瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 灰鸽子病毒(Backdoor.Gpigeon.xav),怎么也清除不掉

123   2  /  3  页   跳转

灰鸽子病毒(Backdoor.Gpigeon.xav),怎么也清除不掉

启动项那么长?
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
一楼附件...下载HijackThis...把日志帖上来..
gototop
 

[IBM KCU Service / TpKmpSVC]
<C:\WINDOWS\system32\TpKmpSVC.exe><N/A>
[Remote access protect / Remote access protect]
<C:\WINDOWS\system32\protect.exe><N/A>
[qq / qq]
<><N/A>
[IBM PM Service / IBMPMSVC]
<C:\WINDOWS\System32\ibmpmsvc.exe><N/A>
[Logical Service Web / Logical Service Web ]
<><N/A>

小聪你看这玩意头不晕..我都懒得看这玩意..
还是HijackThis好..
gototop
 


==================================
浏览器加载项
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems

Incorporated>
[MonitorURL Class]
  {08A312BB-5409-49FC-9347-54BB7D069AC6} <C:\PROGRA~1\DESKAD~1\deskipn.dll, N/A>
[Zhongsou Browser Helper]
  {2A0176FE-008B-4706-90F5-BBA532A49731} <C:\Program Files\SearchNet\SNHpr.dll, Beijing Zhongsou Online Software>
[IE Browser Helper]
  {3CE496D1-1746-41CD-9489-3C0B93DF10E2} <C:\WINDOWS\Downlo~1\uapep.dll, 中搜在线软件有限公司>
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <d:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[BandIE Class]
  {77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\PROGRA~1\baidu\bar\baidubar.dll, Baidu.com, Inc.>
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[SDObmObj Class]
  {D4D5C535-BA95-4327-870D-A33826FDD17A} <C:\WINDOWS\System32\obwbkya.dll, 北京兴华基业软件技术有限公司>
[超级兔子上网精灵]
  {FEDF637B-F631-4583-A210-33CC828D42DB} <C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~2.DLL, 超级兔子>
[维宇RealLink]
  {0713E8D2-850A-101B-AFC0-4210122A8DA9} <C:\Program Files\VerySoft\RealLink\RealLink.exe, 武汉维宇软件有限公司>
[相关站点]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <E:\PROGRA~1\FlashGet\fgiebar.dll, Amaze Soft>
[电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
[&Google]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, Google Inc.>
[一搜工具条]
  {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} <, N/A>
[百度超级搜霸]
  {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\PROGRA~1\baidu\bar\baidubar.dll, Baidu.com, Inc.>
[超级兔子上网精灵]
  {FEDF637B-F631-4583-A210-33CC828D42DB} <C:\PROGRA~1\SUPERR~1\MagicSet\HAOKAN~2.DLL, 超级兔子>
[NowStarter Control]
  {072039AB-2117-4ED5-A85F-9B9EB903E021} <C:\WINDOWS\DOWNLO~1\NOWSTA~1.OCX, (C) NOWCOM>
[YInstStarter Class]
  {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} <C:\WINDOWS\Downloaded Program Files\yinsthelper.dll, Yahoo! Inc.>
[XIsOro Control]
  {48FE89A0-486C-48DF-9DEC-BED22BDC6057} <C:\WINDOWS\DOWNLO~1\XISORO~1.OCX, >
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\System32\wuweb.dll, Microsoft Corporation>
[Java Plug-in 1.4.1]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll, IBM.>
[TV Stream Source]
  {BE9535B7-76FB-4572-AD20-B32BADB3643B} <C:\WINDOWS\System32\FAggr.ax, www.sina.com.cn>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx, Macromedia, Inc.>
[Rising Web Scan Object]
  {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} <C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Technology Co.,

Ltd.>
[JoinBaduk Control]
  {E9429003-6294-4F4F-BCAB-83AD4DAAFED0} <C:\WINDOWS\DOWNLO~1\JOINBA~1.OCX, tygem>
[使用网际快车下载]
  <E:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <E:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <D:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <D:\Program Files\Tencent\QQ\SendMMS.htm, N/A>
[用比特精灵下载(&B)]
  <D:\Program Files\BitSpirit\bsurl.htm, N/A>
[百度--MP3搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HTM, N/A>
[百度--图片搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HTM, N/A>
[百度--新闻搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.HTM, N/A>
[百度--歌词搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.HTM, N/A>
[百度--网页搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH.HTM, N/A>
[百度--词典搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.HTM, N/A>
[百度--贴吧搜索]
  <RES://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.HTM, N/A>
gototop
 

安全模式..打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索  TpKmpSVC      protect.exe      qq      Logical Service Web      IBMPMSVC  ..删除掉咯..
删除
  C:\WINDOWS\system32\protect.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\System32\ibmpmsvc.exe
gototop
 

十三楼的老师,我去试试瞧
gototop
 

IBM KCU Service / TpKmpSVC]
<C:\WINDOWS\system32\TpKmpSVC.exe><N/A>
[IBM PM Service / IBMPMSVC]
<C:\WINDOWS\System32\ibmpmsvc.exe><N/A>

这两个删不得
这是IBM的东东。
gototop
 

1
gototop
 

帖子看不了了。
gototop
 

论坛最近问题多...
老是服务器忙 烦躁..
有的帖子有回的..但是只能看到..楼主的信息..
gototop
 

进入控制面版的添加删除程序中卸载,中搜。

运行System Repair Engineer,点“启动项目,服务,勾选“隐藏微软服务”选中病毒服务System Event Logger,Logical Service Web,qq ,Remote access protect选择“删除所选服务”“否”最后重启。(每一个逗号隔开的就是一个病毒的服务,请逐一删除)
重启后
删除
C:\WINDOWS\system32\protect.exe
C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL
日志很乱,修复后。
请用System Repair Engineer,再扫份报告粘上来。
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT