瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我的电脑中了Gpigeon.door.shk 请各位帮忙分析一下HIJACK日志

1   1  /  1  页   跳转

我的电脑中了Gpigeon.door.shk 请各位帮忙分析一下HIJACK日志

我的电脑中了Gpigeon.door.shk 请各位帮忙分析一下HIJACK日志

用了各种方法就是杀不掉,怎么弄啊,
Logfile of HijackThis v1.99.1
Scan saved at 22:22:16, on 2005-8-16
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
D:\PROGRA~1\RISING\RAV\RAVMON.EXE
D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\wdfmgr.exe
D:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Downloads\driver\1903632005219183744\HijackThis.exe

O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\Program Files\FlashGet\jccatch.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 卡卡安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\System32\KakaTool.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MS-4011 Memory Patch] D:\RavSasser.exe -Patch
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [YDTMain.exe] C:\PROGRA~1\YDT\YDTMain.exe
O4 - HKLM\..\Run: [RavTimer] D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 用比特精灵下载(&B) - C:\Program Files\BitSpirit\bsurl.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/ravkill/rsonline.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: WINServer (WIN GronServer) - Unknown owner - C:\WINDOWS\WIN_Server.exe

最后编辑2005-08-16 23:11:31
分享到:
gototop
 

【回复“88668866”的帖子】以下是我的瑞星扫描日志
病毒名称处理结果扫描方式路径文件病毒来源
Backdoor.Gpigeon.shk删除成功实时监控C:\WINDOWSWIN_Server.DLL本机
Backdoor.Gpigeon.hn删除成功快捷扫描D:\PROGRAM FILES成人H动画!~我想我不用多说了吧!~嘿嘿!~.EXE>>海报.exe>>VEUnpackFile本机
Backdoor.Gpigeon.hn删除成功实时监控D:\Program Files海报.exe>>VEUnpackFile本机
Backdoor.Gpigeon.shk删除成功实时监控C:\WINDOWSWIN_SERVER_HOOK.DLL本机
Backdoor.Gpigeon.shk删除成功实时监控C:\WINDOWSWIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk删除成功实时监控C:\WINDOWSWIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk删除成功实时监控C:\WINDOWSWIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk删除成功手动扫描C:\WINDOWSWIN_Server.DLL本机
Backdoor.Gpigeon.shk删除成功手动扫描C:\System Volume Information\_restore{7CD7D720-5DD3-4188-A5E9-7CC88D9C96FB}\RP9A0009679.DLL本机
Backdoor.Gpigeon.shk删除成功手动扫描C:\System Volume Information\_restore{7CD7D720-5DD3-4188-A5E9-7CC88D9C96FB}\RP9A0009686.DLL本机
Backdoor.Gpigeon.shk删除成功手动扫描C:\System Volume Information\_restore{7CD7D720-5DD3-4188-A5E9-7CC88D9C96FB}\RP9A0009687.DLL本机
Backdoor.Gpigeon.shk删除成功手动扫描C:\System Volume Information\_restore{7CD7D720-5DD3-4188-A5E9-7CC88D9C96FB}\RP9A0009704.DLL本机
Backdoor.Gpigeon.shk删除成功手动扫描C:\System Volume Information\_restore{7CD7D720-5DD3-4188-A5E9-7CC88D9C96FB}\RP10A0009746.DLL本机
Backdoor.Gpigeon.shk删除成功手动扫描C:\System Volume Information\_restore{7CD7D720-5DD3-4188-A5E9-7CC88D9C96FB}\RP11A0010752.DLL本机
Backdoor.Gpigeon.shk删除成功手动扫描C:\System Volume Information\_restore{7CD7D720-5DD3-4188-A5E9-7CC88D9C96FB}\RP11A0010789.DLL本机
Backdoor.GPigeon.sis删除成功手动扫描D:\System Volume Information\_restore{7CD7D720-5DD3-4188-A5E9-7CC88D9C96FB}\RP8A0008670.EXE>>setup.exe本机
Backdoor.Gpigeon.hn删除成功手动扫描D:\System Volume Information\_restore{7CD7D720-5DD3-4188-A5E9-7CC88D9C96FB}\RP10A0009812.exe>>海报.exe>>VEUnpackFile本机
Backdoor.Gpigeon.shk清除成功手动扫描csrss.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描winlogon.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描winlogon.exe>>C:\WINDOWS\WIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描services.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描lsass.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描svchost.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描svchost.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描svchost.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描svchost.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描spoolsv.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描Explorer.EXE>>C:\WINDOWS\WIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描Explorer.EXE>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描realsched.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描realsched.exe>>C:\WINDOWS\WIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描RAVTIMER.EXE>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描RAVTIMER.EXE>>C:\WINDOWS\WIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描ctfmon.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描ctfmon.exe>>C:\WINDOWS\WIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描alg.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描acsd.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描CCENTER.EXE>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描Ravmond.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描wdfmgr.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描RavStub.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描IEXPLORE.EXE>>C:\WINDOWS\WIN_Server.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描IEXPLORE.EXE>>C:\WINDOWS\WIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描IEXPLORE.EXE>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描Rav.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描>>C:\WINDOWSWIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描rasautou.exe>>C:\WINDOWS\WIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描csrss.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描winlogon.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描winlogon.exe>>C:\WINDOWS\WIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描services.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描lsass.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描svchost.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描svchost.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描svchost.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描svchost.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描spoolsv.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描Explorer.EXE>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描realsched.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描realsched.exe>>C:\WINDOWS\WIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描RAVTIMER.EXE>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描RAVTIMER.EXE>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描ctfmon.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描alg.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描acsd.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描CCENTER.EXE>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描Ravmond.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描wdfmgr.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描RavStub.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描IEXPLORE.EXE>>C:\WINDOWS\WIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描IEXPLORE.EXE>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描Rav.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk删除成功手动扫描C:\WINDOWSWIN_Server.DLL本机
Backdoor.Gpigeon.shk删除成功手动扫描C:\WINDOWSWIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk删除成功手动扫描C:\WINDOWSWIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk删除成功实时监控C:\WINDOWSWIN_SERVER_HOOK.DLL本机
Backdoor.Gpigeon.shk删除成功实时监控C:\WINDOWSWIN_SERVERKEY.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描csrss.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描winlogon.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描winlogon.exe>>C:\WINDOWS\WIN_ServerKey.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描services.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描lsass.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描svchost.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
Backdoor.Gpigeon.shk清除成功手动扫描svchost.exe>>C:\WINDOWS\WIN_Server_Hook.DLL本机
gototop
 

【回复“88668866”的帖子】
晚上好。
O23 - Service: WINServer (WIN GronServer) - Unknown owner - C:\WINDOWS\WIN_Server.exe是灰鸽子。
删除文件:
C:\WINDOWS\WIN_Server.exe
C:\WINDOWS\WIN_Server.dll
C:\WINDOWS\WIN_Server_hook.dll
C:\WINDOWS\WIN_Serverkey.dll
展开注册表到:
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES
删除WINServer (WIN GronServer)服务分支。
gototop
 

谢谢,已搞定
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT