瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 我有会鸽子``大家帮我看看是哪个````

12   1  /  2  页   跳转

我有会鸽子``大家帮我看看是哪个````

我有会鸽子``大家帮我看看是哪个````

Logfile of HijackThis v1.99.1
Scan saved at 20:22:49, on 2005-11-22
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\services.exe
D:\Program Files\CNNIC\Cdn\cdnup.exe
D:\WINDOWS\System32\NTdhcp.exe
D:\WINDOWS\SOUNDMAN.EXE
D:\WINDOWS\System32\conime.exe
D:\WINDOWS\System32\RUNDLL32.EXE
D:\WINDOWS\System32\ctfmon.exe
D:\迅雷5\Thunder.exe
D:\Program Files\zsxz\UrlService.exe
D:\Program Files\zsxz\IEUrldrive.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\System32\nvsvc32.exe
D:\security\Server\Server.exe
D:\迅雷5\iPlayIssue.exe
D:\WINDOWS\System32\wuauclt.exe
e:\瑞星杀毒\rising\rising\rfw\rfwsrv.exe
D:\WINDOWS\Explorer.exe
D:\TT\TTraveler.exe
D:\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe 1
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - D:\WINDOWS\System32\xunleibho_v8.dll
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - D:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - D:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] "D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Thunder] "D:\迅雷5\ThunderShell.exe" /s
O4 - HKLM\..\Run: [CdnCtr] D:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [MoveSearch] D:\Program Files\wsearch\Search.exe
O4 - HKLM\..\Run: [Security] D:\security\Server\Server.exe
O4 - HKLM\..\Run: [!!!SecurityUpdate] D:\security\Server\Upload.exe
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe D:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [rundll32] D:\WINDOWS\System32\SHELLEXT\svchs0t.exe
O4 - HKLM\..\Run: [Torjan Program] D:\WINDOWS\services.exe
O4 - HKLM\..\Run: [NTdhcp] D:\WINDOWS\System32\NTdhcp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RfwMain] "E:\瑞星杀毒\Rising\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &使用迅雷下载 - D:\迅雷5\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\迅雷5\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\QQ\SendMMS.htm
O8 - Extra context menu item: 访问通用网址 - D:\Program Files\CNNIC\Cdn\cnnic.htm
O9 - Extra button: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - D:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - D:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O10 - Unknown file in Winsock LSP: d:\windows\system32\cdnns.dll
O11 - Options group: [!CNS]  网络实名
O11 - Options group: [CDNCLIENT]  中文上网
O17 - HKLM\System\CCS\Services\Tcpip\..\{5F94A6D1-B519-46BA-BF89-37B9387AF335}: NameServer = 202.103.44.5,202.103.0.117
O20 - AppInit_DLLs: 49400AppInit.DLL
O23 - Service: Download Service - Unknown owner - D:\WINDOWS\System32\SeedServ.exe
O23 - Service: Event Client - Unknown owner - D:\Program Files\zsxz\UrlService.exe
O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - D:\WINDOWS\G_Server.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Corporation Limited - e:\瑞星杀毒\rising\rising\rfw\rfwsrv.exe

帮我啊大家``
最后编辑2005-11-22 20:53:01
分享到:
gototop
 

O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - D:\WINDOWS\G_Server.exe
这个就是鸽子,干掉他
gototop
 

怎么干啊`我的瑞星怎么启动不鸟啊```
gototop
 

O23 - Service: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - D:\WINDOWS\G_Server.exe
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\GrayPigeonServer]
"Type"=dword:00000110
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"DisplayName"="Gray_Pigeon_Server"
"ObjectName"="LocalSystem"
"Description"="灰鸽子服务端程序。远程监控管理."

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\GrayPigeonServer\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\GrayPigeonServer\Enum]
"0"="Root\\LEGACY_GRAYPIGEONSERVER\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
gototop
 

删除Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - D:\WINDOWS\G_Server.exe注册表项,停止其服务,然后重启到安全模式,设置显示全部文件,删除其文件,一般是三个文件!
gototop
 

用手动杀毒
gototop
 

看不懂啊``
gototop
 

注册表项怎么打开?
gototop
 

在运行里输入regedit,进去查找Gray_Pigeon_Server和G_Server.exe,把找到的都删除,重起电脑,进入安全模式,显示全部文件,然后删除他再windows文件夹的文件
gototop
 

1.开始->运行->regedit
查找G_Server.exe->删除,查找GrayPigeonServer->删除
2.将 C:\WINDOWS\G_Server.exe、C:\WINDOWS\G_Server.DLL、C:\WINDOWS\G_Server_Hook.DLL、C:\WINDOWS\G_ServerKey.DLL 删除。
3.删除完后,删除在你的C盘的 c:\!Submit 文件夹。
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT