Backdoor.Gpigeon.ftq是什么病毒啊?开机扫描后杀掉了。。但重启电脑后的开机扫描又会出来,杀毒又找不到它了,我在安全模式下杀也没有。
顺便帮我看看日志吧。。谢谢~
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 13:15:46, 日期 2006-8-9
操作系统: Windows 2000 SP4 (WinNT 5.00.2195)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
e:\Program Files\rising\Rav\CCenter.exe
e:\Program Files\rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
e:\Program Files\rising\Rav\RavStub.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
e:\Program Files\Tencent\RTXServer\httpsvr\HttpSvr.exe
e:\Program Files\Tencent\RTXServer\bin\RTXSvrMain.exe
C:\WINNT\system32\MSTask.exe
e:\Program Files\Tencent\RTXServer\bin\LicenseServer.exe
e:\Program Files\Tencent\RTXServer\bin\DBServer.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
e:\Program Files\Tencent\RTXServer\bin\GroupServer.exe
e:\Program Files\Tencent\RTXServer\bin\ConnServer.exe
e:\Program Files\Tencent\RTXServer\bin\AppServer.exe
e:\Program Files\Tencent\RTXServer\bin\FileServer.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
e:\Program Files\Tencent\RTXServer\bin\SessionServer.exe
e:\Program Files\Tencent\RTXServer\bin\InfoServer.exe
C:\WINNT\wincup\wincup.exe
e:\Program Files\Tencent\RTXServer\bin\AppManager.exe
C:\WINNT\system32\svchost.exe
e:\Program Files\Tencent\RTXServer\bin\gateway.exe
e:\Program Files\Tencent\RTXServer\bin\GW.exe
e:\Program Files\Tencent\RTXServer\bin\AppDllHost.exe
E:\Program Files\Tencent\RTXServer\httpsvr\HttpSvr.exe
e:\Program Files\Tencent\RTXServer\bin\AppDllHost.exe
e:\Program Files\Tencent\RTXServer\bin\SDKServer.exe
e:\Program Files\Tencent\RTXServer\bin\Upgradesvr.exe
e:\Program Files\Tencent\RTXServer\bin\AppDllHost.exe
C:\WINNT\Explorer.EXE
E:\Program Files\rising\Rav\RavMon.exe
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
E:\Program Files\rising\Rav\RavTask.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINNT\system32\internat.exe
E:\电影\迅雷\TDUpdate.exe
D:\Program Files\ADSL拨号王\HNMainUI.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\Tencent\QQ\QQ.exe
E:\Downloads\QQ\TIMPlatform.exe
F:\日志扫描\HijackThis1991汉化版\HijackThis1991zww.exe
R3 - URLSearchHook: Tencent SearchHook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
O2 - BHO: 搜搜地址栏搜索 - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: stdup - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINNT\SYSTEM32\stdup.dll
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - 启动项HKLM\\Run: [RavTimer] e:\Program Files\rising\Rav\RavTimer.exe
O4 - 启动项HKLM\\Run: [RavMon] e:\Program Files\rising\Rav\RavMon.exe -system
O4 - 启动项HKLM\\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [RavTask] "e:\Program Files\rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [helper.dll] C:\WINNT\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [NvCplDaemon] rem RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [nwiz] rem nwiz.exe /install
O4 - 启动项HKLM\\Run: [NvMediaCenter] rem RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - 启动项HKLM\\Run: [HP Software Update] rem "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - 启动项HKLM\\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - 启动项HKLM\\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - 启动项HKLM\\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - 启动项HKLM\\Run: [SKYNET Personal FireWall] E:\PROGRA~1\SkyNet\FireWall\pfw.exe
O4 - 启动项HKLM\\Run: [CnsMin] Rundll32.exe C:\WINNT\DOWNLO~1\CnsMin.dll,Rundll32
O4 - 启动项HKLM\\Run: [assistse] "C:\PROGRA~1\3721\assistse.exe"
O4 - 启动项HKLM\\Run: [TkBellExe] rem "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKCU\\Run: [Internat.exe] internat.exe
O4 - “启动”文件夹: 迅雷4.lnk = ?
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - E:\电影\迅雷\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - E:\电影\迅雷\getAllurl.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - E:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - E:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - E:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - E:\Program Files\Tencent\QQ\SendMMS.htm
O11 - Options group: [TBH] 搜搜地址栏搜索
O17 - HKLM\System\CCS\Services\Tcpip\..\{64424EE5-679F-491E-85DA-12D49E9F8A7F}: NameServer = 202.96.128.166 202.96.134.133
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINNT\G_Server1.23.exe
O23 - NT 服务: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - e:\Program Files\rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - e:\Program Files\rising\Rav\Ravmond.exe
O23 - NT 服务: RTX_HTTPServer - Apache Software Foundation - e:\Program Files\Tencent\RTXServer\httpsvr\HttpSvr.exe
O23 - NT 服务: RTX_SvrMain - Unknown owner - e:\Program Files\Tencent\RTXServer\bin\RTXSvrMain.exe
O23 - NT 服务: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - NT 服务: winaua - Unknown owner - C:\DOCUME~1\user\LOCALS~1\Temp\aua\aua.exe (file missing)
O23 - NT 服务: WinWrCup - MsWinCup - C:\WINNT\wincup\wincup.exe
017那项是什么东东啊。。我已经修复了。。。