瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 请教baohe我的日志里哪个是病毒,谢谢【求助】

1   1  /  1  页   跳转

请教baohe我的日志里哪个是病毒,谢谢【求助】

请教baohe我的日志里哪个是病毒,谢谢【求助】

O23 - NT 服务: Autodesk Licensing Service - Autodesk, Inc. - D:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - NT 服务: C-DillaCdaC11BA - Macrovision - D:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - NT 服务: C-DillaSrv - C-Dilla Ltd - D:\WINNT\System32\DRIVERS\CDANTSRV.EXE
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - NT 服务: Explorer - Unknown owner - D:\WINNT\NTServer.exe (file missing)
O23 - NT 服务: Gray_Pigeon_Server2.0 (GrayPigeonServer2.0) - Unknown owner - D:\WINNT\G_Server2.0.exe
O23 - NT 服务: Groove Installer Service (GrooveInstallerService) - Groove Networks, Inc. - D:\Program Files\Groove Networks\Groove\Bin\GrooveInstallerService.exe
O23 - NT 服务: Kingsoft AntiVirus Service (KAVSvc) - kingsoft Antivirus - D:\KAV6\KAVSvc.EXE
O23 - NT 服务: MEls - Unknown owner - D:\Program Files\CoCreate\MEls\MEls.exe
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - D:\WINNT\System32\nvsvc32.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - d:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - NT 服务: SDserver11.60.0.13 - CoCreate Software GmbH - D:\PROGRA~1\CoCreate\OSD_MO~1.13\binNT\SDserver.exe
O23 - NT 服务: Windows Support Center (SupportSvc) - Unknown owner - D:\WINNT\SupportSvc.exe (file missing)
O23 - NT 服务: svchost.exe - Unknown owner - D:\WINNT\svchost.exe
O23 - NT 服务: Unigraphics Plot Server (ugiipqd) (ugiipqd) - Unigraphics Solutions, Inc - D:\WINNT\system32\spool\ugplot\ugiipqd.exe
O23 - NT 服务: Unigraphics License Server (uglmd) - Macrovision Corporation - D:\Program Files\EDS\License Servers\UGNXFLEXlm\lmgrd.exe

最后编辑2005-11-03 21:54:29
分享到:
gototop
 

O23 - NT 服务: svchost.exe - Unknown owner - D:\WINNT\svchost.exe
)
O23 - NT 服务: Gray_Pigeon_Server2.0 (GrayPigeonServer2.0) - Unknown owner - D:\WINNT\G_Server2.0.exe

gototop
 

O23 - NT 服务: Explorer - Unknown owner - D:\WINNT\NTServer.exe (file missing)
O23 - NT 服务: Gray_Pigeon_Server2.0 (GrayPigeonServer2.0) - Unknown owner - D:\WINNT\G_Server2.0.exe
O23 - NT 服务: Windows Support Center (SupportSvc) - Unknown owner - D:\WINNT\SupportSvc.exe (file missing)
O23 - NT 服务: svchost.exe - Unknown owner - D:\WINNT\svchost.exe
比较历害,四个鸽子,两个杀掉了,还有两个。
gototop
 

O23 - NT 服务: Explorer - Unknown owner - D:\WINNT\NTServer.exe (file missing)
O23 - NT 服务: Windows Support Center (SupportSvc) - Unknown owner - D:\WINNT\SupportSvc.exe (file missing)
将这两个直接修复

O23 - NT 服务: Gray_Pigeon_Server2.0 (GrayPigeonServer2.0) - Unknown owner - D:\WINNT\G_Server2.0.exe

打开注册表,定位到
HKEY_LOCAL_MACHINE\ SYSTEM \ CURRENTCONTROLSET \ SERVICES
将左拦中的病毒服务名Gray_Pigeon_Server2.0删除
重新启动机器
显示系统文件,显示所有文件及文件夹,找到
G_Server2.0.exe
G_Server2.0.dll
G_Server2.0_hook.dll
G_Server2.0Key.dll
将能找到的都删除.

还有这一只
O23 - NT 服务: svchost.exe - Unknown owner - D:\WINNT\svchost.exe
方法相同:
打开注册表,定位到
HKEY_LOCAL_MACHINE\ SYSTEM \ CURRENTCONTROLSET \ SERVICES
将左拦中的病毒服务名svchost.exe 删除
重新启动机器
显示系统文件,显示所有文件及文件夹,找到
svchost.exe
svchost.dll
svchost_hook.dll
svchostKey.dll
将能找到的都删除.
gototop
 

【回复“bobo无极限”的帖子】
但前面有HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_GRAYPIGEONSERVER2.0
是这项吗
gototop
 

引用:
【zzz21的贴子】【回复“bobo无极限”的帖子】
但前面有HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_GRAYPIGEONSERVER2.0
是这项吗
...........................


不大明白,这是按照版主的思路做的.

从没中过鸽子,所以也不知道现场到底是什么样.
gototop
 

挖 楼住  你家养鸽子的啊?
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT