我的电脑也感染灰鸽子病毒了,,(病毒名称是Backdoor.GPigeon.up )
用瑞星杀完,在开电脑又出来了,我下边发的是日志报告吗/希望电脑高手帮帮忙!在此万分感谢!
自启动项
HKEY_LOCAL_MACHINE Software\Microsoft\Windows\Currentversion\Run
IMJPMIG8.1 = "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
PHIME2002ASync = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
SoundMan = SOUNDMAN.EXE
IgfxTray = C:\WINDOWS\system32\igfxtray.exe
HotKeysCmds = C:\WINDOWS\system32\hkcmd.exe
SysExplr = C:\Program Files\Herosoft\Hero 9\SysExplr.EXE
StormCodec_Helper = "D:\我的工具\播放软件\暴风影音\Storm Codec\StormSet.exe" /S /opti
MINI_BFYY = D:\我的工具\播放软件\暴风影音\Storm Downloader\StormDownloader.exe
RavTimer = D:\我的工具\系统工具\瑞星杀~1\瑞星杀~1\RISING\RAV\RAVTIMER.EXE
RavMon = D:\我的工具\系统工具\瑞星杀~1\瑞星杀~1\RISING\RAV\RAVMON.EXE -SYSTEM
RfwMain = "D:\我的工具\系统工具\瑞星杀毒软件\瑞星防火墙\Rising\Rfw\rfwmain.exe" -Startup
helper.dll = C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
HKEY_CURRENT_USER Software\Microsoft\Windows\Currentversion\Run
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
shell32.dll = C:\WINDOWS\system32\ctfmon.exe
HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\ShellService
ObjectDelayLoad
PostBootReminder = %SystemRoot%\system32\SHELL32.dll
CDBurn = %SystemRoot%\system32\SHELL32.dll
WebCheck = %SystemRoot%\system32\webcheck.dll
SysTray = C:\WINDOWS\system32\st
object.dll
HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
%SystemRoot%\system32\browseui.dll= Browseui 预加载程序
%SystemRoot%\system32\browseui.dll= 组件类别缓存程序
SYSTEM.INI BOOT SHELL Explorer.exe
SYSTEM.INI BOOT SCRNSAVE.EXE C:\WINDOWS\system32\ssmyst.scr
其他相关项
HKEY_LOCAL_MACHINE Software\Microsoft\Windows NT\CurrentVersion\Winlogon DefaultUserName ----> Administrator
HKEY_LOCAL_MACHINE Software\Microsoft\Windows NT\CurrentVersion\Winlogon AltDefaultUserName ----> Administrator
HKEY_LOCAL_MACHINE Software\Microsoft\Windows NT\CurrentVersion\Winlogon Userinit ----> C:\WINDOWS\system32\userinit.exe,
Hosts
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
进程列表
[System Process]
System
C:\WINDOWS\SOUNDMAN.EXE (Made by Realtek Semiconductor Corp.)
D:\我的工具\播放软件\暴风影音\Storm Downloader\StormDownloader.exe (Made by 深圳市三代科技开发有限公司)
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
d:\我的工具\系统工具\瑞星杀毒软件\瑞星防火墙\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Herosoft\Hero 9\SysExplr.EXE
D:\我的工具\系统工具\瑞星杀~1\瑞星杀~1\RISING\RAV\RAVTIMER.EXE
D:\我的工具\系统工具\瑞星杀毒软件\瑞星防火墙\Rising\Rfw\rfwmain.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
D:\我的工具\系统工具\瑞星杀毒软件\瑞星杀毒程序\RISING\RAV\CCENTER.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\conime.exe
D:\我的工具\系统工具\瑞星杀毒软件\瑞星杀毒程序\RISING\RAV\Ravmond.exe
D:\我的工具\系统工具\瑞星杀毒软件\瑞星杀毒程序\RISING\RAV\RavStub.exe
d:\我的工具\系统工具\瑞星杀毒软件\瑞星杀毒程序\rising\rav\RAVMON.EXE
D:\我的工具\系统工具\瑞星听诊器\RavDetect.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
进程详细信息
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\xunleibho_v4.dll
ulWj@Y
90u29p
90u29p
90u29p
@@AAf91u
PSVSSSW
PPPPPPPQPPP
SPSSSSSS
t%8^lt 9^x
TYPELIB
Delete
NoRemove
ForceRemove
--------------------------------------------------
--------------------------
---------------------------
Cookie
---------------------------
------------------------------
.?AVC
Object@@
.?AV?$CArray@UHyperLinkInfoITEM@CHyperLinkInfo@@AA
.?AVCHyperLinkInfo@@
thunder://
Software\Sandai Technologies Inc.\Thunder\Paramete
MMThunder
MutexThunder
UM_SWITCH_INST
.?AVCInstanceManager@@
Thunder.exe"
MainAppPath
.?AVCLinerRegKey@@
.?AVCMonitorFile@@
Software\Sandai Technologies Inc.\Thunder\Paramete
Config_Monitor
MonitoringIE
\Thunder.ini
IESuffixs
.asf;.avi;.exe;.iso;.mp3;.mpeg;.mpga;.ra;.rar;.rm;
CallThunder
#*05#*
#*04#*
#*03#*
#*02#*
#*01#*
#32770
thunder
IsInvalid
Software\Sandai Technologies Inc.\ThunderOem\
mmst://
mms://
https://
http://
ftp://
.?AVCOemSeq@@
ThunderOemArray
Software\Sandai Technologies Inc.\ThunderOem
IsMiniVer
-----------------
----------------
-------------------
----------------
OnDragEnter
Cookie
.?AVCCmdTarget@@
.?AVCWinThread@@
.?AVCWinApp@@
.?AVCXunleibhoApp@@
----------------------------Load BHO Dll----------
----------------------------Unload BHO Dll--------
.?AV?$CCom
ObjectCached@VCComClassFactory@ATL@@@ATL
.?AVCCom
ObjectRootBase@ATL@@
.?AV?$CCom
ObjectRootEx@VCComMultiThreadModel@ATL@@
.?AUIUnknown@@
.?AUIClassFactory@@
.?AVCComClassFactory@ATL@@
.?AUI
ObjectWithSite@@
.?AV?$I
ObjectWithSiteImpl@VCThunderIEHelper@@@ATL@
.?AUIDispatch@@
.?AUIThunderIEHelper@@
.?AV?$IDispatchImpl@UIThunderIEHelper@@$1?IID_IThu
.?AV?$CComCoClass@VCThunderIEHelper@@$1?CLSID_Thun
.?AV?$CCom
ObjectRootEx@VCComSingleThreadModel@ATL@
.?AVCThunderIEHelper@@
.?AV?$CCom
Object@VCThunderIEHelper@@@ATL@@
CThunderIEHelper()
.?AUIDownloadManager@@
.?AV?$CComCoClass@VCDownloadManager@@$1?CLSID_Down
.?AVCDownloadManager@@
.?AV?$CCom
Object@VCDownloadManager@@@ATL@@
.?AV?$CComAgg
Object@VCDownloadManager@@@ATL@@
.?AV?$I
ObjectWithSiteImpl@VCCatchRightClick@@@ATL@
.?AUICatchRightClick@@
.?AV?$IDispatchImpl@UICatchRightClick@@$1?IID_ICat
.?AV?$CComCoClass@VCCatchRightClick@@$1?CLSID_Catc
.?AVCCatchRightClick@@
.?AV?$CCom
Object@VCCatchRightClick@@@ATL@@
CThunderIEHelper Create
=sR]1t
.?AV?$CComAgg
Object@VCThunderIEHelper@@@ATL@@
.?AV?$CComContained
Object@VCThunderIEHelper@@@ATL@
.?AV?$CComContained
Object@VCDownloadManager@@@ATL@
.?AV?$CComContained
Object@VCCatchRightClick@@@ATL@
.?AV?$CComAgg
Object@VCCatchRightClick@@@ATL@@
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
UnRegisterTypeLib
oleaut32.dll
.?AV_com_error@@
.?AVCNoTrack
Object@@
.?AVAFX_MODULE_STATE@@
.?AV_AFX_DLL_MODULE_STATE@@
.?AVtype_info@@
REGISTRY
Module
C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL
SUVWPQ
D$ ,pL
PQhPpL
\$Ht-W
L$@_^][d
L$,PQQ
D$@PWUV
Apartment
ThreadingModel
CLSID\%s
CLSID\%s\InprocServer32
Interface
TypeLib
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
%%%2.2X
Internet Explorer_Server
{62EED7C6-9F02-42f9-B634-98E2899E147B}
YDragSearch
DragSearch
selsearch
Software\Yahoo\Assistant\Assist
mailto:%s
mailto:
SetWindowTheme
UxTheme.dll
DRAGWNDINFO
DragWnd
DragSearch_Main
ToolbarWindow32
http://www.yisou.com/search?source=toolbar_yassist
http://www.yisou.com/search?source=toolbar_yassist
selsearchie
dragdrop
.?AV_com_error@@
.?AVtype_info@@
C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL
REGISTRY
Module
XAction
D:\我的工具\播放软件\暴风影音\Storm Downloader\StormDownloader.exe
D:\我的工具\播放软件\暴风影音\Storm Downloader\StormDownloader.exe (made by 深圳市三代科技开发有限公司)
SUVWh^
D$$U+D$ P
D$(+D$ P
L$(_^]d
j WWWj
SSSSShH
tQ9^,uLj
j PPPj
QQSVW3
t%8^lt 9^x
SVHWt+-
90u29p
j7SSSSS
RQQWRRRj
~TWh0LH
BQPjJP
QSUVWj
F$_^][Y
QQSUVW
_^][YY
jCPPPPPV
GTFSPV
tnHtdHtZHtPHtF
tgHt`HtVHtLHtP
Yt89~(
;0t-9u
WVVVVj
8A|J9u
QSSSSSSSP
F8t4j(
YPht)J
YPhL)J
YPh()J
YPht(J
YPhT(J
YPh`+J
YPhL+J
YPh@+J
YPh0+J
YPh +J
L$0_^][d
YPhh-J
YPh`,J
YPhH,J
YPh,/J
YPh$/J
YPhx.J
YPhd.J
YPh\.J
YPhL.J
YPh4.J
YPh .J
YPh\/J
tDh8/J
YPh8/J
YPh,/J
YPh,0J
YPh,/J
YPh$/J
YPh\0J
YPht+J
YPhX1J
YPhD2J
YPh02J
YPhD2J
YPh02J
YPh,4J
YPhd4J
YPhP4J
YPh@6J
YPh|5J
YPh`5J
YPhH5J
YPh45J
YPh02J
YPhl6J
YPhX6J
YPh 8J
YPhp+J
YPh8;J
YPh$;J
~$XPWS
9FDtf9F@
YPhX=J
YPhD=J
YPh8=J
YPh(=J
YPh,/J
YPhx.J
YPhd.J
YPhh=J
YPh\.J
L$ _^][d
YPh$/J
YPh\@J
YPhP@J
YPhL@J
YPhH@J
YPh@@J
YPh0@J
tA8]$t
YPhDBJ
YPh(CJ
YPhDDJ
PVh TC
YPhpEJ
YPh|HJ
YPh@IJ
YPh4IJ
YPh IJ
YPhtIJ
YPhhIJ
YPh|JJ
YPh\JJ
YPhHJJ
YPh8JJ
YPh0JJ
YPh(JJ
YPh\JJ
YPhHJJ
YPh\%J
YPhTKJ
~4;~8t
~d9~du
9_8uW9_@uR
tC9FTt
8A]u$8D$
u!8AIt
Ad9Qpt
YPhlRJ
YPhPSJ
YPhHSJ
YPh@SJ
YPh@TJ
YPh4TJ
u[FFGG9u
9 t%9u
YPh(ZJ
8A|G9u
8A|J9u
8A|J9u
$8^Ht$
L$ _^][d
YPh|iJ
YPh,/J
L$ _^][d
YPh$/J
N,tDj
8^:u"8^9t
F0;F4~
t}@C;F
uv@C;F
99u&9H
D$$RPQ
L$P_^][d
L$x_^][d
L$0_^][d
L$hPWV
tu;D$ wo
sGRPSS
;~ tBS
;~ t0S
;~ t4S
U8;UPw
U4;ULs
EP9E w
u ;uPw
EP9E8w
EL9E4s
9U(rX;
~(;~,t0
w(;w,t
~(;~,t=
w(;w,t
w(;w,t
vH;N|sC
w(;w,t
~(;~,t
;s,tQW
s(;s,t1
~(;~,th
~(;~,t
w(;w,t
w(;w,t