瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】帮帮我Backdoor.Gpigeon.2006.aeh好象杀不掉呀 附日志

12   2  /  2  页   跳转

【求助】帮帮我Backdoor.Gpigeon.2006.aeh好象杀不掉呀 附日志

[C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [F:\Program Files\Tencent\QQ\QQGroupMng.dll]  <><1, 0, 0, 1>
    [F:\Program Files\Tencent\QQ\GroupLive.dll]  <N/A><N/A>
    [F:\Program Files\Tencent\QQ\UserDefinedHead.dll]  <><1, 0, 0, 1>
    [F:\Program Files\Tencent\QQ\QQPlugin.dll]  <N/A><N/A>
    [F:\Program Files\Tencent\QQ\QQConfigPlugin.dll]  <><1, 0, 0, 1>
    [F:\Program Files\Tencent\QQ\QQSysMsgMng.dll]  <N/A><N/A>
    [F:\Program Files\Tencent\QQ\QRingMng.dll]  <N/A><N/A>
    [F:\Program Files\Tencent\QQ\PhoneAPI.dll]  <><1, 0, 0, 1>
    [F:\Program Files\Tencent\QQ\DialerAllinOne.dll]  <tencent><1, 4, 0, 0>
    [F:\Program Files\Tencent\QQ\QQAllInOne.dll]  <N/A><N/A>
    [F:\Program Files\Tencent\QQ\SCCore.dll]  <N/A><N/A>
    [F:\Program Files\Tencent\QQ\QQPet.dll]  <><1, 0, 0, 1>
    [F:\Program Files\Tencent\QQ\QQCustomFace.dll]  <N/A><N/A>
    [F:\Program Files\Tencent\QQ\FlashAvatarDll.dll]  <><1, 4, 0, 1>
    [F:\Program Files\Tencent\QQ\ImageOle.dll]  <TODO: <Company name>><1.0.0.1>
    [F:\Program Files\Tencent\QQ\QQSceneMng.dll]  <N/A><N/A>
    [F:\Program Files\Tencent\QQ\LongConnection.dll]  <tencent><5, 0, 200, 160>
    [F:\Program Files\Tencent\QQ\QQAvatar.dll]  <N/A><N/A>
    [F:\Program Files\Tencent\QQ\GroupConnection.dll]  <Tencent><5, 0, 202, 170>
    [F:\Program Files\Tencent\QQ\QQMsgFriendMng.dll]  <N/A><N/A>
    [F:\Program Files\Tencent\QQ\QQZip.dll]  <tencent><0, 3, 2, 4>
    [F:\Program Files\Tencent\QQ\BQQApplication.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
    [F:\Program Files\Tencent\QQ\CommercesMng.dll]  <><1, 0, 0, 1>
    [F:\Program Files\Tencent\QQ\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 2>
    [F:\Program Files\Tencent\QQ\QQUdpGetFileLib.dll]  <tencent><0, 2, 2, 3>
    [F:\Program Files\Tencent\QQ\QQAddr.dll]  <深圳市腾讯计算机系统有限公司><5, 0, 101, 200>
    [F:\Program Files\Tencent\QQ\QQPhoneHelper.dll]  <腾讯科技(深圳)有限公司><2, 0, 6, 60>
[PID: 3680][F:\Program Files\Tencent\QQ\TIMPlatform.exe]  <tencent><0, 3, 1, 8>
    [F:\Program Files\Tencent\QQ\TIMProxy.dll]  <tencent><0, 3, 2, 4>
[PID: 2336][F:\Program Files\Macromedia\Fireworks 8\Fireworks.exe]  <Macromedia Inc.><8.0.0.777>
    [F:\Program Files\Macromedia\Fireworks 8\SN.dll]  <N/A><N/A>
    [F:\Program Files\Macromedia\Fireworks 8\jslib.dll]  <N/A><N/A>
    [F:\Program Files\Macromedia\Fireworks 8\libpng.dll]  <N/A><N/A>
    [F:\Program Files\Macromedia\Fireworks 8\zlib.dll]  <N/A><N/A>
    [F:\Program Files\Macromedia\Fireworks 8\python.dll]  <N/A><N/A>
    [F:\Program Files\Macromedia\Fireworks 8\giflib.dll]  <N/A><N/A>
    [F:\Program Files\Macromedia\Fireworks 8\Simplified Chinese\Resources\Fireworks Resources.dll]  <Macromedia, Inc.><8.0>
    [F:\Program Files\Macromedia\Fireworks 8\MMxptResources.dll]  <Macromedia, Inc.><5, 0, 0, 44>
    [F:\Program Files\Macromedia\Fireworks 8\JSExtensions\MMNotes.dll]  <Macromedia, Inc.><3, 0, 2, 0>
    [F:\Program Files\Macromedia\Fireworks 8\Plug-Ins\EMLaunch.dll]  <Macromedia, Inc.><1.7.143>
    [F:\Program Files\Macromedia\Fireworks 8\Plug-Ins\mix32.x32]  <Macromedia, Inc.><1.16>
    [F:\Program Files\Macromedia\Fireworks 8\Plug-Ins\gsdll32.dll]  <N/A><N/A>
    [F:\Program Files\Macromedia\Fireworks 8\Plug-Ins\TwainAgent.x32]  <Macromedia, Inc.><1.0>
    [D:\Program Files\Storm Codec\QTSystem\QuickTime.qts]  <Apple Computer, Inc.><7.0.2a63>
    [D:\Program Files\Storm Codec\QTSystem\CoreVideo.qtx]  <Apple Computer, Inc.><7.0.2a63>
    [D:\Program Files\Storm Codec\QTSystem\QuickTime3GPP.qtx]  <Apple Computer, Inc.><7.0.2a63>
    [D:\Program Files\Storm Codec\QTSystem\QuickTimeAudioSupport.qtx]  <Apple Computer, Inc.><7.0.2a63>
    [D:\Program Files\Storm Codec\QTSystem\QuickTimeEssentials.qtx]  <Apple Computer, Inc.><7.0.2a63>
    [D:\Program Files\Storm Codec\QTSystem\QuickTimeH264.qtx]  <Apple Computer, Inc.><7.0.2a63>
    [D:\Program Files\Storm Codec\QTSystem\QuickTimeInternetExtras.qtx]  <Apple Computer, Inc.><7.0.2a63>
    [D:\Program Files\Storm Codec\QTSystem\QuickTimeMPEG4.qtx]  <Apple Computer, Inc.><7.0.2a63>
    [D:\Program Files\Storm Codec\QTSystem\QuickTimeStreaming.qtx]  <Apple Computer, Inc.><7.0.2a63>
    [D:\Program Files\Storm Codec\QTSystem\QuickTimeStreamingExtras.qtx]  <Apple Computer, Inc.><7.0.2a63>
    [D:\Program Files\Storm Codec\QTSystem\QuickTimeVR.qtx]  <Apple Computer, Inc><7.0.2a63>
    [C:\WINDOWS\system32\ATMLIB.dll]  <Adobe Systems><5.1 Build 226>
    [F:\Program Files\Macromedia\Fireworks 8\Plug-Ins\authplay.dll]  <N/A><N/A>
[PID: 148][C:\Program Files\MSN Messenger\msnmsgr.exe]  <Microsoft Corporation><8.0.0812.00>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
[PID: 2196][C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE]  <Microsoft Corporation><11.0.5529>
    [C:\Program Files\Rising\Rav\RsPlugIn.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 26>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
[PID: 1984][F:\Program Files\Tencent\TT\TTraveler.exe]  <腾讯公司><3.1.0.256>
    [F:\Program Files\Tencent\TT\Plugins\QQFloatBar\QQFloatBar4TT2.dll]  <腾讯公司><1, 1, 0, 5>
    [F:\Program Files\Tencent\TT\Plugins\TWeather\TWeather.dll]  <><1, 0, 0, 3>
    [F:\Program Files\Tencent\TT\PersonalDesktop.dll]  <深圳市腾讯计算机系统公司QQ工作小组><1, 0, 0, 4>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
[PID: 2588][C:\Program Files\Internet Explorer\iexplore.exe]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
[PID: 2344][F:\Program Files\WinRAR\WinRAR.exe]  <N/A><N/A>
[PID: 620][C:\DOCUME~1\Danni\LOCALS~1\Temp\Rar$EX00.328\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>

==================================
文件关联
.TXT  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  Error. [C:\WINDOWS\hh.exe %1]
.HLP  Error. [C:\WINDOWS\winhlp32.exe %1]
.INI  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.INF  Error. [C:\WINDOWS\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

瑞星只能杀一些小賊病毒.
gototop
 

打开SRE 系统修复 修复文件关联..

[Updata / Updata]
<C:\WINDOWS\system32\Updata_Se.exe><N/A>
灰鸽子..安全模式...打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索 Updata 删除...
删除
C:\WINDOWS\system32\Updata_Se.exe
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT