瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】无法删除Backdoor.Gpigeon(已找了N多帖子,无法解决),求高手啊!

1   1  /  1  页   跳转

【求助】无法删除Backdoor.Gpigeon(已找了N多帖子,无法解决),求高手啊!

【求助】无法删除Backdoor.Gpigeon(已找了N多帖子,无法解决),求高手啊!

HijackThis_815汉化版扫描日志 V1.99.1
保存于      12:45:57, 日期 2006-08-14
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Unable to get Internet Explorer version!

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\KAV2006\KWatch.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\SYSTEM32\DWRCS.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\nvsvc32.exe
C:\Program Files\Virus Chaser\SpiderNT.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Virus Chaser\Spiderui.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Virus Chaser\vcrmon.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\WINNT\system32\BHDCRegC.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\同花顺妙手回春\LiveUpdate.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\绿色软件\HijackThis\HijackThis1991zww.exe
最后编辑2006-08-15 12:39:30.217000000
分享到:
gototop
 

O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - IE工具栏增项: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINNT\system32\KakaTool.dll
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [Vcrmon] C:\Program Files\Virus Chaser\vcrmon.exe
O4 - 启动项HKLM\\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - 启动项HKLM\\Run: [BHDCRegC] C:\WINNT\system32\BHDCRegC.exe
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - D:\Program Files\迅雷\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - D:\Program Files\迅雷\getallurl.htm
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O10 - 未知的文件在 Winsock LSP: c:\winnt\system32\drwebsp.dll
O10 - 未知的文件在 Winsock LSP: c:\winnt\system32\drwebsp.dll
O10 - 未知的文件在 Winsock LSP: c:\winnt\system32\drwebsp.dll
O10 - 未知的文件在 Winsock LSP: c:\winnt\system32\drwebsp.dll
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/1007/aliedit.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1144519211481
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {A984ED9F-E8DA-44E5-BC18-C14B9ABEF79D} (photo_uploader Control) - http://upload.photo.163.com/photoup.cab
O16 - DPF: {C661F36D-DF85-4EF4-83C7-E107B83D04B1} (WebActivater Control) - http://dl_dir.qq.com/3dshow/3DShowVM.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl Object) - https://www.tenpay.com/download/qqedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E31A32E1-009B-47B0-9EED-2E8A84561488}: NameServer = 218.85.157.99,202.101.107.55
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: DameWare Mini Remote Control (DWMRCS) - DameWare Development - C:\WINNT\SYSTEM32\DWRCS.EXE
O23 - NT 服务: Kingsoft Antivirus KWatch Service (KWatchSvc) - Kingsoft Corporation - C:\KAV2006\KWatch.EXE
O23 - NT 服务: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - NT 服务: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - NT 服务: Virus Chaser Spider NT (spidernt) - New Technology Wave Inc. - C:\Program Files\Virus Chaser\SpiderNT.exe
O23 - NT 服务: Windows Image Acquisition (WIA (st1svc) - Unknown owner - C:\Program.exe (file missing)
gototop
 

没人知道吗?????????????

没人告诉我吗????????????

还是没人懂吗???????????
gototop
 

全名是不是叫Backdoor.Gpigeon.geg
这个名字?
gototop
 

就这个名字,这个就是全名
gototop
 

这里是卡卡论坛吗?

怎么有问题没人要帮忙啊?
gototop
 

ding.................
gototop
 

已看到怀疑的对象
楼主说一下路径文件名吧
gototop
 

开始 运行 输入 services.msc 找到Windows Image Acquisition (WIA (st1svc)双击 停止并且将启动类型改为 已禁用
开始 运行 输入regedit 分别定位到HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services(X代表任意,比如1,2 ,3……)

查找Windows Image Acquisition (WIA (st1svc)目录,查到的清删除整个目录
gototop
 

已经清楚了,谢谢。。。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT