瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 Backdoor.Gpigeon.uvc 这是什么病毒?怎样彻底查杀?请高手指点

1   1  /  1  页   跳转

Backdoor.Gpigeon.uvc 这是什么病毒?怎样彻底查杀?请高手指点

Backdoor.Gpigeon.uvc 这是什么病毒?怎样彻底查杀?请高手指点

这两天用瑞星查杀毒,发现总有这个,Backdoor.Gpigeon.uvc ,昨天杀了,今天开机查还是有呢,怎样彻底杀掉它,下面是我的扫描日志,请高手给于指点:
Logfile of HijackThis v1.99.1
Scan saved at 7:18:24, on 2006-1-28
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
d:\瑞星杀毒软件\CCenter.exe
C:\WINDOWS\System32\svchost.exe
d:\瑞星杀毒软件\Ravmond.exe
d:\瑞星防火墙\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
d:\瑞星杀毒软件\RavStub.exe
d:\瑞星防火墙\RfwMain.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\瑞星杀毒软件\RavTask.exe
C:\WINDOWS\VM303_STI.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
D:\瑞星杀毒软件\Ravmon.exe
D:\SERV-U\ServUDaemon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\mshta.exe
D:\瑞星杀毒软件\Rav.exe
D:\瑞星杀毒软件\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
D:\瑞星杀毒软件\RsLogVw.exe
C:\WINDOWS\system32\NOTEPAD.EXE
G:\Downloads\software\应用\日志检查\HijackThis.exe
G:\Downloads\software\应用\Windows进程管理器 v3.30\PrcMgr.exe

R3 - Default URLSearchHook is missing
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\下略载毓工ぞ具逫Internet Download Manager\IDMIECC.dll (file missing)
O2 - BHO: CCIT Memory Manager - {2CE7166E-8BBA-4E76-BA7E-02AB3C573011} - C:\WINDOWS\system32\cytdcli.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll (file missing)
O2 - BHO: URLMonitor Class - {3ED9FFDA-79DB-4B2D-99B7-16EA3C4A3A92} - C:\WINDOWS\system32\hap.dll
O2 - BHO: DownloadValue Class - {616D4040-5712-4F0F-BCF1-5C6420A99E14} - C:\WINDOWS\system32\winhtp.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O3 - Toolbar: 完美网译通 - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - C:\WINDOWS\WORLD2\TOOLBAR\hmtoolbar.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [醒目提示器] D:\1醒目桌面自动管理大师1\run.exe
O4 - HKLM\..\Run: [RavTask] "d:\瑞星杀毒软件\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "D:\瑞星防火墙\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item:  >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O8 - Extra context menu item: VeryCD搜索 - C:\Program Files\YOK.com\SuperSearch\yoksch.htm
O8 - Extra context menu item: 使用 IDM 下载 - D:\下载工具Internet Download Manager\IEExt.htm
O8 - Extra context menu item: 使用 IDM 下载所有链接 - D:\下载工具Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: 使用网际快车下载 - D:\tool\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\tool\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\qq\SendMMS.htm
O9 - Extra button: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - D:\浩方对战平台\GameClient.exe (file missing)
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\tool\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\tool\FlashGet\flashget.exe
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {AC036CB4-328D-4DB4-A707-4147B6C20266} (YLauncher Class) - http://et.263.net/realplayer/ephTool.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A01EE0A7-C53E-4700-A000-AF2AC6A5EDF2}: NameServer = 202.99.160.68,211.136.17.107
O23 - Service: Garden Server - Unknown owner - C:\WINDOWS\Garden.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - d:\瑞星防火墙\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - d:\瑞星杀毒软件\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - d:\瑞星杀毒软件\Ravmond.exe
O23 - Service: Serv-U FTP Server (Serv-U) - Unknown owner - D:\SERV-U\ServUDaemon.exe

最后编辑2006-01-28 08:52:37
分享到:
gototop
 

O23 - Service: Garden Server - Unknown owner - C:\WINDOWS\Garden.exe
根本就没删除
http://forum.ikaka.com/topic.asp?board=28&artid=6202404参考这个帖子杀
gototop
 

O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
这个好像也不对吧!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT