|
马上注册,结识高手,享用更多资源,轻松玩转三维网社区。
您需要 登录 才可以下载或查看,没有帐号?注册
x
怎么手工删除backdoor.gpigeon.uql灰鸽子病毒2 j: K+ X2 ?+ O' |
用hijackthis扫描log如下,请高手帮忙确定哪个是可疑文件,如何手工删除,多谢!
# _ o! u1 o* l" i! S8 GLogfile of HijackThis v1.99.1
6 o7 K( k$ H/ p( l6 K/ b4 Q6 ]4 `Scan saved at 19:45:41, on 2007-1-18- ~8 Y, p v. E& a- Q
Platform: Windows XP SP2 (WinNT 5.01.2600): |2 b- e; @# ^2 s0 N- i
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
" Y/ x* n7 q) zRunning processes:
2 }% C* z, a: D& u6 O' wC:\WINDOWS\System32\smss.exe( I9 J. ^7 I5 c5 Z/ x& J% q7 ^
C:\WINDOWS\system32\winlogon.exe- u' q0 b; C: F1 I/ I J
C:\WINDOWS\system32\services.exe1 X# m6 r! D M% p
C:\WINDOWS\system32\lsass.exe! t6 G/ T3 b" [. u: c: ~
C:\WINDOWS\system32\svchost.exe8 L& f. n/ k' k
D:\SOFTWARE\Rising\Rav\CCenter.exe4 F7 R" ?+ U8 [2 |) Z" b8 g! u& [
C:\WINDOWS\System32\svchost.exe
4 l4 ` q3 U8 [0 B. l7 K/ f# s5 n4 ]2 \C:\Program Files\Ahead\InCD\InCDsrv.exe
$ ?" M" I0 W' D/ i( qD:\SOFTWARE\Rising\Rav\Ravmond.exe
, R9 X$ V% ?" oC:\WINDOWS\Explorer.EXE
5 B- }) @1 C8 r3 ]C:\WINDOWS\system32\spoolsv.exe- F; B+ ?) p8 \& n/ j+ G( K
D:\SOFTWARE\Rising\Rav\RavStub.exe; y' C& X4 A; F
D:\SOFTWARE\Rising\Rav\RavTask.exe
3 X6 b* K @0 a8 d# b$ a8 ZC:\Program Files\Common Files\Real\Update_OB\realsched.exe9 B& U$ I; [* Q# b# s' _' n/ Y
D:\SOFTWARE\Rising\Rav\Ravmon.exe" r) ^' X K! b3 [
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
) b% g f( v5 z, g4 B& f0 J% OC:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
. G1 u- |5 P- P' O+ MD:\SOFTWARE\DVD\PowerDVD\PDVDServ.exe" y7 v+ U: {- R. O
D:\SOFTWARE\Rising\Rav\rav.exe
3 o+ O, B6 _+ k( m/ qC:\Program Files\Ahead\InCD\InCD.exe
. d9 G2 K5 b( F+ d8 \D:\SOFTWARE\DVD\fwupdate.exe
) ~: `2 N$ P# i8 C8 ^; XD:\SOFTWARE\Adobe Acrobat 7.0 Professional\Distillr\Acrotray.exe
' C) ^& B* X) w( T, e; R2 [D:\SOFTWARE\xl\WebThunder.exe
! c5 `- n9 w& \; u. uC:\WINDOWS\system32\ctfmon.exe ]' G: o& N( b( e, r- j
C:\Program Files\Skype\Phone\Skype.exe! ^3 W" x9 J* n/ |
D:\SOFTWARE\DVD\Multimedia Launcher\PowerBar.exe
3 a# F. {9 X5 k$ j6 kC:\WINDOWS\system32\ntvdm.exe
2 q4 h. k& W) z! M, N; m) z0 JC:\Discuz!EXP\MySQL5\bin\mysqld-nt.exe0 }0 B6 l2 H& f0 {
C:\Discuz!EXP\Apache2\bin\Apache.exe
8 r8 H2 M( q# w4 rC:\WINDOWS\system32\inetsrv\inetinfo.exe6 H6 b$ p' L j7 a5 {4 u) r; S
C:\Discuz!EXP\Apache2\bin\Apache.exe, K* p0 I( i; E! P" e% v V
C:\WINDOWS\system32\wscntfy.exe
& u; ^, H2 U4 @ J! PC:\Program Files\Internet Explorer\iexplore.exe! G" S) d: D+ R! U6 K
D:\SOFTWARE\Rising\Rav\RsAgent.exe
# E" b* D/ v, G' Q- w$ ?, yC:\WINDOWS\msagent\AgentSvr.exe
, |* s: x- f% J- P! B: B: y" zC:\TDdownload\HijackThis.exe
! S0 z4 R2 a1 Y' l6 QR3 - URLSearchHook: ContextSearch Class - {88351CEF-BAC0-4A9B-8380-31A173E2926F} - C:\PROGRA~1\yok\toolbar.dll
# P/ X& Q8 a. f& {+ eO2 - BHO: WebThunder Browser Helper - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - D:\SOFTWARE\xl\WebThunderBHO_015.dll* u) ~- y: M+ s4 n6 U$ s( g6 H: f* I
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\SOFTWARE\Adobe Acrobat 7.0 Professional\ActiveX\AcroIEHelper.dll$ U: C! H; N A* M# {2 k, _
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll
+ D0 K, Y8 _( {% B! s0 D4 ?" N' xO2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll* `; k8 h! P0 _, m0 y, h2 h
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL0 [' a2 M5 X# S% Z& f
O2 - BHO: (no name) - {69D23154-CA31-43E9-BEEB-F78E6D1642B3} - C:\WINDOWS\system32\3721.5.dll (file missing), }( ^7 `5 P! R0 Q9 r" Q
O2 - BHO: 珊瑚虫超级搜索 - {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} - C:\PROGRA~1\yok\toolbar.dll: `; X: t/ h- ?% z" w; l
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll% x! A2 @& _" A5 t
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\SOFTWARE\FLASHGET\jccatch.dll P; g1 A2 H+ ?% a8 @
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\SOFTWARE\Adobe Acrobat 7.0 Professional\Acrobat\AcroIEFavClient.dll
0 ^# J! ?: @+ v6 ]5 }' a, `O2 - BHO: AssistHelper - {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll+ I6 s2 n& C. n5 E
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\SOFTWARE\FLASHGET\fgiebar.dll; B8 }% t0 J+ |, K$ _6 b' F
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll* N, s/ y% y) w. l y; C
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll5 a6 V# ^$ X7 L! p: R# [. V
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
" D% s( q! S: t$ v2 PO4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload# U$ Q g0 C! F0 @/ K: u! P
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName7 G" P( @5 g* v! @2 C- O6 o, p4 ~' V
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC/ a$ \0 k- c- {7 {: ^9 u2 U) Q
O4 - HKLM\..\Run: [RavTask] "D:\SOFTWARE\Rising\Rav\RavTask.exe" -system& n, N: ^( L' [, q9 t* P3 s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
V$ n; c5 [7 a0 E1 u3 Y( o' DO4 - HKLM\..\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"* T: N; U! g9 I @- o
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe1 q' s" ?" n' s, }, h/ X7 i: i
O4 - HKLM\..\Run: [yok.exe] C:\PROGRA~1\yok\yok.exe
6 ^6 H: y! k6 C7 i# p c9 nO4 - HKLM\..\Run: [SOUNDM] win32smd.exe
8 U) @2 W3 y5 ]4 I* T( P* f# oO4 - HKLM\..\Run: [RemoteControl] D:\SOFTWARE\DVD\PowerDVD\PDVDServ.exe
# R' B* Z* q d/ fO4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
( M4 f. N( W. O; zO4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
+ u P3 L: q; w+ R- |$ P9 j7 ]' O" w( rO4 - HKLM\..\Run: [LGODDFU] D:\SOFTWARE\DVD\fwupdate.exe
% r! k2 T1 p) Q1 s8 Z0 j& W2 l5 xO4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\SOFTWARE\Adobe Acrobat 7.0 Professional\Distillr\Acrotray.exe"3 d& e! M$ t4 M, m
O4 - HKLM\..\Run: [WebThunder] D:\SOFTWARE\xl\WebThunder.exe* `# W% Y# l- J2 _: n$ k' U
O4 - HKLM\..\RunOnce: [RavStub] "D:\SOFTWARE\Rising\Rav\ravstub.exe" /RUNONCE
" h, @2 r; J) b# m6 C4 d/ IO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
! B5 j6 M) m# Q: H/ V8 SO4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized3 U% e- Z. H! j( A
O4 - HKCU\..\Run: [PowerBar] "D:\SOFTWARE\DVD\Multimedia Launcher\PowerBar.exe" /AtBootTime$ Q4 ]* x; b! B' H" D3 S0 A" n: h
O4 - HKCU\..\Run: [ravshelll] C:\Progra~1\Eset\eexplore.exe l+ ?& u; H. |9 J# W9 w
O4 - HKCU\..\Run: [myZt2] C:\DOCUME~1\zq\LOCALS~1\Temp\Zt2\SVCH0ST.EXE r, j/ q7 b6 |" S0 Z) J7 a
O4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE
# l2 O( N' R' Z5 }O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?SystemRoot%\Installer\{AC76BA86-2052-0000-7760-100000000002}\SC_Acrobat.exe
5 @/ S. X; J4 N, n0 P- _6 b6 mO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
( h8 }% q) c0 i \1 z0 F9 T......$ W" ?' n; ~# h1 a K
O14 - IERESET.INF: SEARCH_PAGE_URL=
+ Z9 _) i, N/ \3 a* L' gO14 - IERESET.INF: START_PAGE_URL=* L( h% }; {0 G" P
O17 - HKLM\System\CCS\Services\Tcpip\..\{84AB81AF-1D7F-447B-A14C-35F18C721F58}: NameServer = 202.99.160.68 202.99.166.4
7 w$ ?2 i! s; c# W5 \. CO21 - SSODL: AdobePDF - {D92D666A-0F7B-5892-A7E8-29340333F07E} - c:\program files\internet explorer\PLUGINS\nppdf.dll (file missing)$ L9 u* @- I- t4 ^2 G
O23 - Service: Discuz!EXP-DBS - Unknown owner - C:\Discuz!EXP\MySQL5\bin\mysqld-nt.exe- V/ O% U' D0 k
O23 - Service: Discuz!EXP-WEB - Unknown owner - C:\Discuz!EXP\Apache2\bin\Apache.exe" -k runservice (file missing)6 J- y _- p5 t: V6 }" T3 b
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe% O" j) e' N8 D4 Q8 T5 `1 p
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\SOFTWARE\Rising\Rav\CCenter.exe: H" r3 S$ y; P; r) B$ U
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\SOFTWARE\Rising\Rav\Ravmond.exe2 L& u- i9 U. G. d2 Z7 Z# `( \0 n& ^- h; @
O23 - Service: Windows XP Vista - Unknown owner - C:\WINDOWS\Hacker.com.cn.ini
8 R0 I4 A9 [: d
; I9 K8 ~% [ |7 M, Z6 A[ 本帖最后由 bdblbyq 于 2007-1-18 20:13 编辑 ] |
|