1   1  /  1  页   跳转

求助,又中灰鸽子了,怎么办

求助,又中灰鸽子了,怎么办

用瑞星杀毒提示在C:\Program Files\Internet Explorer\IEXPLORE.EXE中发现Backdoor.Gpigeon.fmm并提示“清除成功”,但是每次重新启动后,又能在同样的路径找到同样的病毒,请指教,怎样才能彻底清除它呢,谢谢了!
 

下面是用Hijackthis扫描后的日志


Logfile of HijackThis v1.99.1
Scan saved at 20:45:05, on 2006-9-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\rising\Rav\RavStub.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\Program Files\rising\Rav\Ravmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ChinaNet\VnetClient.exe
E:\download\soft\shadu\HijackThis\HijackThis.exe

O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - E:\PROGRA~2\FlashGet\fgiebar.dll
O3 - Toolbar: BitComet工具栏 - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - e:\Program Files\BitComet\BitCometBar\BitCometBar0.6.dll
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - Global Startup: 星空极速.lnk = C:\Program Files\ChinaNet\VnetClient.exe
O8 - Extra context menu item: 使用网际快车下载 - E:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - E:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\PROGRA~2\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\PROGRA~2\FlashGet\flashget.exe
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O23 - Service: IISserver  (nternet Information Server SP2) - Unknown owner - C:\Program Files\IISserver\IISserver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\Ravmond.exe

最后编辑2007-06-09 23:11:21
分享到:
gototop
 

O23 - Service: IISserver (nternet Information Server SP2) - Unknown owner - C:\Program Files\IISserver\IISserver.exe
什么服务??
gototop
 

不知道嘛,不是我自己加的
gototop
 

C:\Program Files\IISserver\IISserver.exe
QQ289039676 传给我

修复
O23 - Service: IISserver (nternet Information Server SP2) - Unknown owner - C:\Program Files\IISserver\IISserver.exe
gototop
 

在服务选项里看了IISserver为Internet Information Server提供信息服务,目前设置为“自动”,登录为“本地系统”
gototop
 

我的电脑从4号以来也是如此.每次开机后防火墙提示C:\Program Files\Internet Explorer\IEXPLORE.EXE ->Backdoor.Gpigeon.fmm 木马清除成功.在网上发了三回贴,都没人解答,看来只有重做系统了.
gototop
 

病毒就象蚊子臭虫一样的多,要做好防蚊虫的设施!!~~
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT