瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 灰鸽子病毒,请高手指点。(有日志)

1   1  /  1  页   跳转

灰鸽子病毒,请高手指点。(有日志)

灰鸽子病毒,请高手指点。(有日志)

好几天用正版瑞星杀毒(系统为win2000.),当时是杀掉,但下次重新启动,又出现
backdoor.GPigeon.5.an.路径为
IEXPLORE.EXE>>C:\PROGRAME FILES\INTERNET EXPLORER\IEXPLORE.EXE

对计算机不太懂,但看见前面分析,知道需要日志,所以贴出来如下。望各位高手指点。
扫描日志显示为
Logfile of HijackThis v1.99.1
Scan saved at 12:14:53, on 2006-10-7
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
d:\ENTERN~2\app\pppoeservice.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
D:\MemTurbo30\MemTurbo.exe
d:\ENTERN~2\app\EnterNetFolder.Exe
d:\ENTERN~2\app\EnterNet.exe
C:\Program Files\Rising\Rav\RsLogVw.exe
D:\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.284\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: 59.34.148.98 www.hao123.com
O1 - Hosts: 59.34.148.98 www.4199.com
O1 - Hosts: 59.34.148.98 www.9505.com
O1 - Hosts: 59.34.148.98 www.7322.com
O1 - Hosts: 218.5.76.175 www.huoche.com.cn
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5007.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - d:\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [RfwMain] "c:\program files\rising\rfw\rfwmain.exe" -startup
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: MemTurbo.lnk = D:\MemTurbo30\MemTurbo.exe
O4 - Global Startup: microsoft office.lnk = D:\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: 使用影音传送带下载 - D:\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - D:\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://D:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160048961654
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Microsoft Clibook service. - Unknown owner - C:\WINNT\smss.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - d:\ENTERN~2\app\pppoeservice.exe
O23 - Service: Remote Procedu Help Session - Unknown owner - C:\WINNT\system32\Com\net
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: system - Unknown owner - C:\Program Files\HgzServer\G_Server2006.exe

最后编辑2006-10-07 15:19:13
分享到:
gototop
 

O23 - Service: system - Unknown owner - C:\Program Files\HgzServer\G_Server2006.exe
O23 - Service: Remote Procedu Help Session - Unknown owner - C:\WINNT\system32\Com\net
O23 - Service: Microsoft Clibook service. - Unknown owner - C:\WINNT\smss.exe
O1 - Hosts: 59.34.148.98 www.hao123.com
O1 - Hosts: 59.34.148.98 www.4199.com
O1 - Hosts: 59.34.148.98 www.9505.com
O1 - Hosts: 59.34.148.98 www.7322.com
O1 - Hosts: 218.5.76.175 www.huoche.com.cn
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5007.dll
修复
重启后删除上述对应文件



gototop
 

O23 - Service: Microsoft Clibook service. - Unknown owner - C:\WINNT\smss.exe

O23 - Service: Remote Procedu Help Session - Unknown owner - C:\WINNT\system32\Com\net

O23 - Service: system - Unknown owner - C:\Program Files\HgzServer\G_Server2006.exe

鸽子
参考下这里
http://forum.ikaka.com/topic.asp?board=28&artid=7713905
gototop
 

C:\Program Files\HgzServer\G_Server2006.exe
C:\WINNT\system32\Com\net
C:\WINNT\smss.exe
QQ289039676
传给我
gototop
 

谢谢newcenturymoon, MagenSky,taylor05771的热情帮助,终于杀掉灰鸽子了!!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT