瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了backdoor.gpigeon.2006.iw,该怎么办啊,谁帮我看看【求助】

12   1  /  2  页   跳转

中了backdoor.gpigeon.2006.iw,该怎么办啊,谁帮我看看【求助】

中了backdoor.gpigeon.2006.iw,该怎么办啊,谁帮我看看【求助】

今天用瑞星查杀病毒,发现好多backdoor.gpigeon.2006.iw病毒,显示清楚成功了,可下次查还有,杀不清啊,该怎么办啊,急死我了,大家帮帮我啊,谢谢
最后编辑2006-06-12 12:11:33
分享到:
gototop
 

【回复“小猪丢丢”的帖子】
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
(1楼附件)
下载HIJACKTHIS
导出全部日志
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 9:57:28, on 2006-6-12
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
F:\KV2006\KVSrvXP.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\Rundll32.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\System32\hkcmd.exe
F:\KV2006\KVMonXP.kxp
C:\Program Files\Rising\Rav\RavTask.exe
F:\下载\magicset739\MagicSet\DS.EXE
C:\Program Files\KVFW\kvfw.exe
C:\Program Files\Rising\Rav\Ravmon.exe
F:\KV2006\TrojDie.kxp
F:\KV2006\KRegEx.exe
F:\KV2006\UIHost.exe
C:\Program Files\ChinaNet\VnetClient.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINNT\msagent\AgentSvr.exe
F:\工具\MYIE2\MYIE.EXE
F:\工具\xunlei\Thunder.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.248\HijackThis.exe

R3 - URLSearchHook: BDSrchHook Class - {2C5AA40E-8814-4EB6-876E-7EFB8B3F9662} - C:\WINNT\DOWNLO~1\BDSrHook.dll
O1 - Hosts: www.cnmir.net
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINNT\System32\xunleibho_v11.dll
O2 - BHO: FiltrateWebObj Class - {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} - F:\KV2006\KVBHO.dll
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - F:\工具\QQIEHelper.dll
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - F:\KV2006\KvShell.dll
O2 - BHO: BDHlprObj Class - {CA92B524-BC8A-4610-BD2C-6BD3E28155D0} - C:\WINNT\DOWNLO~1\BDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - F:\KV2006\KvShell.dll
O3 - Toolbar: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\assist\asbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] ; C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] ; SOUNDMAN.EXE
O4 - HKLM\..\Run: [KvMonXP] "F:\KV2006\KVMonXP.kxp" /auto
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [PCSuiteTrayApplication] ; C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] ; C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - HKLM\..\Run: [Super Rabbit Desktop Set] F:\下载\magicset739\MagicSet\DS.EXE /Load
O4 - HKCU\..\Run: [KVFW] C:\Program Files\KVFW\kvfw.exe -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [KvXP] "F:\KV2006\KvXP.kxp" /ScanBoot /ScanSys
O4 - HKCU\..\Run: [PcSync] ; C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Startup: 腾讯QQ.lnk = ?
O8 - Extra context menu item: &使用迅雷下载 - F:\工具\xunlei\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\工具\xunlei\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\工具\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://F:\工具\OFFICE~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\工具\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\工具\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\工具\SendMMS.htm
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\工具\OFFICE~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\工具\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\工具\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\工具\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\工具\QQIEHelper.dll
O11 - Options group: [TBH]  搜搜地址栏搜索
O15 - Trusted Zone: http://www.icbc.com.cn
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147066410726
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147066919808
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A34D348-3EAF-4BEA-B6B5-AACC4F1CFE72}: NameServer = 202.102.192.68 202.102.199.68
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: KVSrvXP - Jiangmin Co. Ltd - F:\KV2006\KVSrvXP.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

帮我看看啊,上面是日志,谢谢
gototop
 

【回复“小猪丢丢”的帖子】
日志没有问题啊

http://www.xfocus.net/tools/200605/1161.html
下载IceSword
用IceSword查看系统服务项
看能否找到灰鸽子的相关服务
gototop
 

下面是进程结果,帮我看看,谢谢

附件附件:

下载次数:230
文件类型:image/pjpeg
文件大小:
上传时间:2006-6-12 10:39:56
描述:



gototop
 

刚才没弄好,下面这个是,帮我看看啊,谢谢

附件附件:

下载次数:271
文件类型:image/pjpeg
文件大小:
上传时间:2006-6-12 10:43:00
描述:



gototop
 

【回复“小猪丢丢”的帖子】
晕倒
查看系统服务项啊
gototop
 

不好意思啊,搞错了,下面这个是吗?帮我看看,谢谢

附件附件:

下载次数:254
文件类型:image/pjpeg
文件大小:
上传时间:2006-6-12 10:58:11
描述:



gototop
 

你看我的瑞星扫描结果

附件附件:

下载次数:231
文件类型:image/pjpeg
文件大小:
上传时间:2006-6-12 11:04:52
描述:



gototop
 

【回复“小猪丢丢”的帖子】
楼主中了插入系统进程的灰鸽子

建议:
http://www.KZTechs.com
下载System Repair Engineer
导出全部日志
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT