|
马上注册,结识高手,享用更多资源,轻松玩转三维网社区。
您需要 登录 才可以下载或查看,没有帐号?注册
x
怎么手工删除backdoor.gpigeon.uql灰鸽子病毒4 Z+ U. x6 ]& G
用hijackthis扫描log如下,请高手帮忙确定哪个是可疑文件,如何手工删除,多谢!: }: f/ [$ c9 y" ^5 e1 y
Logfile of HijackThis v1.99.1
; Y5 v6 W7 ?, A1 k$ {, jScan saved at 19:45:41, on 2007-1-18
& A1 E% x! f4 ZPlatform: Windows XP SP2 (WinNT 5.01.2600)
. s/ S7 }/ I# c6 o1 B. b2 nMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
3 |* }) Y: G, X$ c: W, WRunning processes:
/ _1 K# B4 q; M0 ~7 I( `+ g. H, |+ HC:\WINDOWS\System32\smss.exe, W& U" I: j, v
C:\WINDOWS\system32\winlogon.exe
- V) f+ _4 y8 I* s I n% H3 pC:\WINDOWS\system32\services.exe
* i: [ J; A! ^( H2 CC:\WINDOWS\system32\lsass.exe2 b( g. S* X$ Z) x
C:\WINDOWS\system32\svchost.exe
' |" j1 J( a: b/ nD:\SOFTWARE\Rising\Rav\CCenter.exe
. j2 X8 B. L V, Z3 `6 pC:\WINDOWS\System32\svchost.exe; z* f, j' Z0 e+ X+ X8 B& B
C:\Program Files\Ahead\InCD\InCDsrv.exe6 j3 X$ U7 }/ E3 x+ e' m" f: U
D:\SOFTWARE\Rising\Rav\Ravmond.exe- S# c0 n. R0 R5 T/ p0 o5 {
C:\WINDOWS\Explorer.EXE# D9 V" |$ X) S1 q0 h- N
C:\WINDOWS\system32\spoolsv.exe9 H% J( a. x0 K" ?! t
D:\SOFTWARE\Rising\Rav\RavStub.exe1 a, H* N, N& `$ s; W
D:\SOFTWARE\Rising\Rav\RavTask.exe
# C% v" Y. g! t, i) PC:\Program Files\Common Files\Real\Update_OB\realsched.exe' s: z2 l% `* O
D:\SOFTWARE\Rising\Rav\Ravmon.exe
: Q3 c# s* }) FC:\PROGRA~1\Yahoo!\Assistant\yassistse.exe3 J' n, A. c Z3 c: T9 V
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe! q$ b# h+ f" t b% x/ y- G( ~
D:\SOFTWARE\DVD\PowerDVD\PDVDServ.exe
% _5 @ X9 z& LD:\SOFTWARE\Rising\Rav\rav.exe' _+ P$ T1 ^* s. j! z! P* T; s
C:\Program Files\Ahead\InCD\InCD.exe
8 ]. B$ X. }2 B$ c2 \& SD:\SOFTWARE\DVD\fwupdate.exe1 ]1 n, P, `7 S0 l# @6 N
D:\SOFTWARE\Adobe Acrobat 7.0 Professional\Distillr\Acrotray.exe
) |9 m# N, c0 m4 a* ]D:\SOFTWARE\xl\WebThunder.exe
$ v5 I4 c* V# t' V* I" H. I: M; x3 f, SC:\WINDOWS\system32\ctfmon.exe5 A- L6 X( f3 J3 k }" k4 B
C:\Program Files\Skype\Phone\Skype.exe' x- S& S' }/ x f( B- W
D:\SOFTWARE\DVD\Multimedia Launcher\PowerBar.exe
5 T2 b/ }8 {& ]8 l7 DC:\WINDOWS\system32\ntvdm.exe1 s6 b- P4 u n' u' m1 |
C:\Discuz!EXP\MySQL5\bin\mysqld-nt.exe
) E1 w/ A) i* y, L9 A8 Z+ _* U" vC:\Discuz!EXP\Apache2\bin\Apache.exe
" y2 T& C( R! j; UC:\WINDOWS\system32\inetsrv\inetinfo.exe
2 e! h: s" p$ ? F0 }C:\Discuz!EXP\Apache2\bin\Apache.exe
, s3 _" d" k* b! M; h, gC:\WINDOWS\system32\wscntfy.exe: E1 v% Q) u/ E' r8 n, Z
C:\Program Files\Internet Explorer\iexplore.exe
& i# ]; L5 C& j0 [7 eD:\SOFTWARE\Rising\Rav\RsAgent.exe
1 Z6 M4 S2 u" }! o. \# |; RC:\WINDOWS\msagent\AgentSvr.exe
/ m' C6 ?+ K) G+ ~4 ]C:\TDdownload\HijackThis.exe6 G: X0 X' J/ n5 v$ X/ @
R3 - URLSearchHook: ContextSearch Class - {88351CEF-BAC0-4A9B-8380-31A173E2926F} - C:\PROGRA~1\yok\toolbar.dll
2 ?0 p' \& s7 T2 H4 Q. H" dO2 - BHO: WebThunder Browser Helper - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - D:\SOFTWARE\xl\WebThunderBHO_015.dll
, @1 `/ L9 d y5 I" E& a7 G1 uO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\SOFTWARE\Adobe Acrobat 7.0 Professional\ActiveX\AcroIEHelper.dll
- N$ J5 k) Y0 O9 x) O$ pO2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll
* O+ w- ^# \2 yO2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll T3 h1 X3 |2 ?1 U/ G( U
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL9 w B0 q& `" n% c% h
O2 - BHO: (no name) - {69D23154-CA31-43E9-BEEB-F78E6D1642B3} - C:\WINDOWS\system32\3721.5.dll (file missing)0 c: c1 ?: h, G: `/ U$ n! e
O2 - BHO: 珊瑚虫超级搜索 - {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} - C:\PROGRA~1\yok\toolbar.dll
1 \3 }- \0 b; J; r4 jO2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
9 d' W3 J3 }6 ?8 }* x- bO2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\SOFTWARE\FLASHGET\jccatch.dll
4 T5 H3 G0 R" m7 A. RO2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\SOFTWARE\Adobe Acrobat 7.0 Professional\Acrobat\AcroIEFavClient.dll* V: |& R- ]% Q# J9 k0 l
O2 - BHO: AssistHelper - {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll
+ k, {% C+ u, s, {O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\SOFTWARE\FLASHGET\fgiebar.dll! X- _; e- L) c/ R& k1 Q+ c$ o
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
7 @4 P7 P. r+ F9 mO3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll4 t- q- w* _% w+ B& W0 V! P& X9 W
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
* v/ [) ^! `. E( n* _O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload# ^7 e7 F+ v+ q+ \& n
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName. @! e+ e0 x2 @6 \, I. K
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
* v, F9 f3 C* U/ t7 EO4 - HKLM\..\Run: [RavTask] "D:\SOFTWARE\Rising\Rav\RavTask.exe" -system
$ [1 V. {" @; h1 u2 zO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot. @$ A5 t- s; P5 {2 o8 Q0 b" q
O4 - HKLM\..\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
0 v6 \; a7 B% |) k9 j3 n6 l. HO4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe2 y, a) M+ J3 h* E% j8 b
O4 - HKLM\..\Run: [yok.exe] C:\PROGRA~1\yok\yok.exe
$ s1 T1 r! V7 GO4 - HKLM\..\Run: [SOUNDM] win32smd.exe
2 c0 ]+ w* r) o2 q* vO4 - HKLM\..\Run: [RemoteControl] D:\SOFTWARE\DVD\PowerDVD\PDVDServ.exe) {! V9 ^- J# o. M& k
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe" f1 _5 v2 `+ I6 v
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe) ~2 \& a* f5 x) W+ ]
O4 - HKLM\..\Run: [LGODDFU] D:\SOFTWARE\DVD\fwupdate.exe- h6 }6 G5 G- K
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\SOFTWARE\Adobe Acrobat 7.0 Professional\Distillr\Acrotray.exe") ^/ |5 U9 U4 E: o8 Q
O4 - HKLM\..\Run: [WebThunder] D:\SOFTWARE\xl\WebThunder.exe0 s. Z: V7 e! R# M+ V
O4 - HKLM\..\RunOnce: [RavStub] "D:\SOFTWARE\Rising\Rav\ravstub.exe" /RUNONCE
{' n: a% D9 [0 I; C. iO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
0 U" w8 v4 W V( W: r6 BO4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized" f& l7 T4 h, g, \" L! o. a8 j
O4 - HKCU\..\Run: [PowerBar] "D:\SOFTWARE\DVD\Multimedia Launcher\PowerBar.exe" /AtBootTime ^/ L9 T" e9 A% Z* ]8 h! i
O4 - HKCU\..\Run: [ravshelll] C:\Progra~1\Eset\eexplore.exe
* X g1 }/ c7 A- J" n! ?6 G' v7 c* tO4 - HKCU\..\Run: [myZt2] C:\DOCUME~1\zq\LOCALS~1\Temp\Zt2\SVCH0ST.EXE
, o4 c0 p3 d! @' x' X1 r6 [; GO4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE: n5 r8 ]; t/ f& D6 [% @" ~
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?SystemRoot%\Installer\{AC76BA86-2052-0000-7760-100000000002}\SC_Acrobat.exe
* N3 q) v/ w7 cO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
- Z6 f4 Z2 Z4 G......( m4 C# p' I( A3 W! J* m1 o( C
O14 - IERESET.INF: SEARCH_PAGE_URL=
! j% I, _9 I1 ^8 T6 M) W2 XO14 - IERESET.INF: START_PAGE_URL=& G) V' w" q+ N5 d. c" d% y
O17 - HKLM\System\CCS\Services\Tcpip\..\{84AB81AF-1D7F-447B-A14C-35F18C721F58}: NameServer = 202.99.160.68 202.99.166.4# j- ?+ I c0 H8 ?. v& b! p
O21 - SSODL: AdobePDF - {D92D666A-0F7B-5892-A7E8-29340333F07E} - c:\program files\internet explorer\PLUGINS\nppdf.dll (file missing)2 m; p. m K) ^
O23 - Service: Discuz!EXP-DBS - Unknown owner - C:\Discuz!EXP\MySQL5\bin\mysqld-nt.exe7 e3 f( V$ e+ s$ U7 o+ l8 z) |! Q
O23 - Service: Discuz!EXP-WEB - Unknown owner - C:\Discuz!EXP\Apache2\bin\Apache.exe" -k runservice (file missing)) r" ~5 b/ a- G, P5 `. s
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
% w% Y* N# R% z; ^O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\SOFTWARE\Rising\Rav\CCenter.exe
0 c% r' Y% Z' C) vO23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\SOFTWARE\Rising\Rav\Ravmond.exe
9 h3 Y( V7 I# Z# MO23 - Service: Windows XP Vista - Unknown owner - C:\WINDOWS\Hacker.com.cn.ini
2 v5 x3 B/ \, r/ Y X- p/ M |- C/ Z+ X
[ 本帖最后由 bdblbyq 于 2007-1-18 20:13 编辑 ] |
|