瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 请大家帮帮忙!!!Backdoor.Gpigeon.2006.ro瑞星无法彻底清除

12   2  /  2  页   跳转

请大家帮帮忙!!!Backdoor.Gpigeon.2006.ro瑞星无法彻底清除

[PID: 3908][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 3452][C:\Program Files\Rising\Rav\RsAgent.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
[PID: 3472][C:\WINDOWS\msagent\AgentSvr.exe]  <Microsoft Corporation><2.00.0.3422>
[PID: 380][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><7.0.5.2005092300>
    [d:\QQ\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll]  <Sun Microsystems, Inc.><5.0.60.5>
    [d:\thunder\ComDlls\XunLeiBHO_002.dll]  <Thunder Networking Technologies,LTD><5, 0, 0, 2>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [d:\thunder\ComDlls\ThunderAgent_002.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 8>
[PID: 2804][d:\thunder\Program\Thunder5.exe]  <Thunder Networking Technologies,LTD><5.2.0.207>
    [d:\thunder\Program\UpdateDownload.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 8>
    [d:\thunder\Program\download_interface.dll]  <Thunder Networking Technologies,LTD><1, 0, 3, 70>
    [d:\thunder\Program\log4cplus.dll]  <><1, 0, 2, 1>
    [d:\thunder\Program\stlport_vc646.dll]  <STLport Consulting, Inc.><4.6.2003.1031>
    [d:\thunder\Program\asyn_dns.dll]  <N/A><N/A>
    [d:\thunder\Program\msgmanage.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 15>
    [d:\thunder\Program\historyinfo_manage.dll]  <Thunder Networking Technologies,LTD><5, 2, 0, 148>
    [d:\thunder\Program\RegisterDll.dll]  <Thunder Networking Technologies,LTD><1, 2, 0, 7>
    [d:\thunder\Program\FloatBar.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 2>
    [d:\thunder\Components\InMedia\iEmbedShell.dll]  < ><1, 0, 0, 5>
    [d:\thunder\Components\InMedia\iEmbed.dll]  < ><2, 1, 0, 29>
    [d:\thunder\Components\P4PClient\P4PClient.dll]  <Thunder Networking Technologies,LTD><1, 0, 1, 6>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [d:\thunder\Program\iTargetAd.dll]  <Thunder Networking Technologies,LTD><1, 0, 0, 60>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx]  <Macromedia, Inc.><8,0,22,0>
[PID: 1072][C:\Documents and Settings\sony\桌面\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

贴完了。。。。。。
gototop
 

期待回复。谢谢
gototop
 

O23 - Service: Fixed path browsing not (Fixed duplicate group names ) - Unknown owner - C:\WINDOWS\LeapFTP.exe
安全模式...打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索Fixed duplicate group names  删除..
删除
C:\WINDOWS\LeapFTP.exe

删完看看还报不..
gototop
 

看不出问题
你把瑞星所报的目录粘上来
gototop
 

引用:
【mopery的贴子】O23 - Service: Fixed path browsing not (Fixed duplicate group names ) - Unknown owner - C:\WINDOWS\LeapFTP.exe
安全模式...打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索Fixed duplicate group names  删除..
删除
C:\WINDOWS\LeapFTP.exe

删完看看还报不..
………………


我用了这位朋友的方法,重启后病毒警告消失了。。。
问题应该解决了八?
谢谢了
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT