瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】Backdoor.Gpigeon.shk 谁来救救我呀

123   1  /  3  页   跳转

【求助】Backdoor.Gpigeon.shk 谁来救救我呀

【求助】Backdoor.Gpigeon.shk 谁来救救我呀

这是日志帮我看看我不看不懂怎么杀呀
Logfile of HijackThis v1.99.1
Scan saved at 15:41:33, on 2005-9-12
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\Rundll32.exe
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\PROGRA~1\360so\360Main.exe
C:\WINDOWS\System32\rant.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
D:\2.4\杀灰鸽子\HijackThis.exe

R3 - Default URLSearchHook is missing
O1 - Hosts: 202.103.67.180 auto.search.msn.com
O1 - Hosts: 61.145.118.229 61.145.118.229 #0
O1 - Hosts: 59.34.215.91 www.9i0.com #0
O1 - Hosts: 129.79.78.4 www.indiana.edu #0
O1 - Hosts: 218.108.238.38 music.skyhits.com #0
O1 - Hosts: 222.36.45.109 www.imobile.com.cn #0
O1 - Hosts: 218.85.133.169 www.wiapp.org #0
O1 - Hosts: 61.135.136.107 join.motorola.com.cn #0
O1 - Hosts: 207.46.19.60 www.microsoft.com #0
O1 - Hosts: 211.167.236.40 sdinfo1.chinawater.net.cn #0
O1 - Hosts: 218.106.116.172 qqbq.yule88.com #0
O1 - Hosts: 219.154.96.114 dadui.net #0
O1 - Hosts: 61.146.93.164 www.cn-yock.net #0
O1 - Hosts: 218.30.110.209 ftengin.51.net #0
O1 - Hosts: 210.51.170.68 pk.3000ok.net #0
O1 - Hosts: 203.86.2.98 www.wnwb.com #0
O1 - Hosts: 216.168.224.63 www.qq868.com #0
O1 - Hosts: 219.139.240.117 www.zgdown.com #0
O1 - Hosts: 61.155.107.13 www.blogcn.com #0
O1 - Hosts: 211.167.236.39 www.cws.net.cn #0
O1 - Hosts: 218.249.40.231 www.waterinfo.com.cn #0
O1 - Hosts: 61.129.81.199 www.hack99.com #0
O1 - Hosts: 219.153.14.163 www.99music.net #0
O1 - Hosts: 61.243.190.37 www.yuedui.com #0
O1 - Hosts: 218.83.152.251 www.lihoy.com #0
O1 - Hosts: 210.51.23.33 www.92game.com #0
O1 - Hosts: 61.129.70.201 www.wg8.com.ru #0
O1 - Hosts: 219.153.20.72 www.babeijiu.com #0
O1 - Hosts: 210.51.8.38 www.phoenixtv.com.cn #0
O1 - Hosts: 219.153.5.222 www.17126.com #0
O1 - Hosts: 61.135.150.75 yule.sohu.com #0
O1 - Hosts: 210.51.170.68 book.haodx.com #0
O1 - Hosts: 218.58.59.84 lib.sdkd.net.cn #0
O1 - Hosts: 220.181.29.60 fish-say.go.nease.net #0
O1 - Hosts: 61.233.159.130 www.sdjs.gov.cn #0
O1 - Hosts: 219.238.238.115 www.zcom.com #0
O1 - Hosts: 219.146.174.156 bbs.exue.com.cn #0
O1 - Hosts: 61.153.183.44 www.5151.net #0
O1 - Hosts: 219.238.161.99 www.jsgg.com.cn #0
O1 - Hosts: 211.167.236.39 jhe.ches.org.cn #0
O1 - Hosts: 221.4.151.148 www.fswater.gov.cn #0
O1 - Hosts: 202.108.35.184 lw123.vip.sina.com #0
O1 - Hosts: 202.103.33.62 www.cjw.com.cn #0
O1 - Hosts: 211.144.20.205 www.shuiziyuan.mwr.gov.cn #0
O1 - Hosts: 219.153.19.194 www.72z.net #0
O1 - Hosts: 219.238.233.209 update.rising.com.cn #0
O1 - Hosts: 218.16.125.33 www.vvktv.com #0
O1 - Hosts: 61.156.38.1 lc-www.sd.cninfo.net #0
O1 - Hosts: 59.45.148.29 qianer.dm001.com #0
O1 - Hosts: 219.239.95.131 www.263.net #0
O1 - Hosts: 202.108.9.77 mail.163.com #0
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: IeControler Class - {9AFD91F9-6B03-4D22-A1E1-67D224CB7AB1} - C:\Program Files\Superhunter\NetSpeeder\IEMate.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\Program Files\3721\Assist\asbar.dll
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - Toolbar: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\PROGRA~1\YiSou\yisou.dll
O3 - Toolbar: 完美网译通 - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - C:\WINDOWS\WORLD2\TOOLBAR\hmtoolbar.dll
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\BitComet\BitCometBar\BitCometBar0.1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [360Main.exe] C:\PROGRA~1\360so\360Main.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [rant] rant.exe
O4 - HKLM\..\Run: [NetSpeeder] "C:\Program Files\Superhunter\NetSpeeder\NetSpeeder.exe" hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\RunServices: [rant] rant.exe
O4 - HKCU\..\Run: [rant] rant.exe
O8 - Extra context menu item: !搜一搜 - res://C:\WINDOWS\downlo~1\CnsMinEx.dll/1003
O8 - Extra context menu item: &使用下载加速专家下载 - C:\Program Files\3721\Dlaccel\geturl.htm
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - Extra context menu item: Google 搜索(&G) - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 反向链接 - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 百度-搜索MP3 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度-搜索图片 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度-搜索新闻 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度-搜索歌词 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度-搜索网页 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度-搜索贴吧 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.HTM
O8 - Extra context menu item: 百度-词典搜索 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.HTM
O8 - Extra context menu item: 类似网页 - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: 翻译英文字词(&T) - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=59 (file missing)
O9 - Extra 'Tools' menuitem: 易趣网上购物(&E) - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=59 (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O11 - Options group: [!ANetSpeeder]  NetSpeeder
O11 - Options group: [!CNS]  上网助手-地址栏搜索
O17 - HKLM\System\CCS\Services\Tcpip\..\{A0EB9E38-7FBD-4298-A7D4-7CC1F55C7887}: NameServer = 202.102.152.3 202.102.154.3
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\G_Server.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe

最后编辑2005-09-12 17:22:53
分享到:
gototop
 

引用:
【睡在屋顶的鱼的贴子】这是日志帮我看看我不看不懂怎么杀呀
Logfile of HijackThis v1.99.1
Scan saved at 15:41:33, on 2005-9-12
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\Rundll32.exe
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\PROGRA~1\360so\360Main.exe
C:\WINDOWS\System32\rant.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
D:\2.4\杀灰鸽子\HijackThis.exe

R3 - Default URLSearchHook is missing
O1 - Hosts: 202.103.67.180 auto.search.msn.com
O1 - Hosts: 61.145.118.229 61.145.118.229 #0
O1 - Hosts: 59.34.215.91 www.9i0.com #0
O1 - Hosts: 129.79.78.4 www.indiana.edu #0
O1 - Hosts: 218.108.238.38 music.skyhits.com #0
O1 - Hosts: 222.36.45.109 www.imobile.com.cn #0
O1 - Hosts: 218.85.133.169 www.wiapp.org #0
O1 - Hosts: 61.135.136.107 join.motorola.com.cn #0
O1 - Hosts: 207.46.19.60 www.microsoft.com #0
O1 - Hosts: 211.167.236.40 sdinfo1.chinawater.net.cn #0
O1 - Hosts: 218.106.116.172 qqbq.yule88.com #0
O1 - Hosts: 219.154.96.114 dadui.net #0
O1 - Hosts: 61.146.93.164 www.cn-yock.net #0
O1 - Hosts: 218.30.110.209 ftengin.51.net #0
O1 - Hosts: 210.51.170.68 pk.3000ok.net #0
O1 - Hosts: 203.86.2.98 www.wnwb.com #0
O1 - Hosts: 216.168.224.63 www.qq868.com #0
O1 - Hosts: 219.139.240.117 www.zgdown.com #0
O1 - Hosts: 61.155.107.13 www.blogcn.com #0
O1 - Hosts: 211.167.236.39 www.cws.net.cn #0
O1 - Hosts: 218.249.40.231 www.waterinfo.com.cn #0
O1 - Hosts: 61.129.81.199 www.hack99.com #0
O1 - Hosts: 219.153.14.163 www.99music.net #0
O1 - Hosts: 61.243.190.37 www.yuedui.com #0
O1 - Hosts: 218.83.152.251 www.lihoy.com #0
O1 - Hosts: 210.51.23.33 www.92game.com #0
O1 - Hosts: 61.129.70.201 www.wg8.com.ru #0
O1 - Hosts: 219.153.20.72 www.babeijiu.com #0
O1 - Hosts: 210.51.8.38 www.phoenixtv.com.cn #0
O1 - Hosts: 219.153.5.222 www.17126.com #0
O1 - Hosts: 61.135.150.75 yule.sohu.com #0
O1 - Hosts: 210.51.170.68 book.haodx.com #0
O1 - Hosts: 218.58.59.84 lib.sdkd.net.cn #0
O1 - Hosts: 220.181.29.60 fish-say.go.nease.net #0
O1 - Hosts: 61.233.159.130 www.sdjs.gov.cn #0
O1 - Hosts: 219.238.238.115 www.zcom.com #0
O1 - Hosts: 219.146.174.156 bbs.exue.com.cn #0
O1 - Hosts: 61.153.183.44 www.5151.net #0
O1 - Hosts: 219.238.161.99 www.jsgg.com.cn #0
O1 - Hosts: 211.167.236.39 jhe.ches.org.cn #0
O1 - Hosts: 221.4.151.148 www.fswater.gov.cn #0
O1 - Hosts: 202.108.35.184 lw123.vip.sina.com #0
O1 - Hosts: 202.103.33.62 www.cjw.com.cn #0
O1 - Hosts: 211.144.20.205 www.shuiziyuan.mwr.gov.cn #0
O1 - Hosts: 219.153.19.194 www.72z.net #0
O1 - Hosts: 219.238.233.209 update.rising.com.cn #0
O1 - Hosts: 218.16.125.33 www.vvktv.com #0
O1 - Hosts: 61.156.38.1 lc-www.sd.cninfo.net #0
O1 - Hosts: 59.45.148.29 qianer.dm001.com #0
O1 - Hosts: 219.239.95.131 www.263.net #0
O1 - Hosts: 202.108.9.77 mail.163.com #0
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: IeControler Class - {9AFD91F9-6B03-4D22-A1E1-67D224CB7AB1} - C:\Program Files\Superhunter\NetSpeeder\IEMate.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\Program Files\3721\Assist\asbar.dll
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - Toolbar: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\PROGRA~1\YiSou\yisou.dll
O3 - Toolbar: 完美网译通 - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - C:\WINDOWS\WORLD2\TOOLBAR\hmtoolbar.dll
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\BitComet\BitCometBar\BitCometBar0.1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [360Main.exe] C:\PROGRA~1\360so\360Main.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [rant] rant.exe
O4 - HKLM\..\Run: [NetSpeeder] "C:\Program Files\Superhunter\NetSpeeder\NetSpeeder.exe" hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\RunServices: [rant] rant.exe
O4 - HKCU\..\Run: [rant] rant.exe
O8 - Extra context menu item: !搜一搜 - res://C:\WINDOWS\downlo~1\CnsMinEx.dll/1003
O8 - Extra context menu item: &使用下载加速专家下载 - C:\Program Files\3721\Dlaccel\geturl.htm
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - Extra context menu item: Google 搜索(&G) - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 反向链接 - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 百度-搜索MP3 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度-搜索图片 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度-搜索新闻 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度-搜索歌词 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度-搜索网页 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度-搜索贴吧 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.HTM
O8 - Extra context menu item: 百度-词典搜索 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.HTM
O8 - Extra context menu item: 类似网页 - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: 翻译英文字词(&T) - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra ''Tools'' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=59 (file missing)
O9 - Extra ''Tools'' menuitem: 易趣网上购物(&E) - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=59 (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra ''Tools'' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra ''Tools'' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O11 - Options group: [!ANetSpeeder]  NetSpeeder
O11 - Options group: [!CNS]  上网助手-地址栏搜索
O17 - HKLM\System\CCS\Services\Tcpip\..\{A0EB9E38-7FBD-4298-A7D4-7CC1F55C7887}: NameServer = 202.102.152.3 202.102.154.3
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\G_Server.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe


...........................

请修复:
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\G_Server.exe
鸽子
gototop
 

【回复“子阳”的帖子】
怎么修呀我不会请大哥耐心教教我说仔细点
gototop
 


http://forum.ikaka.com/topic.asp?board=28&artid=6202404
gototop
 

噢明白了谢谢大哥用刚才扫描日志的工具修复对吧
gototop
 

晕,这么简单就好了~~~~
gototop
 

还不一定呢我得从起机器再杀一次再知道有没有
gototop
 

呵呵~~~~~~~~~那就祝你好运了!
gototop
 

还有,建议修复一下所有01项。太多了。
gototop
 

老大们我快晕死了怎么重起机器后还有Backdoor.Gpigeon.shk 大量灰鸽子呀
请看现在的日志
Logfile of HijackThis v1.99.1
Scan saved at 16:01:03, on 2005-9-12
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\Rundll32.exe
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\PROGRA~1\360so\360Main.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\WINDOWS\System32\rant.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\RISING\RAV\Rav.exe
C:\PROGRA~1\RISING\RAV\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
D:\2.4\杀灰鸽子\HijackThis.exe

R3 - Default URLSearchHook is missing
O1 - Hosts: 202.103.67.180 auto.search.msn.com
O1 - Hosts: 61.145.118.229 61.145.118.229 #0
O1 - Hosts: 59.34.215.91 www.9i0.com #0
O1 - Hosts: 129.79.78.4 www.indiana.edu #0
O1 - Hosts: 218.108.238.38 music.skyhits.com #0
O1 - Hosts: 222.36.45.109 www.imobile.com.cn #0
O1 - Hosts: 218.85.133.169 www.wiapp.org #0
O1 - Hosts: 61.135.136.107 join.motorola.com.cn #0
O1 - Hosts: 207.46.19.60 www.microsoft.com #0
O1 - Hosts: 211.167.236.40 sdinfo1.chinawater.net.cn #0
O1 - Hosts: 218.106.116.172 qqbq.yule88.com #0
O1 - Hosts: 219.154.96.114 dadui.net #0
O1 - Hosts: 61.146.93.164 www.cn-yock.net #0
O1 - Hosts: 218.30.110.209 ftengin.51.net #0
O1 - Hosts: 210.51.170.68 pk.3000ok.net #0
O1 - Hosts: 203.86.2.98 www.wnwb.com #0
O1 - Hosts: 216.168.224.63 www.qq868.com #0
O1 - Hosts: 219.139.240.117 www.zgdown.com #0
O1 - Hosts: 61.155.107.13 www.blogcn.com #0
O1 - Hosts: 211.167.236.39 www.cws.net.cn #0
O1 - Hosts: 218.249.40.231 www.waterinfo.com.cn #0
O1 - Hosts: 61.129.81.199 www.hack99.com #0
O1 - Hosts: 219.153.14.163 www.99music.net #0
O1 - Hosts: 61.243.190.37 www.yuedui.com #0
O1 - Hosts: 218.83.152.251 www.lihoy.com #0
O1 - Hosts: 210.51.23.33 www.92game.com #0
O1 - Hosts: 61.129.70.201 www.wg8.com.ru #0
O1 - Hosts: 219.153.20.72 www.babeijiu.com #0
O1 - Hosts: 210.51.8.38 www.phoenixtv.com.cn #0
O1 - Hosts: 219.153.5.222 www.17126.com #0
O1 - Hosts: 61.135.150.75 yule.sohu.com #0
O1 - Hosts: 210.51.170.68 book.haodx.com #0
O1 - Hosts: 218.58.59.84 lib.sdkd.net.cn #0
O1 - Hosts: 220.181.29.60 fish-say.go.nease.net #0
O1 - Hosts: 61.233.159.130 www.sdjs.gov.cn #0
O1 - Hosts: 219.238.238.115 www.zcom.com #0
O1 - Hosts: 219.146.174.156 bbs.exue.com.cn #0
O1 - Hosts: 61.153.183.44 www.5151.net #0
O1 - Hosts: 219.238.161.99 www.jsgg.com.cn #0
O1 - Hosts: 211.167.236.39 jhe.ches.org.cn #0
O1 - Hosts: 221.4.151.148 www.fswater.gov.cn #0
O1 - Hosts: 202.108.35.184 lw123.vip.sina.com #0
O1 - Hosts: 202.103.33.62 www.cjw.com.cn #0
O1 - Hosts: 211.144.20.205 www.shuiziyuan.mwr.gov.cn #0
O1 - Hosts: 219.153.19.194 www.72z.net #0
O1 - Hosts: 219.238.233.209 update.rising.com.cn #0
O1 - Hosts: 218.16.125.33 www.vvktv.com #0
O1 - Hosts: 61.156.38.1 lc-www.sd.cninfo.net #0
O1 - Hosts: 59.45.148.29 qianer.dm001.com #0
O1 - Hosts: 219.239.95.131 www.263.net #0
O1 - Hosts: 202.108.9.77 mail.163.com #0
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: IeControler Class - {9AFD91F9-6B03-4D22-A1E1-67D224CB7AB1} - C:\Program Files\Superhunter\NetSpeeder\IEMate.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\Program Files\3721\Assist\asbar.dll
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - Toolbar: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\PROGRA~1\YiSou\yisou.dll
O3 - Toolbar: 完美网译通 - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - C:\WINDOWS\WORLD2\TOOLBAR\hmtoolbar.dll
O3 - Toolbar: BitCometBar - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\BitComet\BitCometBar\BitCometBar0.1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [360Main.exe] C:\PROGRA~1\360so\360Main.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [rant] rant.exe
O4 - HKLM\..\Run: [NetSpeeder] "C:\Program Files\Superhunter\NetSpeeder\NetSpeeder.exe" hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\RunServices: [rant] rant.exe
O4 - HKCU\..\Run: [rant] rant.exe
O8 - Extra context menu item: !搜一搜 - res://C:\WINDOWS\downlo~1\CnsMinEx.dll/1003
O8 - Extra context menu item: &使用下载加速专家下载 - C:\Program Files\3721\Dlaccel\geturl.htm
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - Extra context menu item: Google 搜索(&G) - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 反向链接 - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 百度-搜索MP3 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度-搜索图片 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度-搜索新闻 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度-搜索歌词 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度-搜索网页 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度-搜索贴吧 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDUPOST.HTM
O8 - Extra context menu item: 百度-词典搜索 - res://C:\PROGRA~1\baidu\bar\baidubar.dll/BAIDU_DIC.HTM
O8 - Extra context menu item: 类似网页 - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: 翻译英文字词(&T) - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=59 (file missing)
O9 - Extra 'Tools' menuitem: 易趣网上购物(&E) - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=59 (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O11 - Options group: [!ANetSpeeder]  NetSpeeder
O11 - Options group: [!CNS]  上网助手-地址栏搜索
O17 - HKLM\System\CCS\Services\Tcpip\..\{A0EB9E38-7FBD-4298-A7D4-7CC1F55C7887}: NameServer = 202.102.152.3 202.102.154.3
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe

gototop
 
123   1  /  3  页   跳转
页面顶部
Powered by Discuz!NT