瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 Backdoor.Gpigeon.2006.jv 死活杀不干净,怎么办

123   1  /  3  页   跳转

Backdoor.Gpigeon.2006.jv 死活杀不干净,怎么办

Backdoor.Gpigeon.2006.jv 死活杀不干净,怎么办

每次开机一查,Backdoor.Gpigeon.2006.jv 就会蹦出来,在windows下的admin1.dll文件上,并且都是提示“重新启动计算机后删除文件”。
为什么总是杀不干净,一开机又出现,怎么解决呢?
最后编辑2006-06-30 17:58:27
分享到:
gototop
 

下载灰鸽子专杀.
gototop
 

在哪儿可以下载?是瑞星的网站上吗
gototop
 

http://forum.ikaka.com/topic.asp?board=28&artid=6979213第4楼下载System Repair Engineer导出全部日志
gototop
 

在瑞星网站上下载了灰鸽子专杀1.0版,可是查不出病毒呀,是不是因为是2005年10月的软件,太旧了。Backdoor.Gpigeon.2006.jv是个新病毒吧?
第3楼介绍的软件我也下了,导出日志再怎么办呀
gototop
 

复制上来..
分三次 复制上来..
gototop
 

2006-06-29,17:12:40

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联


启动项目

注册表

启动文件夹

[Adobe Reader Speed Launch]
(C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk)(N)
[AutoCAD 启动加速器]
(C:\Documents and Settings\All Users\「开始」菜单\程序\启动\AutoCAD 启动加速器.lnk)(N)

gototop
 

服务

[admin1 / admin1]
(C:\WINDOWS\admin1.exe)(N/A)
[Adobe LM Service / Adobe LM Service]
("C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe")(Adobe Systems)
[Autodesk Licensing Service / Autodesk Licensing Service]
("C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe")(Autodesk, Inc.)
[C-DillaCdaC11BA / C-DillaCdaC11BA]
(C:\WINDOWS\System32\drivers\CDAC11BA.EXE)(Macrovision)
[C-DillaSrv / C-DillaSrv]
(C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE)(C-Dilla Ltd)
[Macromedia Licensing Service / Macromedia Licensing Service]
("C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe")(N/A)
[NVIDIA Driver Helper Service / NVSvc]
(C:\WINDOWS\System32\nvsvc32.exe)(NVIDIA Corporation)
[PACSPTISVR / PACSPTISVR]
(C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe)()
[Rising Proxy Service / RfwProxySrv]
(d:\program files\rising\rfw\rfwproxy.exe)(Beijing Rising Technology Co., Ltd.)
[Rising Personal Firewall Service / RfwService]
(d:\program files\rising\rfw\rfwsrv.exe)(Beijing Rising Technology Co., Ltd.)
[Rising Process Communication Center / RsCCenter]
(D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE)(Beijing Rising Technology Co., Ltd.)
[RsRavMon Service / RsRavMon]
("D:\Program Files\Rising\Rav\Ravmond.exe")(Beijing Rising Technology Co., Ltd.)
[SoundMAX Agent Service / SoundMAX Agent Service (default)]
(C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe)(Analog Devices, Inc.)
[Sony SPTI Service / SPTISRV]
(C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe)(Sony Corporation)
[Ulead Burning Helper / UleadBurningHelper]
(C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe)(Ulead Systems, Inc.)
gototop
 

浏览器加载项

[HelperObject Class]
{00C6482D-C502-44C8-8409-FCE54AD9C208} (C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll, TechSmith Corporation)
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, N/A)
[Yahoo!Photo]
{33BBE430-0E42-4f12-B075-8D21ACB10DCB} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll, Yahoo! China)
[AntiFish Class]
{38928D50-8A48-44C2-945F-D2F23F771410} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll, Yahoo.)
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!)
[QQBrowserHelperObject Class]
{54EBD53A-9BC1-480B-966A-843A333CA162} (C:\Program Files\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司)
[DragSearch BHO]
{62EED7C6-9F02-42f9-B634-98E2899E147B} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, )
[IeCatch2 Class]
{A5366673-E8CA-11D3-9CD9-0090271D075B} (C:\PROGRA~1\FLASHGET\jccatch.dll, Amaze Soft)
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} (c:\program files\google\googletoolbar2.dll, Google Inc.)
[CnsHook Class]
{D157330A-9EF3-49F8-9A67-4141AC41ADD4} (C:\WINDOWS\downlo~1\CnsHook.dll, 北京三七二一科技有限公司)
[新浪UC]
{2253922F-1B26-4C74-8B57-E3AEE748DBB8} (C:\Program Files\sina\UC\UC.exe, 北京新浪信息技术有限公司)
[Yahoo 1G电邮]
{507F9113-CD77-4866-BA92-0E86DA3D0B97} (http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail, N/A)
[寻宝乐趣多]
{59BC54A2-56B3-44a0-93E5-432D58746E26} (http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=taobao, N/A)
[雅虎助手]
{5D73EE86-05F1-49ed-B850-E423120EC338} (http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist, N/A)
[ICQ Pro]
{6224f700-cba3-4071-b251-47cb894244cd} (C:\PROGRA~1\ICQ\ICQ.exe, ICQ Inc.)
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} (, N/A)
[QQ]
{c95fe080-8f5d-11d2-a20b-00aa003c157b} (C:\Program Files\Tencent\qq\QQ.EXE, TENCENT)
[FlashGet]
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} (C:\PROGRA~1\FLASHGET\flashget.exe, Amaze Soft)
[QQIEFloatBarCfgCmd Class]
{DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} (C:\Program Files\Tencent\qq\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司)
[情景聊天]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} (http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/, N/A)
[]
{ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} (http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair, N/A)
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} (C:\Program Files\Messenger\MSMSGS.EXE, Microsoft Corporation)
[]
{FD00D911-7529-4084-9946-A29F1BDF4FE5} (http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean, N/A)
[FlashGet Bar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} (C:\PROGRA~1\FLASHGET\fgiebar.dll, Amaze Soft)
[SnagIt]
{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} (C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll, TechSmith Corporation)
[雅虎助手]
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} (C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll, Yahoo!)
[电台(&R)]
{8E718888-423F-11D2-876E-00A0C9082467} (C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation)
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} (c:\program files\google\googletoolbar2.dll, Google Inc.)
[InstaFred]
{1F831FA1-42FC-11D4-95A6-0080AD30DCE1} (C:\WINDOWS\DOWNLO~1\InstFred.ocx, Autodesk, Inc.)
[CEditCtrl Object]
{488A4255-3236-44B3-8F27-FA1AECAA8844} (C:\WINDOWS\System32\aliedit\AliEdit.dll, www.alipay.com)
[MofileUploadX Control]
{7260569F-1D40-4E7F-B95B-2E68D35668B9} (C:\WINDOWS\DOWNLO~1\MoUpload.ocx, )
[AxInputControl Class]
{73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (C:\WINDOWS\DOWNLO~1\INPUTC~1.DLL, )
[AcDcToday 控件]
{78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (C:\WINDOWS\DOWNLO~1\ACDCTO~1.OCX, Autodesk)
[Update Class]
{9F1C11AA-197B-4942-BA54-47A8489BB47F} (C:\WINDOWS\System32\iuctl.dll, Microsoft Corporation)
[NOXLATE-BANR]
{AE563722-B4F5-11D4-A415-00108302FDFD} (C:\WINDOWS\DOWNLO~1\InstBanr.ocx, Autodesk, Inc.)
[Blueskyvoice Control]
{BA0F088C-72C1-475A-92F8-42391DEF6961} (C:\WINDOWS\DOWNLO~1\BLUESK~1.OCX, 蓝天工作室(http://www.bluesky.cn))
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} (C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.)
[Rising Web Scan Object]
{E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (C:\WINDOWS\Downloaded Program Files\OL2005.dll, Beijing Rising Tech. Co., Ltd.)
[AcPreview 控件]
{F281A59C-7B65-11D3-8617-0010830243BD} (C:\WINDOWS\DOWNLO~1\ACPREV~1.OCX, Autodesk)
[Google 搜索(&G)]
(res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html, N/A)
[上传到QQ网络硬盘]
(C:\Program Files\Tencent\qq\AddToNetDisk.htm, N/A)
[下载页面上的ED2(&K)链接]
(d:\Program Files\eMule\ed2k.html, N/A)
[使用网际快车下载]
(C:\Program Files\FlashGet\jc_link.htm, N/A)
[使用网际快车下载全部链接]
(C:\Program Files\FlashGet\jc_all.htm, N/A)
[反向链接]
(res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html, N/A)
[导出到 Microsoft Office Excel(&X)]
(res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A)
[收藏此页到新浪ViVi]
(http://vivi.sina.com.cn/collect/click.php?agent=ddt, N/A)
[新浪搜索]
(http://cha.sina.com.cn/ddt.html, N/A)
[查看 Exif 信息(&V)]
(res://d:\Program Files\Exif Show\ExShow.dll/EXSHOW.HTML, N/A)
[添加到QQ自定义面板]
(C:\Program Files\Tencent\qq\AddPanel.htm, N/A)
[添加到QQ表情]
(C:\Program Files\Tencent\qq\AddEmotion.htm, N/A)
[添加到雅虎订阅(&Y)]
(res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll/YRSSMENUEXT, N/A)
[用QQ彩信发送该图片]
(C:\Program Files\Tencent\qq\SendMMS.htm, N/A)
[类似网页]
(res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html, N/A)
[缓存的网页快照]
(res://c:\program files\google\GoogleToolbar2.dll/cmcache.html, N/A)
[翻译英文字词(&T)]
(res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html, N/A)
[雅虎搜索]
(res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246, N/A)
gototop
 

正在运行的进程

[PID: 560][\SystemRoot\System32\smss.exe] (Microsoft Corporation)(5.1.2600.1106 (xpsp1.020828-1920))
[PID: 640][\??\C:\WINDOWS\system32\csrss.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 664][\??\C:\WINDOWS\system32\winlogon.exe] (Microsoft Corporation)(5.1.2600.1106 (xpsp1.020828-1920))
[C:\WINDOWS\System32\SYNCOR11.DLL] (SoundMAX)(1.2.2)
[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\WINDOWS\System32\upengine.dll] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[PID: 708][C:\WINDOWS\system32\services.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 720][C:\WINDOWS\system32\lsass.exe] (Microsoft Corporation)(5.1.2600.1106 (xpsp1.020828-1920))
[PID: 900][C:\WINDOWS\system32\svchost.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 1000][C:\WINDOWS\System32\svchost.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[C:\WINDOWS\System32\SYNCOR11.DLL] (SoundMAX)(1.2.2)
[PID: 1188][C:\WINDOWS\System32\svchost.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 1236][C:\WINDOWS\System32\svchost.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 1268][D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 3)
[PID: 1368][D:\Program Files\Rising\Rav\Ravmond.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 1, 26)
[D:\Program Files\Rising\Rav\BWList.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 19)
[D:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
[D:\Program Files\Rising\Rav\CfgDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[D:\Program Files\Rising\Rav\RsLog.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 20)
[D:\Program Files\Rising\Rav\HOOKSYS.dll] (Rising)(18, 1, 0, 9)
[D:\Program Files\Rising\Rav\Scanner.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 30)
[D:\Program Files\Rising\Rav\libload.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
[D:\Program Files\Rising\Rav\VirusLib.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
[D:\Program Files\Rising\Rav\regmon.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 6)
[D:\Program Files\Rising\Rav\HookWeb.dll] (rising)(18, 0, 0, 1)
[D:\Program Files\Rising\Rav\MemMon.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 9)
[D:\Program Files\Rising\Rav\expscan.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[D:\Program Files\Rising\Rav\mPorts.dll] (Beijing Rising Technology Co., Ltd.)(4, 0, 0, 3)
[D:\Program Files\Rising\Rav\MailMon.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 5)
gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT