瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我中的是“Backdoor.Gpigeon.pr”灰鸽子病毒!请教了!

1   1  /  1  页   跳转

我中的是“Backdoor.Gpigeon.pr”灰鸽子病毒!请教了!

我中的是“Backdoor.Gpigeon.pr”灰鸽子病毒!请教了!

查日志,023项如下:

O23 - Service: DuDu Accelerator (DuDuProsvc) - Unknown owner - D:\Program Files\DuDu\DddClient\DuDuProsvc.exe (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - D:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - D:\PROGRA~1\EFFICI~1\ENTERN~1.5\app\pppoeservice.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - D:\Program Files\Rising\Rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: Remote_Procedure_Call (svchost) - Unknown owner - %windir%\system32\svchost.cmd (file missing)
O23 - Service: SVCHOST.EXE - Unknown owner - D:\WINDOWS\SVCHOST.EXE
O23 - Service: Performance Accounts (WksPatch) - Unknown owner - D:\WINDOWS\System32\drivers\svchost.exe (file missing)

我猜下列几项是“灰鸽子病毒”,对吗?可以删吗?

O23 - Service: DuDu Accelerator (DuDuProsvc) - Unknown owner - D:\Program Files\DuDu\DddClient\DuDuProsvc.exe (file missing)
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - D:\PROGRA~1\EFFICI~1\ENTERN~1.5\app\pppoeservice.exe
O23 - Service: Remote_Procedure_Call (svchost) - Unknown owner - %windir%\system32\svchost.cmd (file missing)
O23 - Service: SVCHOST.EXE - Unknown owner - D:\WINDOWS\SVCHOST.EXE
O23 - Service: Performance Accounts (WksPatch) - Unknown owner - D:\WINDOWS\System32\drivers\svchost.exe (file missing)
最后编辑2005-09-25 23:26:52
分享到:
gototop
 

O23 - Service: DuDu Accelerator (DuDuProsvc) - Unknown owner - D:\Program Files\DuDu\DddClient\DuDuProsvc.exe (file missing)
O23 - Service: Remote_Procedure_Call (svchost) - Unknown owner - %windir%\system32\svchost.cmd (file missing)

O23 - Service: Performance Accounts (WksPatch) - Unknown owner - D:\WINDOWS\System32\drivers\svchost.exe (file missing)上面这几项修复一下就可以了!
O23 - Service: SVCHOST.EXE - Unknown owner - D:\WINDOWS\SVCHOST.EXE这个是鸽子。要用杀鸽子的方法清除。
gototop
 

谢过豪侠!
请问:怎么修复?怎么清除?
gototop
 

在注册表中删除后,重启,再查日志,023项如下:

O23 - Service: DuDu Accelerator (DuDuProsvc) - Unknown owner - D:\Program Files\DuDu\DddClient\DuDuProsvc.exe (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - D:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - D:\PROGRA~1\EFFICI~1\ENTERN~1.5\app\pppoeservice.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - D:\Program Files\Rising\Rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: Performance Accounts (WksPatch) - Unknown owner - D:\WINDOWS\System32\drivers\svchost.exe (file missing)

用瑞星查杀,似乎没有灰鸽子了,请专家诊断!

gototop
 

没有版主在吗?请教了!
gototop
 

引用:
【独孤豪侠的贴子】O23 - Service: DuDu Accelerator (DuDuProsvc) - Unknown owner - D:\Program Files\DuDu\DddClient\DuDuProsvc.exe (file missing)
O23 - Service: Remote_Procedure_Call (svchost) - Unknown owner - %windir%\system32\svchost.cmd (file missing)

O23 - Service: Performance Accounts (WksPatch) - Unknown owner - D:\WINDOWS\System32\drivers\svchost.exe (file missing)上面这几项修复一下就可以了!
O23 - Service: SVCHOST.EXE - Unknown owner - D:\WINDOWS\SVCHOST.EXE这个是鸽子。要用杀鸽子的方法清除。
...........................
按上面的操作,再显示所有文件,查找可能存在的病毒文件SVCHOST.EXE SVCHOST.DLL SVCHOSTKey.dll SVCHOST_hook.dll删除就行了
gototop
 

O23 - Service: DuDu Accelerator (DuDuProsvc) - Unknown owner - D:\Program Files\DuDu\DddClient\DuDuProsvc.exe (file missing)
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - D:\PROGRA~1\EFFICI~1\ENTERN~1.5\app\pppoeservice.exe
O23 - Service: Remote_Procedure_Call (svchost) - Unknown owner - %windir%\system32\svchost.cmd (file missing)
O23 - Service: SVCHOST.EXE - Unknown owner - D:\WINDOWS\SVCHOST.EXE
O23 - Service: Performance Accounts (WksPatch) - Unknown owner - D:\WINDOWS\System32\drivers\svchost.exe (file missing)

第一个是某软件生成的,第2个是你的Enternet300生成的,下面三个都可疑,不是鸽子也是其它东西。。
gototop
 

O23 - Service: SVCHOST.EXE - Unknown owner - D:\WINDOWS\SVCHOST.EXE
这个是鸽子!~~~~
gototop
 

晕了头.你门说的这些东西我看的一头雾水.
有哪为小心的大哥能教教小妹吗?
gototop
 

关于鸽子的病毒手动删除方法的帖子已经很多了,自己找找吧
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT