瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 救命啊 我机器中了 backdoor.gpigeon.2006.ip 怎么杀啊

12   2  /  2  页   跳转

救命啊 我机器中了 backdoor.gpigeon.2006.ip 怎么杀啊

==================================
正在运行的进程
[PID: 732][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 820][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 844][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\igfxdev.dll]  <Intel Corporation><3.0.0.4396>
[PID: 888][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\msplus1.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\msplus.dll]  <><1, 0, 0, 1>
[PID: 900][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1068][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1156][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\msplus1.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 1276][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\system32\msplus1.dll]  <><1, 0, 0, 1>
[PID: 1376][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1496][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
[PID: 1528][C:\PROGRAM FILES\RISING\RAV\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><17, 0, 1, 58>
    [C:\PROGRAM FILES\RISING\RAV\guidll.dll]  <rising><17, 0, 0, 13>
    [C:\PROGRAM FILES\RISING\RAV\RsCommX.dll]  <rising><17, 0, 0, 3>
    [C:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL]  <Rising Corp.><17, 0, 0, 7>
    [C:\PROGRAM FILES\RISING\RAV\CfgDll.dll]  <Rising Corp.><17, 0, 1, 71>
    [C:\Program Files\Rising\Rav\Scanner.dll]  <Rising><17, 0, 0, 43>
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
    [C:\Program Files\Rising\Rav\libload.dll]  <Rising><17, 0, 0, 14>
    [C:\Program Files\Rising\Rav\VirusLib.dll]  <Rising><17, 0, 0, 26>
    [C:\PROGRAM FILES\RISING\RAV\MailMon.dll]  < ><17, 0, 0, 9>
    [C:\Program Files\Rising\Rav\engine.dll]  <rising><17, 0, 0, 43>
    [C:\Program Files\Rising\Rav\UnExe.dll]  <Rising><17, 0, 0, 31>
    [C:\Program Files\Rising\Rav\SpamEng.dll]  <N/A><17, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanEx.dll]  <Rising><17, 0, 0, 39>
    [C:\Program Files\Rising\Rav\PostTrt.dll]  <Rising><17, 0, 0, 21>
    [C:\PROGRAM FILES\RISING\RAV\MemMon.dll]  <北京瑞星><17, 8, 0, 0>
    [C:\Program Files\Rising\Rav\NvFile.dll]  <瑞星><17, 0, 0, 13>
    [C:\PROGRAM FILES\RISING\RAV\expscan.dll]  <N/A><17, 0, 0, 6>
    [C:\Program Files\Rising\Rav\ScanMac.dll]  <rising><17, 0, 0, 20>
    [C:\Program Files\Rising\Rav\ScanSct.dll]  <rising><17, 0, 0, 37>
    [C:\Program Files\Rising\Rav\ScanExec.dll]  <N/A><17, 0, 0, 23>
    [C:\Program Files\Rising\Rav\Unpacker.dll]  <rising><17, 0, 0, 19>
    [C:\PROGRAM FILES\RISING\RAV\mPorts.dll]  <Beijing Rising Technology Corporation Limited><3, 0, 0, 3>
    [C:\PROGRAM FILES\RISING\RAV\regmon.dll]  < ><17, 0, 0, 12>
    [C:\PROGRAM FILES\RISING\RAV\HookWeb.dll]  <rising><17, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsStore.dll]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 10>
    [C:\Program Files\Rising\Rav\posttrtx.dll]  <瑞星科技股份有限公司><17, 0, 0, 32>
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  <rising><17, 0, 0, 22>
[PID: 1572][C:\PROGRAM FILES\RISING\RAV\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 27>
    [C:\PROGRAM FILES\RISING\RAV\RsCommX.dll]  <rising><17, 0, 0, 3>
    [C:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
[PID: 1776][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)>
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\vprproc.dll]  <Windows (R) 2000 DDK provider><5.00.2195.1620>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBF252E.DLL]  <Hewlett-Packard Company><4.27.5100.430>
[PID: 1944][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\WINDOWS\system32\igfxpph.dll]  <Intel Corporation><3.0.0.4396>
    [C:\WINDOWS\system32\hccutils.DLL]  <Intel Corporation><3.0.0.4396>
    [C:\WINDOWS\system32\igfxres.dll]  <Intel Corporation><3.0.0.4396>
    [C:\WINDOWS\system32\igfxress.dll]  <Intel Corporation><3.0.0.4396>
    [C:\WINDOWS\system32\igfxsrvc.dll]  <Intel Corporation><3.0.0.4396>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 8>
    [C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll]  <CNNIC><1, 0, 0, 11>
[PID: 228][C:\Program Files\Rising\Rav\RavTray.exe]  <Rising><17, 0, 0, 32>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\Program Files\Rising\Rav\RavTray936.dll]  <Rising><17, 0, 0, 28>
    [C:\Program Files\Rising\Rav\RsCommx.dll]  <rising><17, 0, 0, 3>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
[PID: 232][C:\Program Files\Rising\Rav\RavTimer.exe]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 36>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Rising Corp.><17, 0, 0, 7>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Rising Corp.><17, 0, 1, 71>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><17, 0, 0, 3>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
gototop
 

[PID: 260][C:\Program Files\Rising\Rav\RavMon.exe]  <Beijing Rising Technology Co., Ltd.><17, 0, 1, 39>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 40>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Rising Corp.><17, 0, 0, 7>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Rising Corp.><17, 0, 1, 71>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><17, 0, 0, 3>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Rising><17, 0, 0, 2>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 17>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
[PID: 292][E:\个人\桌面日历\桌面日历\TaskXP.exe]  <N/A><N/A>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
[PID: 444][C:\WINDOWS\system32\hkcmd.exe]  <Intel Corporation><3.0.0.4396>
    [C:\WINDOWS\system32\hccutils.DLL]  <Intel Corporation><3.0.0.4396>
    [C:\WINDOWS\system32\igfxsrvc.dll]  <Intel Corporation><3.0.0.4396>
    [C:\WINDOWS\system32\igfxres.dll]  <Intel Corporation><3.0.0.4396>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
[PID: 460][C:\WINDOWS\system32\igfxpers.exe]  <Intel Corporation><3.0.0.4396>
    [C:\WINDOWS\system32\igfxsrvc.dll]  <Intel Corporation><3.0.0.4396>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
[PID: 512][C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE]  <Microsoft Corporation><7.00.9466>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
[PID: 564][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.1622>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
[PID: 584][C:\WINDOWS\VM_STI.EXE]  <BIGDOG><4, 2, 610, 4>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\VM31bPrp.Ax]  <Vimicro><1.00.01.00>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
[PID: 644][C:\Program Files\Rising\Rav\RavService.exe]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 73>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><17, 0, 0, 3>
    [C:\WINDOWS\system32\msplus1.dll]  <><1, 0, 0, 1>
    [C:\WINDOWS\system32\msplus.dll]  <><1, 0, 0, 1>
[PID: 1076][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
[PID: 1200][C:\WINDOWS\system32\conime.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
[PID: 1248][C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 6>
[PID: 1332][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1452][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\icwip.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\system32\msplus1.dll]  <><1, 0, 0, 1>
    [C:\Program Files\MySec\secbaraai.dll]  <SemeanKitty's Office><1.00.05>
    [C:\WINDOWS\DOWNLO~1\yjzgveof.dll]  <xlcbosoft><1, 0, 0, 1>
    [C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll]  <CNNIC><1, 0, 0, 11>
    [C:\Program Files\MySec\secmouseaai.dll]  <SemeanKitty's Office><1.00.04>
    [C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll]  <CNNIC><1, 1, 0, 0>
    [C:\WINDOWS\system32\msplus.dll]  <><1, 0, 0, 1>
[PID: 2616][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\msplus1.dll]  <><1, 0, 0, 1>
[PID: 2332][D:\安装的非系统文件\遨游浏览器\Maxthon\Maxthon.exe]  <Maxthon International Ltd.><1, 5, 2, 21>
    [D:\安装的非系统文件\遨游浏览器\Maxthon\maxzlib.dll]  < ><1, 0, 0, 2>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\system32\msplus.dll]  <><1, 0, 0, 1>
    [D:\安装的非系统文件\遨游浏览器\Maxthon\Services\RealTime\real_time.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <><17, 0, 0, 8>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx]  <Macromedia, Inc.><8,0,24,0>
    [C:\WINDOWS\system32\icwipKey.DLL]  <N/A><N/A>
    [C:\WINDOWS\system32\rmoc3260.dll]  <RealNetworks><6.0.8.1839>
    [C:\WINDOWS\system32\PNCRT.dll]  <Real Networks, Inc><6.0.0.0>
    [C:\Program Files\Real\RealOne Player\rpplugins\embd3260.dll]  <RealNetworks, Inc.><6.0.11.847>
    [C:\Program Files\Common Files\Real\Common\pngu3267.dll]  <RealNetworks, Inc.><6.7.0.900>
    [C:\Program Files\Common Files\Real\Common\pnrs3260.dll]  <RealNetworks, Inc.><6.0.9.2068>
    [C:\Program Files\Real\RealOne Player\rpplugins\rpcl3260.dll]  <RealNetworks, Inc.><6.0.9.1576>
    [C:\Program Files\Real\RealOne Player\rpplugins\rput3260.dll]  <RealNetworks, Inc.><6.0.9.1544>
    [C:\Program Files\Common Files\Real\Common\pnen3260.dll]  <RealNetworks, Inc.><6.0.9.2006>
    [C:\Program Files\Common Files\Real\Plugins\zipf3260.dll]  <RealNetworks><6.0.7.2536>
    [C:\Program Files\Common Files\Real\Plugins\vsrl3260.dll]  <RealNetworks, Inc.><6.0.7.3265>
    [C:\Program Files\Common Files\Real\Plugins\pnxr3260.dll]  <RealNetworks, Inc.><6.0.7.4552>
[PID: 3876][C:\Program Files\Rising\Rav\RsAgent.exe]  <Beijing Rising Technology Co., Ltd.><17, 0, 0, 27>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><17, 0, 0, 3>
[PID: 9164][C:\WINDOWS\msagent\AgentSvr.exe]  <Microsoft Corporation><2.00.0.3422>
[PID: 9272][D:\安装源文件\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\WINDOWS\system32\cdnns.dll]  <CNNIC><2, 0, 0, 0>
    [C:\WINDOWS\system32\msplus.dll]  <><1, 0, 0, 1>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

各位大哥  上面就是日志吧  帮我看看能否治疗阿  55555555
gototop
 

[Network safety / The network safety service]
<C:\WINDOWS\system32\icwip.exe><N/A>
鸽子..安全模式...打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索The network safety service 删除...
删除
C:\WINDOWS\system32\icwip.exe
C:\WINDOWS\system32\icwipKey.DLL
C:\WINDOWS\system32\icwip.DLL



[Windows Media Player Network Sharing Service / WMPNetworkSvc]
<C:\Program Files\Windows Media Player\WMPNetwk.exe><N/A>
这也不是什么好东西...
打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索WMPNetworkSvc  删除...

删除
C:\Program Files\Windows Media Player\WMPNetwk.exe



http://www.crsky.com/soft/2924.html
下载超级兔子..用超级兔子清理王卸载流氓软件...
安全模式下卸...
gototop
 

太谢谢您了  感动流涕  不行的话再请教
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT