1   1  /  1  页   跳转

【求助】关于灰鸽子

【求助】关于灰鸽子

机子中了灰鸽子  金山毒霸的病毒名为Win32.Hack.Huigezi.ki.52736
一进系统就让 金山毒霸给删了
每次进系统都是杀毒提示
现在隔离区里都是G_ServerKey.DLL

求解决方法???????????
扫描如下::
Logfile of HijackThis v1.99.0
Scan saved at 19:51:05, on 2006-1-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
D:\金山毒霸\KAVSvc.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
D:\PerfectDisk\PerfectDisk V7.0\PDSched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
D:\金山毒霸\KWatchUI.EXE
D:\金山毒霸\KpopMon.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\3721\assistse.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
D:\金山毒霸\MailMon.EXE
D:\金山毒霸\KAVPlus.EXE
D:\金山毒霸\KAVPFW.EXE
D:\讯雷V5\Thunder.exe
D:\GreenBrowserGB\GreenBrowser.exe
C:\WINDOWS\system32\dllhost.exe
E:\新建文件夹\HijackThis.exe

R3 - URLSearchHook: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\Program Files\3721\Assist\asbar.dll
O2 - BHO: NaviHelperObj Class - {3E422F49-1566-40D3-B43D-077EF739AC32} - C:\WINDOWS\system32\NaviHelper.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\QQ 2006ip\Tencent\QQIEHelper.dll
O3 - Toolbar: 金山毒霸 - {A9BE2902-C447-420A-BB7F-A5DE921E6138} - D:\金鹕山蕉毒景霸診\KAIEPlus.DLL (file missing)
O3 - Toolbar: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\Program Files\3721\Assist\asbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [KAVRun] D:\金山毒霸\KAVRun.EXE
O4 - HKLM\..\Run: [Kulansyn] D:\金山毒霸\Kulansyn.EXE
O4 - HKLM\..\Run: [KpopMon] D:\金山毒霸\KpopMon.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [assistse] "C:\PROGRA~1\3721\assistse.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iDuba Personal FireWall] D:\金山毒霸\KAVPFW.EXE
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [iDuba Personal FireWall] D:\金山毒霸\KAVPFW.EXE
O8 - Extra context menu item: &使用迅雷下载 - D:\讯雷V5\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\讯雷V5\getallurl.htm
O8 - Extra context menu item: Download with &Shareaza - res://D:\BT 86_7.0\Plugins\RazaWebHook.dll/3000
O8 - Extra context menu item: 使用网际快车下载 - D:\网际快车(FlashGet) V1.65\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - D:\网际快车(FlashGet) V1.65\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ 2005ip\qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\QQ 2005ip\qq\SendMMS.htm
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\QQ 2006ip\Tencent\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\QQ 2006ip\Tencent\QQIEHelper.dll
O11 - Options group: [!CNS]  上网助手-地址栏搜索
O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} (V3ProX Control) - http://origin-www.ahn.com.cn/aspservice/plugin/myv3.cab
O16 - DPF: {9BDBC41E-C335-4263-83C0-ECE78EE28A33} (SysMonOCX Control) - http://auth70.ahn.com.cn/myv32006/plugin/myfirewall20.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{47389CE6-6B84-4BDC-BF30-B4A7C3C5F2FD}: NameServer = 202.100.192.68 202.100.199.8
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Kingsoft AntiVirus Service - kingsoft Antivirus - D:\金山毒霸\KAVSvc.EXE
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PDEngine - Raxco Software, Inc. - D:\PerfectDisk\PerfectDisk V7.0\PDEngine.exe
O23 - Service: PDScheduler - Raxco Software, Inc. - D:\PerfectDisk\PerfectDisk V7.0\PDSched.exe
最后编辑2006-01-20 19:58:07
分享到:
gototop
 

杀软报的病毒文件的路径是???
gototop
 

现在进系统还有提示?
gototop
 

进系统就有杀毒提示
就是那G_ServerKey.DLL
路径为C:\WINDOWS\G_SERVERKEY.EXE
gototop
 

天呀
没人了
gototop
 


你用G_SERVERKEY.EXE在注册表里查找一下~~
看看能否有什么发现~~`
gototop
 

另,可以再试着关闭IE等不必要的程序后,清空临时文件夹,关闭系统还原~~
再重启系统看看~~~

gototop
 

到这里看看。应该有所帮助的。http://www.yesky.com/searchsecurity/505532391066959872/20050224/1914508_2.shtml
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT