瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 如何杀掉Backdoor.Gpigeon.2006.r 在线等

1   1  /  1  页   跳转

如何杀掉Backdoor.Gpigeon.2006.r 在线等

如何杀掉Backdoor.Gpigeon.2006.r 在线等

如何杀掉Backdoor.Gpigeon.2006.r  在线等,这个病毒真的顽固到底了,不知道如何杀掉,用了瑞星杀掉重启动后,还是有啊,高手指点一下

附件附件:

下载次数:204
文件类型:image/pjpeg
文件大小:
上传时间:2006-5-12 13:12:20
描述:



最后编辑2006-08-09 16:08:28
分享到:
gototop
 

2006-05-12,13:19:05

System Repair Engineer 2.0.12.350 (2.0 RC 1)
    Windows 2000 Advanced Server Service Pack 4 - 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <Xplus_spy><"C:\Program Files\Xplus\xvcclip.exe" /min>
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  <ctfmon.exe><ctfmon.exe>
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <load><>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <ATIModeChange><Ati2mdxx.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <AtiPTA><atiptaxx.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <MINI_BFYY><C:\Program Files\Ringz Studio\Storm Downloader\StormDownloader.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <StormCodec_Helper><"C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe">
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <Thunder><"C:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <xBarUpdate><C:\Program Files\xBar\xBarUpdate.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <HP SchedIndexer><C:\Program Files\Hewlett-Packard\LaserJet All-in-one\hppschedindexer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <HP AutoIndexer><C:\Program Files\Hewlett-Packard\LaserJet All-in-one\hppautoindexer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <BullsEye Network><C:\Program Files\BullsEye Network\bin\bargains.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <NaviSearch><C:\Program Files\NaviSearch\bin\nls.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <TuoTu><C:\Program Files\Tuotu\Tuotu.exe /m>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <supdate2.dll><RUNDLL32.EXE C:\WINNT\system32\supdate2.dll,Run>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <shell><Explorer.exe>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  <Userinit><C:\WINNT\system32\userinit.exe,>
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><C:\WINNT\system32\SoDAHK.DLL>
gototop
 

=================================
启动文件夹
[Adobe Gamma Loader]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Gamma Loader.lnk><N>
[HP LaserJet Director]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\HP LaserJet Director.lnk><N>
[Microsoft Office]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Microsoft Office.lnk><N>
[DreamMail]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\DreamMail.lnk><N>
[飞鸽传书]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\飞鸽传书.lnk><N>

==================================
服务
[Adobe LM Service / Adobe LM Service]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Ati HotKey Poller / Ati HotKey Poller]
  <C:\WINNT\System32\Ati2evxx.exe><N/A>
[Logical Disk Manager Administrative Service / dmadmin]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[ Internet Explorer  / Internet Explorer ]
  <C:\WINNT\SVCH0ST.exe><N/A>
[Windows Install Helper / iSPONER]
  <C:\WINNT\SYSTEM32\RUNDLL32.EXE C:\WINNT\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[Logical ServiceWeb / Logical ServiceWeb]
  <C:\WINNT\eveil.exe><N/A>
[OracleMTSRecoveryService / OracleMTSRecoveryService]
  <C:\oracle\ora92\bin\omtsreco.exe "OracleMTSRecoveryService"><Oracle Corporation>
[OracleOraHome92ClientCache / OracleOraHome92ClientCache]
  <C:\oracle\ora92\BIN\ONRSD.EXE><N/A>
[P4P Service / P4P Service]
  <C:\Program Files\Common Files\Sogou PXP\p2psvr.exe><Sohu.com Inc.>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Network System / Universal Disk Manager]
  <C:\Program Files\Common Files\COMM\Network.exe><COMENET TECHNOLOGY>
[VRVWatchServer / VRVWatchServer]
  <"C:\WINNT\system32\WatchClient.exe" -service><BXY>

==================================
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT