瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 但每次开机都这么提示Backdoor.Gpigeon.sfa这个病毒已成功清除
andierl - 2005-9-26 10:57:00
各位高手你们好!求助!今天我一启动电脑瑞星防火墙就提示Backdoor.Gpigeon.sfa这个病毒已成功清除(但每次开机都这么提示)我启动瑞星杀毒软件,瑞星杀毒软件没有发现这个病毒,但每次开机都这么提示。这是怎么回事?请帮助解决!谢谢!
独孤豪侠 - 2005-9-26 11:02:00
灰鸽子,扫个HJ日志上来,教你怎么杀
andierl - 2005-9-26 11:12:00
请看,

附件: 2650892005926111206.jpg
风中的鹰 - 2005-9-26 11:16:00
http://forum.ikaka.com/topic.asp?board=28&artid=6202404
andierl - 2005-9-26 11:56:00
C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra button: WellGet - {35980F6E-A258-4E50-953D-813BB8556899} - D:\Program Files\WellGet\WellGet.exe
O9 - Extra button: (no name) - {676ab8e0-f5a6-11d3-86a5-0088cc224026} - D:\Herosoft\Application\TransIE.dll
O9 - Extra 'Tools' menuitem: 译星帮助 - {676ab8e0-f5a6-11d3-86a5-0088cc224026} - D:\Herosoft\Application\TransIE.dll
O9 - Extra button: 英文 - {C2EDD5E0-EB64-11d3-B4D2-0088CC231035} - D:\Herosoft\Application\TransIE.dll
O9 - Extra 'Tools' menuitem: 英文 - {C2EDD5E0-EB64-11d3-B4D2-0088CC231035} - D:\Herosoft\Application\TransIE.dll
O9 - Extra button: 易趣购物 - {DE60714F-AC19-427e-861A-FD60ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=1 (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {DE60714F-AC19-427e-861A-FD60ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=1 (file missing)
O11 - Options group: [CDNCLIENT]  中文上网
O16 - DPF: {448A5F6B-8C03-4B54-A338-F00237C508AD} (WEBChatRoomOCX Control) - http://www.51uc.com/cab/WEBChatRoom_1_39.cab
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {9A578C98-3C2F-4630-890B-FC04196EF420} (CNNIC_IDN) - http://client.jogo.cn/download/cnnic/cdn.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3432E768-8EE0-4B4C-BAE7-4850552DE5AA}: NameServer = 61.128.99.133 218.30.19.40
O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\SYSTEM32\dimsntfy.dll
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\G_Server.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - d:\瑞星杀毒\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - D:\瑞星杀毒\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\瑞星杀毒\RAV\Ravmond.exe
baohe - 2005-9-26 11:59:00
【回复“andierl”的帖子】
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\G_Server.exe

灰鸽子。
查杀方法可参考:http://forum.ikaka.com/topic.asp?board=28&artid=6202404
andierl - 2005-9-26 12:12:00
引用:
【baohe的贴子】【回复“andierl”的帖子】
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\G_Server.exe

灰鸽子。
查杀方法可参考:http://forum.ikaka.com/topic.asp?board=28&artid=6202404
...........................

我按照这个方法没有找到C:\WINDOWS\G_Server.exe,怎么办?
1
查看完整版本: 但每次开机都这么提示Backdoor.Gpigeon.sfa这个病毒已成功清除