12   2  /  2  页   跳转

Backdoor.Gpigeon.bc

O23 - NT 服务: Gray_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\G_Server.exe
这个服务 就是老
前面你在看上面的介绍吧 按照上面贴子做就行老 试试 有不一样的收获哦
gototop
 

O23 - NT 服务: Gray_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\G_Server.exe
典型得不能再典型的灰鸽子了,参考置顶帖解决。
楼主要是一上来就说清楚和发日志的话,早就搞定了
gototop
 

C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\MySQL\bin\mysqld.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\OpenSSL.exe
这几个我也不知道是啥 你装了点啥东西?
gototop
 

楼主的日志简直是流氓软件大全!!如果要彻底解决问题的话,就按以下做:
结束进程:
C:\Program Files\WhenUSearch\Search.exe
C:\Program Files\Save\Save.exe
C:\Program Files\DuDu\DddClient\DuDuAcc.exe
C:\Program Files\DuDu\DddClient\dudupros.exe
修复
O2 - BHO: wmpdrm - {0E674588-66B7-4E19-9D0E-2053B800F69F} - C:\WINDOWS\System32\wmpdrm.dll
O2 - BHO: QuickBtn - {1A199C20-DE2B-4838-AE3F-B5257ECE2B7E} - C:\Program Files\CoolWebsite\QuickLink.dll
O2 - BHO: Link Filter - {4022F902-ABC7-4C79-924F-BB26F1D355A2} - C:\WINDOWS\System32\diybar2\diybar2.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O2 - BHO: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: DuDu.com - {6BDE1669-B490-48E3-B668-456314F2D6C3} - C:\Program Files\DuDu\DddClient\dddiemon.dll
O2 - BHO: BHelper - {8A4280AD-9B37-4922-A51D-73F3C3A32AF7} - C:\WINDOWS\System32\msibm\cfsbho.dll
O2 - BHO: NewWeb Controller - {9ACEEE30-143F-471A-AA45-72B061FE7D60} - C:\WINDOWS\system32\AdvSC32.dll
O2 - BHO: HBObject Class - {AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} - C:\PROGRA~1\HBClient\tbhelper.dll
O2 - BHO: T2BHO Class - {B1D147E7-873E-4909-8127-695D9BB78728} - C:\WINDOWS\Downloaded Program Files\barhelp24.0.dll
O2 - BHO: MacroMediapd - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD} - C:\WINDOWS\System32\microapmddt.dll (file missing)
O2 - BHO: WhenUSearch Helper - {BA2325ED-F9EB-4830-8FCE-0BC35B16969B} - C:\Program Files\WhenUSearch\search.dll
O2 - BHO: MEobjectSDT - {D4D5C535-BA95-4327-870D-A33826FDD17A} - C:\WINDOWS\System32\obwbkya.dll
O3 - IE工具栏增项: 虎翼DIY吧! - {0A00D11E-B1E7-44b5-AD88-C9190876AAC4} - C:\WINDOWS\System32\diybar2\diybar2.dll
O3 - IE工具栏增项: 天下搜索 - {56A7DC70-E102-4408-A34A-AE06FEF01586} - C:\WINDOWS\Downloaded Program Files\iebar23.0.dll
O3 - IE工具栏增项: YOK超级搜索 - {F869BB38-FFEF-4589-B986-610B7AD0ADA2} - C:\PROGRA~1\YOK.com\SUPERS~1\YOK_SuperSearch.dll
O4 - 启动项HKLM\\Run: [WindowsUpdate] C:\WINDOWS\System32\WindowsUpdate.exe
O4 - 启动项HKLM\\Run: [Update] C:\Program Files\Common Files\UPDAT\Update.exe
O4 - 启动项HKLM\\Run: [spoolsv] C:\WINDOWS\System32\spoolsv\spoolsv.exe -printer
O4 - 启动项HKLM\\Run: [RichMedia] C:\WINDOWS\System32\Rundll32.exe "C:\PROGRA~1\HBClient\tbhelper.dll",WaitWindows
O4 - 启动项HKLM\\Run: [mscfs] RUNDLL32 C:\WINDOWS\System32\msibm\cfsys.dll,cfs
O4 - 启动项HKLM\\Run: [WhenUSearch] "C:\Program Files\WhenUSearch\Search.exe"
O4 - 启动项HKLM\\Run: [WhenUSearchWHSE] "C:\Program Files\WhenUSearch\whse.exe"
O4 - 启动项HKLM\\Run: [supdate2.dll] RUNDLL32.EXE C:\WINDOWS\System32\supdate2.dll,Run
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - Global Startup: DuDu下载加速器.lnk = C:\Program Files\DuDu\DddClient\DuDuAcc.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: >> 彩信发送 << - res://C:\PROGRA~1\MMSASS~1\Mmsass~1.dll/mms.htm
O8 - IE右键菜单中的新增项目: &使用DuDu 加速器下载 - res://C:\Program Files\DuDu\DddClient\dddmext.dll/202
O8 - IE右键菜单中的新增项目: &使用DuDu 加速器下载全部链接 - res://C:\Program Files\DuDu\DddClient\dddmext.dll/203
O8 - IE右键菜单中的新增项目: YOK搜索 - C:\Program Files\YOK.com\SuperSearch\yoksch.htm
9 - 浏览器额外的按钮: 实用网址导航 - {1D901067-2529-4A9B-9B6B-7A1DB3A44CB5} - C:\Program Files\CoolWebsite\QuickLink.dll
O9 - 浏览器额外的按钮: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O9 - 浏览器额外的“工具”菜单项: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\Mmsass~1.dll
O16 - DPF: {28E0FA88-ABA8-4937-A247-3031F1A11165} (Installer Class) - http://pi.51.net/download/diybar2.cab
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} (天下搜索) - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {8135EF31-FE8C-4C6E-A18A-F59944C3A488} (Spocx Class) - http://ddddl.dudu.com/ddd/update/plugin/dddspocx.cab
O16 - DPF: {EF9F1C48-1A63-495A-9317-B7B71B34A9CF} (Msp Class) - http://ddddl.dudu.com/ddd/update/plugin/dudumsp.cab
O23 - NT 服务: SDAgent Service (SDAgentService) - 北京兴华基业软件技术有限公司 - C:\Program Files\Common Files\smartde\sde.exe

未完待续
gototop
 

这台机器简直太乱了...
gototop
 

看看头都晕
gototop
 

卸载删除(是文件夹的,里面有卸载程序的,先卸载再删除,其他文件夹和文件通通删除):
C:\Program Files\WhenUSearch\(最后有一个“\”表示整个文件夹,下同)
C:\Program Files\Save\
C:\Program Files\DuDu\DddClient\
C:\WINDOWS\System32\wmpdrm.dll
C:\Program Files\CoolWebsite\
C:\WINDOWS\System32\diybar2\
C:\PROGRA~1\MMSASS~1\
C:\WINDOWS\SYSTEM32\stdup.dll(参考http://forum.ikaka.com/topic.asp?board=67&artid=7423269)
C:\WINDOWS\System32\msibm\
C:\WINDOWS\System32\msicn\(若存在的话)
C:\WINDOWS\system32\AdvSC32.dll
C:\PROGRA~1\HBClient\(参考http://forum.ikaka.com/topic.asp?board=28&artid=7795226)
C:\WINDOWS\Downloaded Program Files\barhelp24.0.dll
C:\WINDOWS\System32\obwbkya.dll
C:\WINDOWS\Downloaded Program Files\iebar23.0.dll
C:\PROGRA~1\YOK.com\
C:\WINDOWS\System32\WindowsUpdate.exe
C:\Program Files\Common Files\UPDAT\
O4 - 启动项HKLM\\Run: [spoolsv] C:\WINDOWS\System32\spoolsv\(注意是文件夹,不要删错了)
C:\WINDOWS\System32\supdate2.dll,Run
C:\PROGRA~1\MMSASS~1\
C:\Program Files\Common Files\smartde\

呼,终于搞定了,大家帮忙看看还有什么遗漏的。
gototop
 

搞定了以上的这些之后,你会觉得开机速度、上网速度等各方面都改善了不少,CPU占用率也不会如以前那么高了,也不会弹出莫名其妙的网页。
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT