瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 电脑中了杀不掉的灰鸽子病毒(高手来帮看下,谢谢)

1   1  /  1  页   跳转

电脑中了杀不掉的灰鸽子病毒(高手来帮看下,谢谢)

电脑中了杀不掉的灰鸽子病毒(高手来帮看下,谢谢)

电脑中了病毒 我用瑞星最新版的杀,每次多说杀掉了
但一重启 还是有。郁闷 高手帮我解决一下
电脑信息和日志:
文件名:IEXPLORE.EXE
文件路径:c;\program files\internet explorer\IEXPLORE.EXE
病毒名:Backdoor.Gpigeon.uql
HijackThis@Qoo的扫描日志  V1.97.7
Scan saved at 1:07:44, on 2007-10-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\杀毒软件\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
D:\杀毒软件\RISING\RAV\Ravmond.exe
d:\杀毒软件\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
D:\杀毒软件\RISING\RAV\RavStub.exe
C:\WINDOWS\Explorer.EXE
d:\杀毒软件\rising\rfw\RfwMain.exe
C:\Program Files\SigmaTel\SigmaTel AC97 音频驱动器\stacmon.exe
C:\WINDOWS\system32\hkcmd.exe
D:\杀毒软件\Rising\Rav\RavTask.exe
D:\杀毒软件\Rising\Rav\Ravmon.exe
D:\应用软件\abode reader 8.1.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Administrator\桌面\HijackThis.exe
C:\WINDOWS\system32\高清.韩剧.小孩.珍藏.幼女.教室.医生.流行.可爱.大学.野外.名模.动漫.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe

O2 - BHO: (no name) - RsAutorunsDisabled - (no file)
O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - D:\
O2 - BHO: ThunderBHO - {06849E9E-C8D7-4D59-B87D-784B7D6BE0B3} - D:\
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: ????? - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [RavTask] "D:\
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O4 - Startup: sys_log_262289479.upt
O8 - Extra context menu item: &Dict.CN Definition - http://dict.cn/rightclick.html
O8 - Extra context menu item: 使用迅雷下载 - D:\
O8 - Extra context menu item: 使用迅雷下载全部链接 - D:\
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\
O8 - Extra context menu item: 添加到QQ表情 - D:\
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (EditCtrl Class) - https://img.alipay.com/download/1101/aliedit.cab
O16 - DPF: {C661F36D-DF85-4EF4-83C7-E107B83D04B1} (WebActivater Control) - http://dl_dir.qq.com/3dshow/3DShowVM.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (PasswordEditCtrl Class) - https://password.qq.com/download/qqedit2.cab
O16 - DPF: {EC0978ED-24E3-403C-AB7A-060E388553E6} (BoBoControl Class) - http://www.88044.com/BoBo_ActiveX_V3.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{3598B2CE-6EC1-4C20-B94C-CA67709F27E7}: NameServer = 218.30.19.40,61.134.1.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{3598B2CE-6EC1-4C20-B94C-CA67709F27E7}: NameServer = 218.30.19.40,61.134.1.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{3598B2CE-6EC1-4C20-B94C-CA67709F27E7}: NameServer = 218.30.19.40,61.134.1.4



附件附件:

下载次数:129
文件类型:application/octet-stream
文件大小:
上传时间:2007-10-13 1:36:04
描述:

最后编辑2007-10-13 10:11:50
分享到:
gototop
 

把临时文件清理了,再安全模式杀病毒,顺便清理下系统有没有可以软件之类的。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT