瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】如何把它彻底清除 Backdoor.Gpigeon.pi ??

12   2  /  2  页   跳转

【求助】如何把它彻底清除 Backdoor.Gpigeon.pi ??

灰鸽子目前没有那个杀软可以自动杀掉!
gototop
 

瑞星也没招
gototop
 

挨,瑞星快想想防治的办法吖。出点补丁什么的吖!
gototop
 

O23 - Service: Windows Upload (rund1132) - Unknown owner - C:\WINNT\rund1132.exe
出问题的可能性比较大,这个文件名蛮具有欺骗力的,和RUNDLL32很像,但实际是RUNDLL1132,建议在HijackThis 把这个文件修复,重新启动到安全模式,把注册表里关于rund1132.exe的注册信息删了,再看看C:\WINNT\目录下有没有以下的档案,有就删除
C:\WINNT\NetService.exe
C:\WINNT\NetService.dll
C:\WINNT\NetServiceKey.dll
C:\WINNT\NetService_Hook.dll
C:\WINNT\NetService_Hook2.dll
C:\WINNT\NetService_H00K.dll
gototop
 

引用:
【jerryangel的贴子】O23 - Service: Windows Upload (rund1132) - Unknown owner - C:\WINNT\rund1132.exe
出问题的可能性比较大,这个文件名蛮具有欺骗力的,和RUNDLL32很像,但实际是RUNDLL1132,建议在HijackThis 把这个文件修复,重新启动到安全模式,把注册表里关于rund1132.exe的注册信息删了,再看看C:\WINNT\目录下有没有以下的档案,有就删除
C:\WINNT\NetService.exe
C:\WINNT\NetService.dll
C:\WINNT\NetServiceKey.dll
C:\WINNT\NetService_Hook.dll
C:\WINNT\NetService_Hook2.dll
C:\WINNT\NetService_H00K.dll

...........................
的确是这个,建议参考这个清除http://forum.ikaka.com/topic.asp?board=28&artid=6202404
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 0:35:03, on 2005-10-4
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Tencent\qq\QQ.exe
D:\Tencent\QQ\TIMPlatform.exe
D:\Tencent\qq\QQ.exe
D:\Tencent\qq\QQ.exe
D:\Tencent\qq\QQ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\regedit.exe
C:\Documents and Settings\user_child\桌面\155847200541134207\HijackThis.exe

O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL (file missing)
O4 - HKLM\..\Run: [KAVPersonal50] "D:\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB PC Camera 301P
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Tencent\qq\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Tencent\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Tencent\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Tencent\qq\SendMMS.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Tencent\QQ\QQ.EXE
O9 - Extra button: 易趣购物 - {EE60714F-AC19-427e-861A-FD60ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=1 (file missing)
O9 - Extra 'Tools' menuitem: 易趣购物 - {EE60714F-AC19-427e-861A-FD60ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=1 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.fm365.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/aliedit.cab
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1126117933542
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {AC3A36A8-9BFF-410A-A33D-2279FFEB69D2} (QQPlayer Control) - http://219.133.62.247/QQPlayer.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl Object) - https://tenpay.qq.com/download/qqedit.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3879E7EE-AF38-4551-A070-1EA2671C6C88}: NameServer = 202.99.96.68 202.99.64.69
O23 - Service: Gray_Pigeon_Server2.0 (GrayPigeonServer2.0) - Unknown owner - C:\WINDOWS\G_Server2.0.exe
O23 - Service: kavsvc - Kaspersky Lab - D:\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


哪位朋友帮我看看哪个是?如何解决?谢谢!
gototop
 

斑竹大哥能不能教大家如何分析HijackThis扫描出来的日志?
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT