我们都知道感染了"灰鸽子"病毒的明显特征是在系统根目录下生成类似smsss.exe smsss.dll smsss_hook.dll这三个文件!但是最近又有新变化!我的机子就感染了!情况如下:
2005-07-13 11:14:12, IEXPLORE.EXE>>C:\WINDOWS\WIMLOGON.DLL ->Backdoor.GPigeon.5.a(灰鸽子后门)
2005-07-13 11:14:12, alg.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:14:10, taskmgr.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:14:07, wmiprvse.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:14:05, wuauclt.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:14:02, ctfmon.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:14:00, RAVTIMER.EXE>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:57, realsched.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:54, SOUNDMAN.EXE>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:52, IEXPLORE.EXE>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:48, IEXPLORE.EXE>>C:\WINDOWS\WIMLOGON.DLL ->Backdoor.GPigeon.5.a(灰鸽子后门)
2005-07-13 11:13:47, nvsvc32.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:44, inetinfo.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:39, Explorer.EXE>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:34, spoolsv.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:30, rfwsrv.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:29, svchost.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:26, svchost.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:24, svchost.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:15, svchost.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:12, svchost.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:09, lsass.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:13:05, services.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
2005-07-13 11:12:58, csrss.exe>>C:\WINDOWS\WIMLOGON vac.dll ->Backdoor.Gpigeon.bc
明显不同的是这次生成的是wimlogon vac.dll文件!我猜想应该还有另外两个病毒文件,文件名应是wimlogon.exe和wimlogon.dll, 果然还是让我在隐藏文件中找到它们。
然而如何查杀呢?最好的方法是手动删除
第一步:在安全模式下 删除windows目录下的wimlogon.exe/wimlogon.dll/wimlogon vac.dll三个文件(注意有两个文件时隐藏的,2000或NT系统是winnt目录)。
第二步:在安全模式下 运行regedit 查找所有有关wimlogon的注册表项目逐个删除。