1   1  /  1  页   跳转

灰鸽子,又是灰鸽子,求救!

灰鸽子,又是灰鸽子,求救!

我那天中了灰鸽子,用瑞星杀了后,每次启动都有个Backdoor.Gpigeon.5.bn存在于IEXPLORE.EXE里面,请问各位高手如何才能彻底根除啊???小弟感激不尽~~~
最后编辑2005-07-28 20:24:38
分享到:
gototop
 

用HijackThis扫描日志结果如下:
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\Servesr.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee Framework 服务 (McAfeeFramework) - Unknown owner - (no file)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
gototop
 

以下修复工作中有关操作方法可参考:
【推荐】反浏览器劫持的一些常用操作
http://forum.ikaka.com/topic.asp?board=67&artid=6490491

以安全模式启动

停止并禁用服务:Gray_Pigeon_Server (GrayPigeonServer)

请关闭所有浏览器窗口和文件夹窗口,重新使用HijackThis扫描,在下列建议修复的项目前打上勾,然后点[修复](Fix):

O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\Servesr.exe

O23 - Service: McAfee Framework 服务 (McAfeeFramework) - Unknown owner - (no file)

设置系统显示所有文件和文件夹,不隐藏已知文件类型扩展名

找到并删除:C:\WINDOWS\Servesr.exe


请参考:

baohe版主贴:

关于查杀“灰鸽子2005”的一点建议
http://forum.ikaka.com/topic.asp?board=28&artid=6202404

灰鸽子2005手工查杀方法总结
http://forum.ikaka.com/topic.asp?board=28&artid=5666824
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT