瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 Backdoor.Gpigeon.fcr到底是个什么病毒,怎么杀不掉?

1   1  /  1  页   跳转

Backdoor.Gpigeon.fcr到底是个什么病毒,怎么杀不掉?

Backdoor.Gpigeon.fcr到底是个什么病毒,怎么杀不掉?

把自己隐藏到IEXPLORE.EXE中,每次都要手动杀毒,杀完了开机自动又加载!!!
最恶心的是还能自动关闭瑞星的实时监控!这个病毒到底怎么杀啊!!!

附件附件:

下载次数:389
文件类型:image/pjpeg
文件大小:
上传时间:2006-7-31 20:04:28
描述:



最后编辑2006-07-31 20:57:40.590000000
分享到:
gototop
 

2006-07-31,20:06:58

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [Microsoft Corporation]
    <pyjj><C:\Program Files\jj4\jjsvr4.exe>  [加加开发组]
    <Active Desktop Calendar><C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe>  [XemiComputers ltd.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Logitech Utility><Logi_MwX.Exe>  [Logitech Inc.]
    <DAEMON Tools><"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033>  [DT Soft Ltd.]
    <RemoteControl><"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe">  [Cyberlink Corp.]
    <LanguageShortcut><"C:\Program Files\CyberLink\PowerDVD\Language\Language.exe">  []
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <NeroCheck><C:\WINDOWS\system32\\NeroCheck.exe>  [Ahead Software Gmbh]
    <NVIDIA nTune><"C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear>  []
    <NetSense><E:\Net\netsense\netsense.exe>  [Beijing Grabsun Tech Co,. LTD.]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [NVIDIA Corporation]
    <MSConfig><C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]

==================================
启动文件夹
[Adobe Reader Speed Launch]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Adobe Reader Speed Launch.lnk><N>
[Service Manager]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\Service Manager.lnk><N>
[T-Utility Fan Control]
  <C:\Documents and Settings\Duyes\「开始」菜单\程序\启动\T-Utility Fan Control.lnk><N>

==================================
服务
[Adobe LM Service / Adobe LM Service]
  <"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[BlueSoleil Hid Service / BlueSoleil Hid Service]
  <C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe><N/A>
[ctuserver / ctuserver]
  <C:\WINDOWS\ctuserver.exe><N/A>
[DriveHealth / DriveHealth]
  <C:\Program Files\Helexis\Drive Health\dhcore.exe><Helexis Software Development>
[InstallDriver Table Manager / IDriverT]
  <"C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[nTune Service / nTuneService]
  <C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe /StartService><NVIDIA>
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Cyberlink RichVideo Service(CRVS) / RichVideo]
  <"C:\Program Files\CyberLink\Shared files\RichVideo.exe"><>
[Remote Packet Capture Protocol v.0 (experimental) / rpcapd]
  <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
gototop
 

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v13.dll, Thunder Networking Technologies,LTD>
[BHO Class]
  {04DCC17E-35E1-417A-ABCF-41623FA2ACE7} <E:\Net\K750C上网工具\Garden3.34\gbho.dll, >
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Windows Live Sign-in Helper]
  {9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[NewWebController Class]
  {9ACEEE30-143F-471A-AA45-72B061FE7D60} <C:\WINDOWS\system32\AdvSC.dll, N/A>
[WinSC Class]
  {9ACEEE31-1440-471B-AA46-72B061FE7D61} <C:\WINDOWS\system32\WinSC.dll, N/A>
[FlashFXP Helper for Internet Explorer]
  {E5A1691B-D188-4419-AD02-90002030B8EE} <E:\Net\FlashFXP\IEFlash.dll, IniCom Networks, Inc.>
[iTrusPTA Class]
  {1E0DFFCF-27FF-4574-849B-55007349FEDA} <C:\WINDOWS\system32\aliedit\pta.dll, >
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINDOWS\system32\xunleibho_v13.dll, Thunder Networking Technologies,LTD>
[BHO Class]
  {04DCC17E-35E1-417A-ABCF-41623FA2ACE7} <E:\Net\K750C上网工具\Garden3.34\gbho.dll, >
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Edit Class]
  {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[iTrusPTA Class]
  {1E0DFFCF-27FF-4574-849B-55007349FEDA} <C:\WINDOWS\system32\aliedit\pta.dll, >
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, N/A>
[BrowserHelper Class]
  {2D99E8F4-56B7-457B-9A92-61B5D247D263} <C:\WINDOWS\system32\WinDefendor.dll, TODO: <公司名>>
[CEditCtrl Object]
  {488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\AliEdit.dll, www.alipay.com>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Microsoft Web 浏览器]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\shdocvw.dll, Microsoft Corporation>
[Windows Live Sign-in Helper]
  {9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[NewWebController Class]
  {9ACEEE30-143F-471A-AA45-72B061FE7D60} <C:\WINDOWS\system32\AdvSC.dll, N/A>
[WinSC Class]
  {9ACEEE31-1440-471B-AA46-72B061FE7D61} <C:\WINDOWS\system32\WinSC.dll, N/A>
[SearchAssistantOC]
  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[FlashFXP Helper for Internet Explorer]
  {E5A1691B-D188-4419-AD02-90002030B8EE} <E:\Net\FlashFXP\IEFlash.dll, IniCom Networks, Inc.>
[PBActiveX40 Control]
  {F2EB8999-766E-4BF6-AAAD-188D398C0D0B} <C:\WINDOWS\system32\CMBPB40.ocx, China Merchants Bank>
[&使用迅雷下载]
  <C:\Program Files\Thunder Network\Thunder\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <C:\Program Files\Thunder Network\Thunder\getallurl.htm, N/A>
gototop
 

==================================
正在运行的进程
[PID: 956][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1048][\??\C:\WINDOWS\system32\csrss.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1096][\??\C:\WINDOWS\system32\winlogon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1144][C:\WINDOWS\system32\services.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1156][C:\WINDOWS\system32\lsass.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1308][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1388][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1508][C:\Program Files\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 1524][C:\WINDOWS\System32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1568][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1728][C:\WINDOWS\system32\svchost.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1832][C:\Program Files\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 29>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [C:\Program Files\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [C:\Program Files\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [C:\Program Files\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [C:\Program Files\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 12>
    [C:\Program Files\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\Program Files\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\ExtMail.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 1956][C:\WINDOWS\Explorer.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\XemiComputers\Active Desktop Calendar\mousehook.dll]  <N/A><N/A>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll]  <Adobe Systems Incorporated><7.0.0.2004121400>
    [C:\WINDOWS\system32\AdvSC.dll]  <N/A><N/A>
    [C:\WINDOWS\system32\WinSC.dll]  <N/A><N/A>
    [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll]  <Adobe Systems, Inc.><7.0.0.0>
    [C:\WINDOWS\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 21>
[PID: 368][C:\WINDOWS\system32\spoolsv.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 476][C:\Program Files\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 16>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 684][C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe]  <N/A><N/A>
[PID: 756][C:\Program Files\Helexis\Drive Health\dhcore.exe]  <Helexis Software Development><2.3.0.110>
[PID: 752][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 804][C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe]  <Microsoft Corporation><2005.090.1399.00>
[PID: 864][C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe]  <Microsoft Corporation><2000.080.0194.00>
[PID: 920][C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe]  <NVIDIA><5.00.06>
    [C:\Program Files\NVIDIA Corporation\nTune\nTuneServiceENU.dll]  <NVIDIA><5.00.06>
[PID: 348][C:\WINDOWS\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.9131>
[PID: 568][C:\Program Files\CyberLink\Shared files\RichVideo.exe]  <><1.1.0808  >
[PID: 1612][C:\WINDOWS\system32\wdfmgr.exe]  <Microsoft Corporation><5.2.3790.1230 built by: dnsrv(bld4act)>
[PID: 780][C:\WINDOWS\System32\alg.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
[PID: 1332][C:\Program Files\DAEMON Tools\daemon.exe]  <DT Soft Ltd.><4.00.0.0>
    [C:\Program Files\DAEMON Tools\daemon.dll]  <DT Soft Ltd.><4.00.0.0>
    [C:\Program Files\DAEMON Tools\PFCTOC.DLL]  <Padus(R), Inc.><1, 0, 0, 12>
    [C:\Program Files\DAEMON Tools\Plugins\Images\bw5mount.dll]  <N/A><1.0.6.0>
    [C:\Program Files\DAEMON Tools\Plugins\Images\ccdmount.dll]  <GENERIC><1.10.0.0>
    [C:\Program Files\DAEMON Tools\Plugins\Images\mdsmount.dll]  <GENERIC><1.12.0.0>
    [C:\Program Files\DAEMON Tools\Plugins\Images\nrgmount.dll]  <GENERIC><1.11.0.0>
    [C:\Program Files\DAEMON Tools\Plugins\Images\pdimount.dll]  <GENERIC><1.01.0.0>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\XemiComputers\Active Desktop Calendar\mousehook.dll]  <N/A><N/A>
[PID: 1024][C:\Program Files\Logitech\MouseWare\system\em_exec.exe]  <Logitech Inc.><9.79.019>
    [C:\Program Files\Logitech\MouseWare\system\EVENTEX.dll]  <Logitech Inc.><9.79.019>
    [C:\WINDOWS\system32\COMNCTR.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\Logitech\MouseWare\system\ccresrce.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\Logitech\MouseWare\system\GlbResLt.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Logitech\MouseWare\System\devices.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\Logitech\MouseWare\system\ccstmglb.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\Logitech\MouseWare\system\ccustom.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\Logitech\MouseWare\system\ccmsghk.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\XemiComputers\Active Desktop Calendar\mousehook.dll]  <N/A><N/A>
[PID: 1552][C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe]  <Cyberlink Corp.><5.00.0910>
    [C:\Program Files\CyberLink\PowerDVD\CLRCEngine3.dll]  <CyberLink Corp.><4, 5, 0, 1711>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\XemiComputers\Active Desktop Calendar\mousehook.dll]  <N/A><N/A>
[PID: 1892][C:\Program Files\Rising\Rav\RavTask.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 22>
gototop
 

[C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\XemiComputers\Active Desktop Calendar\mousehook.dll]  <N/A><N/A>
[PID: 1964][C:\Program Files\Rising\Rav\Ravmon.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 30>
    [C:\Program Files\Rising\Rav\RsGuiLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 24>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\PngDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\XemiComputers\Active Desktop Calendar\mousehook.dll]  <N/A><N/A>
[PID: 2324][C:\WINDOWS\system32\ctfmon.exe]  <Microsoft Corporation><5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\XemiComputers\Active Desktop Calendar\mousehook.dll]  <N/A><N/A>
[PID: 2360][C:\Program Files\jj4\jjsvr4.exe]  <加加开发组><4.0.0.19>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\XemiComputers\Active Desktop Calendar\mousehook.dll]  <N/A><N/A>
[PID: 2376][C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe]  <XemiComputers ltd.><5, 5, 0, 0>
    [C:\Program Files\XemiComputers\Active Desktop Calendar\mousehook.dll]  <N/A><N/A>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
[PID: 2444][C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe]  <Adobe Systems Incorporated><7.0.0.0>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
    [C:\Program Files\XemiComputers\Active Desktop Calendar\mousehook.dll]  <N/A><N/A>
[PID: 2456][C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe]  <Microsoft Corporation><2000.080.0194.00>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\XemiComputers\Active Desktop Calendar\mousehook.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
[PID: 2484][C:\Program Files\BIOSTAR\T-Utility Fan Control\FanConditioner.exe]  <BIOSTAR MICROTECH INT'L CORP.><1.0.0.6>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\BIOSTAR\T-Utility Fan Control\nvgpio.dll]  <NVIDIA Corporation><1.0.2.1>
    [C:\WINDOWS\system32\msdmo.dll]  <N/A><N/A>
    [C:\Program Files\XemiComputers\Active Desktop Calendar\mousehook.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>
[PID: 2912][H:\Download\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll]  <Logitech Inc.><9.79.019>
    [C:\Program Files\XemiComputers\Active Desktop Calendar\mousehook.dll]  <N/A><N/A>
    [C:\Program Files\Common Files\Logitech\Scrolling\LgMsgHk.dll]  <Logitech Inc.><1.1.0>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock 提供者

==================================
gototop
 

引用:
【huihuicat的贴子】你删注册表了吗?我那天好象也是中了这个毒,去c://windows/system32下面按创建时间排序,看看有没有什么中毒日新创建的文件,多半就是那个毒了.
...........................


老兄说详细一些,谢谢,我不是很明白,创建的什么文件呢?
注册表我想删的,问题不知道删那个!他用的IEXPLORE,我怕删出问题

说来都可恶,是去看了中关村在线www.zol.com.cn中的毒,现在也不敢过去了!!!
gototop
 

引用:
【oo123oo3的贴子】用HJ扫描 

帖日志上来
...........................


HJ是虾米东西……
gototop
 

引用:
【huihuicat的贴子】你删注册表了吗?我那天好象也是中了这个毒,去c://windows/system32下面按创建时间排序,看看有没有什么中毒日新创建的文件,多半就是那个毒了.
...........................

不知道这个是什么东西?!

附件附件:

下载次数:234
文件类型:image/pjpeg
文件大小:
上传时间:2006-7-31 20:28:40
描述:



gototop
 

引用:
【newcenturymoon的贴子】开始 运行 输入 services.msc 找到ctuserver 双击 停止并且将启动类型改为 已禁用
开始 运行 输入regedit 分别定位到HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00X\Services
查找ctuserver  目录,查到的清删除整个目录
重启计算机
显示所有文件并且显示隐藏的系统文件
删除如下文件C:\WINDOWS\ctuserver.exe
另外请把C:\WINDOWS\ctuserver.exe
打包发到newcenturymoon@126.com谢谢
...........................


已经发送,请查收,收到后我就删文件了
gototop
 

已经解决,谢谢newcenturymoon
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT