1   1  /  1  页   跳转

灰鸽子病毒!!! 求救!!

灰鸽子病毒!!! 求救!!

我的电脑中了Backdoor.Gpigeon.jnw  瑞星查杀了,可是重起后又有!
请大侠们指教该怎样清除该病毒
最后编辑2007-02-28 17:14:52
分享到:
gototop
 

该用户帖子内容已被屏蔽
gototop
 

鸽子...应该是服务没有删吧.
扫份sreng日志上来看看.
gototop
 

用江民和金山在线查毒看看

江民在线查毒
http://online.jiangmin.com/chadu.asp

金山在线查毒
http://shadu.duba.net/

开机时按F8安全模式

而且通过KAKA看看"进程管理"(通过发行者和时间)和系统启动项管理有没可疑的
gototop
 

服务
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[HighPoint RAID Management Service / hptsvr][Stopped/Auto Start]
  <"C:\Program Files\HighPoint Technologies, Inc.\HighPoint RAID Management Software\service\hptsvr.exe"><N/A>
[Microsoft Search / MSSEARCH][Running/Auto Start]
  <"C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe"><Microsoft Corporation>
[MSSQL$RAVN / MSSQL$RAVN][Running/Auto Start]
  <C:\Program Files\MSDE\MSSQL$RAVN\Binn\sqlservr.exe -sRAVN><Microsoft Corporation>
[MSSQLSERVER / MSSQLSERVER][Running/Auto Start]
  <C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe><Microsoft Corporation>
[MSSQLServerADHelper / MSSQLServerADHelper][Stopped/Manual Start]
  <C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe><Microsoft Corporation>
[OracleDBConsoleorcl / OracleDBConsoleorcl][Stopped/Manual Start]
  <c:\oracle\product\10.2.0\db_1\bin\nmesrvc.exe><Oracle Corporation>
[OracleJobSchedulerORCL / OracleJobSchedulerORCL][Stopped/Disabled]
  <c:\oracle\product\10.2.0\db_1\Bin\extjob.exe ORCL><N/A>
[OracleOraDb10g_home1iSQL*Plus / OracleOraDb10g_home1iSQL*Plus][Stopped/Manual Start]
  <c:\oracle\product\10.2.0\db_1\bin\isqlplussvc.exe><Oracle>
[OracleOraDb10g_home1TNSListener / OracleOraDb10g_home1TNSListener][Stopped/Manual Start]
  <c:\oracle\product\10.2.0\db_1\BIN\TNSLSNR ><N/A>
[OracleServiceORCL / OracleServiceORCL][Stopped/Manual Start]
  <c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE ORCL><Oracle Corporation>
[RavAgent / RavAgent][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\RavAgent.exe"><北京瑞星科技股份有限公司>
[Rav Net Alert / RavAlert][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\RavAlert.exe"><瑞星科技股份发展有限公司>
[RavService / RavService][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\RavService.exe" /service><Beijing Rising Technology Co., Ltd.>
[RavUpdate / RavUpdate][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\RavUpdate.exe" ><Beijing Rising Technology Co., Ltd.>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[RNReport / RNReport][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\RNReport.exe"><瑞星科技股份发展有限公司>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Serv-U FTP Server / Serv-U][Running/Auto Start]
  <C:\WINDOWS\system32\1035\etc\system\ServUDaemon.exe><Rhino Software, Inc. +1(262) 560-9627>
[IBM DS4000/FAStT Storage Manager 9 Event Monitor / SMmonitor][Running/Auto Start]
  <C:\Program Files\IBM_DS4000\client\monitor\SMmonitor.exe><N/A>
[spoolntA / spoolntA][Stopped/Auto Start]
  <C:\WINDOWS\system32\1035\etc\system\svchost.exe -b C:\WINDOWS\system32\1035\etc\system\1.dll><N/A>
[SQLAgent$RAVN / SQLAgent$RAVN][Stopped/Manual Start]
  <C:\Program Files\MSDE\MSSQL$RAVN\Binn\sqlagent.EXE -i RAVN><Microsoft Corporation>
[system32 / system32][Stopped/Auto Start]
  <C:\Program Files\system32><N/A>
[Wireless Zero Configuratiom / Wireless Zero Configuratiom][Stopped/Auto Start]
  <C:\WINDOWS\system32\Wireless.exe><N/A>
gototop
 

[system32 / system32][Stopped/Auto Start]
<C:\Program Files\system32><N/A>
[Wireless Zero Configuratiom / Wireless Zero Configuratiom][Stopped/Auto Start]
<C:\WINDOWS\system32\Wireless.exe><N/A>

两只鸽子
gototop
 

请教大侠们该如何删除服务呢?
gototop
 

该用户帖子内容已被屏蔽
gototop
 

看一下"UFO不幸外人"写的"SREng的使用方法"
http://forum.ikaka.com/topic.asp?board=28&artid=8270267
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT