瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 Backdoor.Gpigeon.2006.jv 死活杀不干净,怎么办

123   2  /  3  页   跳转

Backdoor.Gpigeon.2006.jv 死活杀不干净,怎么办

[D:\Program Files\Rising\Rav\SpamEng.dll] (N/A)(18, 0, 0, 6)
[D:\Program Files\Rising\Rav\engine.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 30)
[D:\Program Files\Rising\Rav\PostTrt.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 9)
[D:\Program Files\Rising\Rav\UnExe.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
[D:\Program Files\Rising\Rav\ScanExec.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
[D:\Program Files\Rising\Rav\ScanEx.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 11)
[D:\Program Files\Rising\Rav\NvFile.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 7)
[D:\Program Files\Rising\Rav\ScanMac.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 8)
[D:\Program Files\Rising\Rav\ScanSct.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 17)
[D:\Program Files\Rising\Rav\RsStore.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
[D:\Program Files\Rising\Rav\Unpacker.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 3)
[D:\Program Files\Rising\Rav\ScanNet.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 5)
[D:\Program Files\Rising\Rav\ExtOLE.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 6)
[PID: 1436][C:\WINDOWS\system32\spoolsv.exe] (Microsoft Corporation)(5.1.2600.0 (XPClient.010817-1148))
[PID: 1580][C:\WINDOWS\System32\drivers\CDAC11BA.EXE] (Macrovision)(4.20.020)
[PID: 1596][C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE] (C-Dilla Ltd)(3.24.010)
[PID: 1604][C:\Program Files\Internet Explorer\IEXPLORE.EXE] (Microsoft Corporation)(6.00.2800.1106 (xpsp1.020828-1920))
[C:\WINDOWS\System32\AcSignIcon.dll] (Autodesk)(16.1.63.0)
[C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll] (TechSmith Corporation)(1.0.6)
[C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddinRes.dll] (TechSmith 公司)(1.0.6)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll] (Yahoo!)(2, 1, 8, 1048)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll] (Yahoo! China)(1, 1, 3, 1035)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yaswiper.dll] (Yahoo)(1, 0, 1, 1004)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasiesec.dll] (Yahoo)(1, 0, 2, 1003)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasnoad.dll] ()(1, 1, 4, 1006)
[C:\WINDOWS\System32\SYNCOR11.DLL] (SoundMAX)(1.2.2)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yzsNetProto.dll] (Yahoo)(1, 0, 0, 1)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yrss.dll] (Yahoo! China)(1, 0, 1, 1015)
[C:\WINDOWS\downlo~1\CnsHook.dll] (北京三七二一科技有限公司)(1, 0, 2, 5)
[C:\WINDOWS\system32\RavExt.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 21)
[c:\program files\google\googletoolbar2.dll] (Google Inc.)(3, 0, 131, 0)
[C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll] (TechSmith Corporation)(1.0.1)
gototop
 

[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll] (Yahoo.)(1, 0, 2, 1002)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll] (Yahoo)(1, 0, 2, 1002)
[C:\Program Files\Tencent\qq\QQIEHelper.dll] (深圳市腾讯计算机系统有限公司)(1, 1, 0, 5)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] ()(1, 2, 7, 1006)
[C:\PROGRA~1\FLASHGET\jccatch.dll] (Amaze Soft)(1, 1, 4, 0)
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] ()(2, 0, 2, 1025)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] ( )(2, 0, 1, 1007)
[PID: 1668][C:\WINDOWS\System32\nvsvc32.exe] (NVIDIA Corporation)(6.14.10.4523)
[PID: 1764][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] (Analog Devices, Inc.)(3, 2, 5, 0)
[PID: 1772][C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe] ( )(2, 0, 0, 1001)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] ()(2, 0, 2, 1025)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] ( )(2, 0, 1, 1007)
[PID: 1824][C:\WINDOWS\System32\svchost.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[PID: 1840][C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe] (Ulead Systems, Inc.)(1, 0, 0, 3)
[PID: 1988][D:\Program Files\Rising\Rav\RavStub.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 16)
[D:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
[PID: 552][C:\WINDOWS\Explorer.EXE] (Microsoft Corporation)(6.00.2800.1106 (xpsp1.020828-1920))
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\WINDOWS\System32\AcSignIcon.dll] (Autodesk)(16.1.63.0)
[C:\WINDOWS\downlo~1\CnsHook.dll] (北京三七二一科技有限公司)(1, 0, 2, 5)
[C:\WINDOWS\system32\RavExt.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 21)
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\WINDOWS\System32\upengine.dll] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll] (Autodesk)(16.1.63.0)
[C:\PROGRA~1\3721\helper.dll] ()(1, 0, 9, 1324)
[C:\PROGRA~1\3721\alrex.dll] ()(1, 0, 1, 1001)
[C:\WINDOWS\System32\SYNCOR11.DLL] (SoundMAX)(1.2.2)
gototop
 

[C:\PROGRA~1\3721\autolive.dll] ()(1, 1, 2, 1023)
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] ()(2, 0, 2, 1025)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] ( )(2, 0, 1, 1007)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll] (Yahoo! China)(1, 1, 3, 1035)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL] ()(1, 2, 7, 1006)
[C:\PROGRA~1\FLASHGET\jccatch.dll] (Amaze Soft)(1, 1, 4, 0)
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] (Adobe Systems, Inc.)(7.0.0.0)
[PID: 364][C:\WINDOWS\System32\Rundll32.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\WINDOWS\downlo~1\CnsMinIO.dll] (北京三七二一科技有限公司)(1, 0, 3, 4)
[C:\WINDOWS\downlo~1\cnsio.dll] (北京三七二一科技有限公司)(1, 0, 2, 5)
[PID: 972][C:\Program Files\Analog Devices\SoundMAX\Smtray.exe] (Analog Devices, Inc.)(3, 2, 10, 0)
[C:\WINDOWS\System32\SYNCOR11.DLL] (SoundMAX)(1.2.2)
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[PID: 988][C:\Program Files\Common Files\Real\Update_OB\realsched.exe] (RealNetworks, Inc.)(0.1.0.3208)
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[PID: 996][C:\Program Files\D-Tools\daemon.exe] (DAEMON'S HOME)(3.47.0.0)
[C:\WINDOWS\daemon.dll] (N/A)(3.47.0.0)
[C:\Program Files\D-Tools\PFCTOC.DLL] (Padus(R), Inc.)(1, 0, 0, 12)
[C:\Program Files\D-Tools\Plugins\Images\ccdmount.dll] (GENERIC)(1.02.0.0)
[C:\Program Files\D-Tools\Plugins\Images\mdsmount.dll] (GENERIC)(1.01.0.0)
[C:\Program Files\D-Tools\Plugins\Images\pdimount.dll] (GENERIC)(1.01.0.0)
[C:\Program Files\D-Tools\Plugins\Images\nrgmount.dll] (GENERIC)(1.02.0.0)
[C:\Program Files\D-Tools\Plugins\Images\bw5mount.dll] (N/A)(1.0.2.0)
[C:\PROGRA~1\3721\helper.dll] ()(1, 0, 9, 1324)
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
gototop
 

[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\WINDOWS\System32\SYNCOR11.DLL] (SoundMAX)(1.2.2)
[PID: 1040][C:\WINDOWS\system32\rundll32.exe] (Microsoft Corporation)(5.1.2600.0 (xpclient.010817-1148))
[C:\PROGRA~1\3721\helper.dll] ()(1, 0, 9, 1324)
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\WINDOWS\system32\upengine.dll] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\PROGRA~1\3721\autolive.dll] ()(1, 1, 2, 1023)
[PID: 1128][C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe] ( )(2, 0, 0, 1001)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\PROGRA~1\3721\helper.dll] ()(1, 0, 9, 1324)
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\WINDOWS\System32\upengine.dll] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll] ()(2, 0, 2, 1025)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yalliveex.dll] ( )(2, 0, 1, 1007)
[PID: 1136][C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe] (Yahoo!)(1, 0, 1, 1001)
[C:\PROGRA~1\3721\helper.dll] ()(1, 0, 9, 1324)
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAssecblk.dll] (Yahoo)(1, 0, 2, 1002)
[C:\PROGRA~1\Yahoo!\Assistant\shell\yMenuInfo.dll] (Yahoo)(1, 0, 0, 2)
[C:\PROGRA~1\Yahoo!\Assistant\shell\yIEAngel.dll] (Yahoo)(1, 0, 1, 1001)
[C:\PROGRA~1\Yahoo!\Assistant\shell\yAsMenu.dll] (Yahoo)(1, 0, 1, 1006)
[C:\WINDOWS\System32\upengine.dll] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\WINDOWS\downlo~1\cnsio.dll] (北京三七二一科技有限公司)(1, 0, 2, 5)
[PID: 1152][C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe] (InstallShield Software Corporation)(3, 20, 100, 1123)
[PID: 1176][D:\Program Files\Rising\Rav\RavTask.exe] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 22)
[D:\Program Files\Rising\Rav\RSCOMMON.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 4)
gototop
 

[D:\Program Files\Rising\Rav\RSAPPMGR.DLL] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 2)
[D:\Program Files\Rising\Rav\CfgDll.dll] (Beijing Rising Technology Co., Ltd.)(18, 0, 0, 10)
[D:\Program Files\Rising\Rav\RsCommX.dll] (rising)(18, 0, 0, 1)
[C:\PROGRA~1\3721\helper.dll] ()(1, 0, 9, 1324)
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[PID: 1328][C:\WINDOWS\System32\ctfmon.exe] (Microsoft Corporation)(5.1.2600.1106 (xpsp1.020828-1920))
[C:\PROGRA~1\3721\helper.dll] ()(1, 0, 9, 1324)
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[PID: 1340][C:\Program Files\DTgrafic\BusNotes\b2notes.exe] (DTgrafic GmbH - http://www.dtgrafic.com)(1, 1, 0, 164)
[C:\PROGRA~1\3721\helper.dll] ()(1, 0, 9, 1324)
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[PID: 1476][C:\Program Files\Messenger\msmsgs.exe] (Microsoft Corporation)(4.7.2010)
[C:\PROGRA~1\3721\helper.dll] ()(1, 0, 9, 1324)
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\WINDOWS\System32\SYNCOR11.DLL] (SoundMAX)(1.2.2)
[C:\WINDOWS\System32\msdmo.dll] (N/A)(N/A)
[PID: 1760][C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe] (Adobe Systems Incorporated)(7.0.5.2005092300)
[C:\PROGRA~1\3721\helper.dll] ()(1, 0, 9, 1324)
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[PID: 2768][F:\download\SREng2\SREng.exe] (Smallfrogs Studio)(2.0.21.505)
[C:\PROGRA~1\3721\helper.dll] ()(1, 0, 9, 1324)
[C:\WINDOWS\downlo~1\CnsMin.dll] (北京三七二一科技有限公司)(1, 5, 2, 8)
[C:\PROGRA~1\Yahoo!\ASSIST~1\Yhelper.dll] ()(2, 0, 1, 1018)
gototop
 

[C:\WINDOWS\System32\UNISPIM.IME] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\WINDOWS\System32\upengine.dll] (北京清华紫光软件股份有限公司)(3.0.0.3045)
[C:\WINDOWS\System32\SYNCOR11.DLL] (SoundMAX)(1.2.2)



--------------------------------------------------------------------------------



文件关联

.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\system32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]



--------------------------------------------------------------------------------


Winsock 提供者
gototop
 

日志贴完了,大侠快帮我看看后面怎么办呀
gototop
 

[admin1 / admin1]
(C:\WINDOWS\admin1.exe)(N/A)
鸽子..安全模式...打开注册表编辑器,展开:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
搜索admin1 删除..
删除
C:\WINDOWS\admin1.exe
gototop
 

注册表编辑器在哪儿呀
gototop
 

开始-运行-regedit


http://www.crsky.com/soft/2924.html
下载超级兔子..用超级兔子清理王卸载流氓软件...(安全模式下..)
gototop
 
123   2  /  3  页   跳转
页面顶部
Powered by Discuz!NT