QQ登录

只需一步,快速开始

登录 | 注册 | 找回密码

三维网

 找回密码
 注册

QQ登录

只需一步,快速开始

展开

通知     

全站
10天前
查看: 1509|回复: 3
收起左侧

[求助] 如何删除backdoor.gpigeon.uql病毒

[复制链接]
发表于 2007-1-18 20:08:55 | 显示全部楼层 |阅读模式 来自: 中国河北保定

马上注册,结识高手,享用更多资源,轻松玩转三维网社区。

您需要 登录 才可以下载或查看,没有帐号?注册

x
怎么手工删除backdoor.gpigeon.uql灰鸽子病毒4 Z+ U. x6 ]& G
用hijackthis扫描log如下,请高手帮忙确定哪个是可疑文件,如何手工删除,多谢!: }: f/ [$ c9 y" ^5 e1 y
Logfile of HijackThis v1.99.1
; Y5 v6 W7 ?, A1 k$ {, jScan saved at 19:45:41, on 2007-1-18
& A1 E% x! f4 ZPlatform: Windows XP SP2 (WinNT 5.01.2600)
. s/ S7 }/ I# c6 o1 B. b2 nMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
3 |* }) Y: G, X$ c: W, WRunning processes:
/ _1 K# B4 q; M0 ~7 I( `+ g. H, |+ HC:\WINDOWS\System32\smss.exe, W& U" I: j, v
C:\WINDOWS\system32\winlogon.exe
- V) f+ _4 y8 I* s  I  n% H3 pC:\WINDOWS\system32\services.exe
* i: [  J; A! ^( H2 CC:\WINDOWS\system32\lsass.exe2 b( g. S* X$ Z) x
C:\WINDOWS\system32\svchost.exe
' |" j1 J( a: b/ nD:\SOFTWARE\Rising\Rav\CCenter.exe
. j2 X8 B. L  V, Z3 `6 pC:\WINDOWS\System32\svchost.exe; z* f, j' Z0 e+ X+ X8 B& B
C:\Program Files\Ahead\InCD\InCDsrv.exe6 j3 X$ U7 }/ E3 x+ e' m" f: U
D:\SOFTWARE\Rising\Rav\Ravmond.exe- S# c0 n. R0 R5 T/ p0 o5 {
C:\WINDOWS\Explorer.EXE# D9 V" |$ X) S1 q0 h- N
C:\WINDOWS\system32\spoolsv.exe9 H% J( a. x0 K" ?! t
D:\SOFTWARE\Rising\Rav\RavStub.exe1 a, H* N, N& `$ s; W
D:\SOFTWARE\Rising\Rav\RavTask.exe
# C% v" Y. g! t, i) PC:\Program Files\Common Files\Real\Update_OB\realsched.exe' s: z2 l% `* O
D:\SOFTWARE\Rising\Rav\Ravmon.exe
: Q3 c# s* }) FC:\PROGRA~1\Yahoo!\Assistant\yassistse.exe3 J' n, A. c  Z3 c: T9 V
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe! q$ b# h+ f" t  b% x/ y- G( ~
D:\SOFTWARE\DVD\PowerDVD\PDVDServ.exe
% _5 @  X9 z& LD:\SOFTWARE\Rising\Rav\rav.exe' _+ P$ T1 ^* s. j! z! P* T; s
C:\Program Files\Ahead\InCD\InCD.exe
8 ]. B$ X. }2 B$ c2 \& SD:\SOFTWARE\DVD\fwupdate.exe1 ]1 n, P, `7 S0 l# @6 N
D:\SOFTWARE\Adobe Acrobat 7.0 Professional\Distillr\Acrotray.exe
) |9 m# N, c0 m4 a* ]D:\SOFTWARE\xl\WebThunder.exe
$ v5 I4 c* V# t' V* I" H. I: M; x3 f, SC:\WINDOWS\system32\ctfmon.exe5 A- L6 X( f3 J3 k  }" k4 B
C:\Program Files\Skype\Phone\Skype.exe' x- S& S' }/ x  f( B- W
D:\SOFTWARE\DVD\Multimedia Launcher\PowerBar.exe
5 T2 b/ }8 {& ]8 l7 DC:\WINDOWS\system32\ntvdm.exe1 s6 b- P4 u  n' u' m1 |
C:\Discuz!EXP\MySQL5\bin\mysqld-nt.exe
) E1 w/ A) i* y, L9 A8 Z+ _* U" vC:\Discuz!EXP\Apache2\bin\Apache.exe
" y2 T& C( R! j; UC:\WINDOWS\system32\inetsrv\inetinfo.exe
2 e! h: s" p$ ?  F0 }C:\Discuz!EXP\Apache2\bin\Apache.exe
, s3 _" d" k* b! M; h, gC:\WINDOWS\system32\wscntfy.exe: E1 v% Q) u/ E' r8 n, Z
C:\Program Files\Internet Explorer\iexplore.exe
& i# ]; L5 C& j0 [7 eD:\SOFTWARE\Rising\Rav\RsAgent.exe
1 Z6 M4 S2 u" }! o. \# |; RC:\WINDOWS\msagent\AgentSvr.exe
/ m' C6 ?+ K) G+ ~4 ]C:\TDdownload\HijackThis.exe6 G: X0 X' J/ n5 v$ X/ @
R3 - URLSearchHook: ContextSearch Class - {88351CEF-BAC0-4A9B-8380-31A173E2926F} - C:\PROGRA~1\yok\toolbar.dll
2 ?0 p' \& s7 T2 H4 Q. H" dO2 - BHO: WebThunder Browser Helper - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - D:\SOFTWARE\xl\WebThunderBHO_015.dll
, @1 `/ L9 d  y5 I" E& a7 G1 uO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\SOFTWARE\Adobe Acrobat 7.0 Professional\ActiveX\AcroIEHelper.dll
- N$ J5 k) Y0 O9 x) O$ pO2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll
* O+ w- ^# \2 yO2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll  T3 h1 X3 |2 ?1 U/ G( U
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL9 w  B0 q& `" n% c% h
O2 - BHO: (no name) - {69D23154-CA31-43E9-BEEB-F78E6D1642B3} - C:\WINDOWS\system32\3721.5.dll (file missing)0 c: c1 ?: h, G: `/ U$ n! e
O2 - BHO: 珊瑚虫超级搜索 - {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} - C:\PROGRA~1\yok\toolbar.dll
1 \3 }- \0 b; J; r4 jO2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
9 d' W3 J3 }6 ?8 }* x- bO2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\SOFTWARE\FLASHGET\jccatch.dll
4 T5 H3 G0 R" m7 A. RO2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\SOFTWARE\Adobe Acrobat 7.0 Professional\Acrobat\AcroIEFavClient.dll* V: |& R- ]% Q# J9 k0 l
O2 - BHO: AssistHelper - {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll
+ k, {% C+ u, s, {O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\SOFTWARE\FLASHGET\fgiebar.dll! X- _; e- L) c/ R& k1 Q+ c$ o
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
7 @4 P7 P. r+ F9 mO3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll4 t- q- w* _% w+ B& W0 V! P& X9 W
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
* v/ [) ^! `. E( n* _O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload# ^7 e7 F+ v+ q+ \& n
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName. @! e+ e0 x2 @6 \, I. K
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
* v, F9 f3 C* U/ t7 EO4 - HKLM\..\Run: [RavTask] "D:\SOFTWARE\Rising\Rav\RavTask.exe" -system
$ [1 V. {" @; h1 u2 zO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot. @$ A5 t- s; P5 {2 o8 Q0 b" q
O4 - HKLM\..\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
0 v6 \; a7 B% |) k9 j3 n6 l. HO4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe2 y, a) M+ J3 h* E% j8 b
O4 - HKLM\..\Run: [yok.exe] C:\PROGRA~1\yok\yok.exe
$ s1 T1 r! V7 GO4 - HKLM\..\Run: [SOUNDM] win32smd.exe
2 c0 ]+ w* r) o2 q* vO4 - HKLM\..\Run: [RemoteControl] D:\SOFTWARE\DVD\PowerDVD\PDVDServ.exe) {! V9 ^- J# o. M& k
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe" f1 _5 v2 `+ I6 v
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe) ~2 \& a* f5 x) W+ ]
O4 - HKLM\..\Run: [LGODDFU] D:\SOFTWARE\DVD\fwupdate.exe- h6 }6 G5 G- K
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\SOFTWARE\Adobe Acrobat 7.0 Professional\Distillr\Acrotray.exe") ^/ |5 U9 U4 E: o8 Q
O4 - HKLM\..\Run: [WebThunder] D:\SOFTWARE\xl\WebThunder.exe0 s. Z: V7 e! R# M+ V
O4 - HKLM\..\RunOnce: [RavStub] "D:\SOFTWARE\Rising\Rav\ravstub.exe" /RUNONCE
  {' n: a% D9 [0 I; C. iO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
0 U" w8 v4 W  V( W: r6 BO4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized" f& l7 T4 h, g, \" L! o. a8 j
O4 - HKCU\..\Run: [PowerBar] "D:\SOFTWARE\DVD\Multimedia Launcher\PowerBar.exe" /AtBootTime  ^/ L9 T" e9 A% Z* ]8 h! i
O4 - HKCU\..\Run: [ravshelll] C:\Progra~1\Eset\eexplore.exe
* X  g1 }/ c7 A- J" n! ?6 G' v7 c* tO4 - HKCU\..\Run: [myZt2] C:\DOCUME~1\zq\LOCALS~1\Temp\Zt2\SVCH0ST.EXE
, o4 c0 p3 d! @' x' X1 r6 [; GO4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE: n5 r8 ]; t/ f& D6 [% @" ~
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?SystemRoot%\Installer\{AC76BA86-2052-0000-7760-100000000002}\SC_Acrobat.exe
* N3 q) v/ w7 cO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
- Z6 f4 Z2 Z4 G......( m4 C# p' I( A3 W! J* m1 o( C
O14 - IERESET.INF: SEARCH_PAGE_URL=
! j% I, _9 I1 ^8 T6 M) W2 XO14 - IERESET.INF: START_PAGE_URL=& G) V' w" q+ N5 d. c" d% y
O17 - HKLM\System\CCS\Services\Tcpip\..\{84AB81AF-1D7F-447B-A14C-35F18C721F58}: NameServer = 202.99.160.68 202.99.166.4# j- ?+ I  c0 H8 ?. v& b! p
O21 - SSODL: AdobePDF - {D92D666A-0F7B-5892-A7E8-29340333F07E} - c:\program files\internet explorer\PLUGINS\nppdf.dll (file missing)2 m; p. m  K) ^
O23 - Service: Discuz!EXP-DBS - Unknown owner - C:\Discuz!EXP\MySQL5\bin\mysqld-nt.exe7 e3 f( V$ e+ s$ U7 o+ l8 z) |! Q
O23 - Service: Discuz!EXP-WEB - Unknown owner - C:\Discuz!EXP\Apache2\bin\Apache.exe" -k runservice (file missing)) r" ~5 b/ a- G, P5 `. s
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
% w% Y* N# R% z; ^O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\SOFTWARE\Rising\Rav\CCenter.exe
0 c% r' Y% Z' C) vO23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\SOFTWARE\Rising\Rav\Ravmond.exe
9 h3 Y( V7 I# Z# MO23 - Service: Windows XP Vista         - Unknown owner - C:\WINDOWS\Hacker.com.cn.ini
2 v5 x3 B/ \, r/ Y  X- p/ M  |- C/ Z+ X
[ 本帖最后由 bdblbyq 于 2007-1-18 20:13 编辑 ]
发表于 2007-1-18 20:16:42 | 显示全部楼层 来自: 中国河南焦作
你是怎么做的,我用赛门铁克在安全模式下搞玩后重启就可以了.
 楼主| 发表于 2007-1-18 21:22:35 | 显示全部楼层 来自: 中国河北保定
原帖由 michelzz 于 2007-1-18 20:16 发表
& F9 V5 b- ^, v& ?- m& {. D. ]你是怎么做的,我用赛门铁克在安全模式下搞玩后重启就可以了.

' Q+ p' A5 |. w: f$ R2 W  x我不会做,所以才求助的 * M# g! e/ x" g# i9 C2 e
网上搜索,说用hijackthis扫描,找到可疑服务,然后在安全模式下修改注册表,再删除文件什么的。可哪个是可疑文件呢?" F% C  a# h* d5 M
' L3 I3 @) B4 g% O* ^
[ 本帖最后由 bdblbyq 于 2007-1-18 21:24 编辑 ]
发表于 2007-1-18 22:36:32 | 显示全部楼层 来自: 中国浙江杭州
一般的杀毒软件都可以清除
3 k* e1 c1 R9 U6 u8 e不建议手动
发表回复
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Licensed Copyright © 2016-2020 http://www.3dportal.cn/ All Rights Reserved 京 ICP备13008828号

小黑屋|手机版|Archiver|三维网 ( 京ICP备2023026364号-1 )

快速回复 返回顶部 返回列表