.145.35 www.1t1t.com
O1 - Hosts: 61.183.15.95 www.mop.com
O1 - Hosts: 64.233.189.104 www.google.com
O1 - Hosts: 219.239.89.45 www.enet.com.cn
O1 - Hosts: 218.10.216.131 bbs1.btbbt.com
O1 - Hosts: 203.90.128.75 www.lovemgc.com
O1 - Hosts: 61.152.145.79 bbs3.btbbt.com
O1 - Hosts: 218.199.102.216 bbs.5qzone.net
O1 - Hosts: 218.7.69.214 bbs.lovemgc.com
O1 - Hosts: 61.129.90.159 wowsearch.92wy.com
O1 - Hosts: 211.161.159.90 bt2.btchina.net
O1 - Hosts: 220.181.27.5 www.baidu.com
O1 - Hosts: 61.152.188.174 www.wfbrood.com
O1 - Hosts: 219.136.244.102 www.pconline.com.cn
O1 - Hosts: 61.152.107.141 to.gamigo.com.cn
O1 - Hosts: 218.92.50.27 comic.ktxp.com
O1 - Hosts: 219.129.20.134 www.qq163.com
O1 - Hosts: 219.238.237.140 fairyland.aijoy.com
O1 - Hosts: 202.85.22.10 bbs.100free.net
O1 - Hosts: 202.85.22.10 100free.net
O1 - Hosts: 202.85.22.10 www.100free.net
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - D:\WINDOWS\system32\xunleibho_v4.dll
O2 - BHO: 搜索助手 - {04844102-FC0B-4f44-9E93-0C4293BB5E80} - (no file)
O2 - BHO: SohuDAIEHelper - {0CA51D02-7739-43EA-8D9A-1E8AD4327B03} - D:\Program Files\P4P\sodaie.dll (file missing)
O2 - BHO: Infofo 工具栏 - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\Program Files\Infofo Bar\infofobar.dll (file missing)
O3 - IE工具栏增项: 博采 - {4DA2EE61-6399-4C39-AEB9-0D990E610D29} - D:\WINDOWS\system32\BOCAIT~1.DLL (file missing)

gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=6202404
http://forum.ikaka.com/topic.asp?board=28&artid=6882330
这两个帖子写的很详细了,仔细看看!~
gototop
 

【回复“eeeeee111”的帖子】
那说个简单点的,进安全模式,显示所有文件,把隐藏系统文件的钩去掉,找到D:\WINDOWS\Server.exe文件删除,
在去注册表里找到它生成的服务,把它删掉就行了。。
O23 - NT 服务:   - Unknown owner - D:\WINDOWS\Server.exe
这个服务好象没名字。。。。
gototop
 

我也中了,帮忙看一下,谢了。


HijackThis_zww汉化版扫描日志 V1.99.1
保存于      :10:06, 日期 2005-11-24
操作系统:  Windows XP  (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 (6.00.2600.0000)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\eEBAPI\SAgent2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
E:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\JJOL\IME\JJSvr.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Jedi\LOCALS~1\Temp\Rar$EX00.973\HijackThis1991zww.exe

O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - E:\PROGRA~1\FLASHGET\jccatch.dll
O3 - IE工具栏增项: (no name) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - (no file)
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - E:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [NvCplDaemon] rem  RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - 启动项HKLM\\Run: [SysExplr] rem  E:\HEROSOFT\SYSEXPLR.EXE
O4 - 启动项HKLM\\Run: [Super Rabbit SRRestore] rem  E:\PROGRA~1\SUPERR~1\MAGICSET\SRRest.exe /autosave
O4 - 启动项HKLM\\Run: [EPSON Stylus C41 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C41 Series" /O6 "USB001" /M "Stylus C41"
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - 启动项HKLM\\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - 启动项HKLM\\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - E:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - E:\Program Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - 浏览器额外的按钮: NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - C:\WINDOWS\System32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: &NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - C:\WINDOWS\System32\shdocvw.dll
O9 - 浏览器额外的按钮: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm (file missing)
O9 - 浏览器额外的按钮: (no name) - {BF1F4A1A-BDCD-43ac-9D17-261D2C197AB8} - http://assistant.3721.com/uninstall.htm (file missing)
O9 - 浏览器额外的“工具”菜单项: 卸载网络实名 - {BF1F4A1A-BDCD-43ac-9D17-261D2C197AB8} - http://assistant.3721.com/uninstall.htm (file missing)
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的按钮: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm (file missing)
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm (file missing)
O11 - Options group: [!CNS]  网络实名
O16 - DPF: {1AF783BD-BFC0-48A2-816E-A667B2BC69E9} (CHtmlClientView Object) - http://zdc.zol.com.cn/Ip1HtmlClientView.dll
O16 - DPF: {1F831FA1-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://E:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1132791653730
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday 控件) - file://E:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {A2C271DF-91C3-11D5-9FA6-860301900128} (PPlayerX Control) - http://ad4.sina.com.cn/ads/test/av/pplayer.cab
O16 - DPF: {AE563722-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://E:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview 控件) - file://E:\Program Files\AutoCAD 2002\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{AFD1C383-CE70-430A-8CEF-DC35ECC3F4C5}: NameServer = 61.144.56.101 202.96.128.86
O23 - NT 服务: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\eEBAPI\SAgent2.exe
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - NT 服务: Print Spooler Desktop Sharing (PriSpds) - Unknown owner - C:\WINDOWS\PrintSpooler.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe

gototop
 

O23 - NT 服务: Print Spooler Desktop Sharing (PriSpds) - Unknown owner - C:\WINDOWS\PrintSpooler.exe
鸽子。!~
杀查方法详见帖子:
http://forum.ikaka.com/topic.asp?board=28&artid=6202404
http://forum.ikaka.com/topic.asp?board=28&artid=6882330


仔细看看会有帮助的!~

你要懒的看,我在这里说说。
先停掉Print Spooler Desktop Sharing (PriSpds)这个服务,
服务名字可能是(priSpds),然后显示所有文件,把隐藏系统文件的钩去掉,找到C:\WINDOWS\PrintSpooler.exe文件,删除!~
去注册表里,找到prispds这个服务,删掉就好了。。

gototop
 

微点主动防御软件对新病毒,黑客攻击,木马特别是针对灰鸽子这样变种多的病毒很有效果,建议有这样问题的朋友不仿去下下来装看看,
www.micropoint.com.cn
gototop
 

to 病毒新手,谢谢了,杀了,瑞星查 不到病毒了,但上网的时候还是遇到攻击。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT