紫眸790616 - 2005-8-6 21:06:00
我的瑞星发现了backdoor.gpigeon.shk病毒,每次都显示清除成功,可是每次重启电脑时再检测还是有,真的好烦啊,希望各份能帮帮我。
蜀苡 - 2005-8-6 21:18:00
我这同样的问题,病毒为backdoor.gpigeon.fu 谢谢
niniddd - 2005-8-6 22:47:00
dsd
xiaoguang1975 - 2005-8-6 22:49:00
我的也是,附上HijackThis扫描日志,请高手解读O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - Service: WINServer (WIN GronServer) - Unknown owner - C:\WINNT\WIN_Server.exe
niniddd - 2005-8-6 22:54:00
首先用瑞星进行杀毒,会在C盘杀出N个病毒(根据运行进程的多少而定)。然后在我的电脑中的文件夹选项里显示所有文件和系统文件。进入C盘---WINDOWS,再里面找到KC打头的,好象是KCMP。三种文件格式。EXE的一个,DLL的两个。HOOK.DLL的一个.将他们删除,然后重新启动计算机。OK了!
xiaoguang1975 - 2005-8-6 23:53:00
楼上的,根本没你说的那几个文件,只能看到一个win_server_hook.dll。
CAJINCHEN - 2005-8-7 0:08:00
O23 - Service: WINServer (WIN GronServer) - Unknown owner - C:\WINNT\WIN_Server.exe
http://forum.ikaka.com/topic.asp?board=28&artid=6202404
© 2000 - 2026 Rising Corp. Ltd.