瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了Backdoor.GPigeon.thx和Backdoor.GPigeon.ths如何清除

1   1  /  1  页   跳转

中了Backdoor.GPigeon.thx和Backdoor.GPigeon.ths如何清除

中了Backdoor.GPigeon.thx和Backdoor.GPigeon.ths如何清除

每次重启,在IE里都能杀出以上两个Backdoor.GPigeon.thx和Backdoor.GPigeon.ths病毒其中一个,还真拿它们没有办法,有没有高手支招,先谢了
最后编辑2006-03-21 09:27:56
分享到:
gototop
 

请到http://www.spywareinfo.com/~merijn/files/hijackthis.zip 下载Hijackthis,贴个log上来
gototop
 

【回复“人人为我为人人”的帖子】
关于HijackThis日志发现灰鸽子的处理方法:
http://forum.ikaka.com/topic.asp?board=28&artid=7713905

HIJACKTHIS下载:
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
gototop
 

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Tencent\QQ\QQ.exe
E:\Tencent\QQ\TIMPlatform.exe
E:\Tencent\QQ\QQ.exe
C:\Program Files\Thunder Network\Thunder\Thunder.exe
E:\inst\ha_hijackthis_1991\HijackThis.exe

O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\system32\xunleibho_v14.dll
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\BaiduBar.dll
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - E:\KuGoo2\KuGoo3DownXControl.ocx
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\BaiduBar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - E:\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用KuGoo3下载(&K) - E:\KuGoo2\KuGoo3DownX.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - E:\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - E:\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - E:\Tencent\QQ\SendMMS.htm
O9 - Extra button: 联想 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.lenovo.com (file missing)
O14 - IERESET.INF: START_PAGE_URL=about:blank
O17 - HKLM\System\CCS\Services\Tcpip\..\{191B7E8C-AD05-47CA-B7F4-415546E2E4FF}: NameServer = 211.98.2.4,211.98.4.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{191B7E8C-AD05-47CA-B7F4-415546E2E4FF}: NameServer = 211.98.2.4,211.98.4.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{191B7E8C-AD05-47CA-B7F4-415546E2E4FF}: NameServer = 211.98.2.4,211.98.4.1
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - 灰色天空专版 - C:\WINDOWS\Server.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
请问一下,这里什么程序需要恢复的
gototop
 

【回复“人人为我为人人”的帖子】
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - 灰色天空专版 - C:\WINDOWS\Server.exe
灰鸽子
参考http://forum.ikaka.com/topic.asp?board=28&artid=7713905
gototop
 

下载“灰鸽子”专用检测清除工具试试:
http://it.rising.com.cn/service/technology/Ravgpk_Download1.htm

灰鸽子病毒手工清除方法[多图]
http://it.rising.com.cn/newSite/Channels/Anti_Virus/Antivirus_Base/Antivirus_Tech/200502/01-112318318.htm

“瑞星听诊器”可检测huigezi等木马程序
http://it.rising.com.cn/service/technology/RS_RavDetect.htm

网友杀毒经验共享:杀绝灰鸽子(Trojan.Huigezi)
http://it.rising.com.cn/newSite/Channels/Anti_Virus/Antivirus_Base/Antivirus_Tech/200312/25-103013344.htm
gototop
 

已按四楼的指出删了,瑞星再也不提示了,重启杀毒正常了,谢谢各位高手
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT