QQ登录

只需一步,快速开始

登录 | 注册 | 找回密码

三维网

 找回密码
 注册

QQ登录

只需一步,快速开始

展开

通知     

全站
9天前
查看: 1507|回复: 3
收起左侧

[求助] 如何删除backdoor.gpigeon.uql病毒

[复制链接]
发表于 2007-1-18 20:08:55 | 显示全部楼层 |阅读模式 来自: 中国河北保定

马上注册,结识高手,享用更多资源,轻松玩转三维网社区。

您需要 登录 才可以下载或查看,没有帐号?注册

x
怎么手工删除backdoor.gpigeon.uql灰鸽子病毒( ?4 E( v. W0 K9 |, E" h
用hijackthis扫描log如下,请高手帮忙确定哪个是可疑文件,如何手工删除,多谢!
; ~* ]5 ]7 C$ U; K8 L  L/ ]) oLogfile of HijackThis v1.99.1
) |# ?+ A5 N! O) iScan saved at 19:45:41, on 2007-1-18; l% _  v/ Z' {5 \
Platform: Windows XP SP2 (WinNT 5.01.2600)
) R" g% a% g! sMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)! a: j! G* A0 o! G' y0 i2 D
Running processes:; |# S7 K% _6 u
C:\WINDOWS\System32\smss.exe, `) C2 B# w- A  N5 S0 ]" n
C:\WINDOWS\system32\winlogon.exe" x0 Z5 t, L2 e" V+ U4 E
C:\WINDOWS\system32\services.exe
+ \  _0 C  ^& c. I& G; yC:\WINDOWS\system32\lsass.exe
- P* T8 c3 L# s9 R% AC:\WINDOWS\system32\svchost.exe
8 Q: g0 Y' j+ i0 ^D:\SOFTWARE\Rising\Rav\CCenter.exe
# {$ g" G+ f% I, `2 s8 a  lC:\WINDOWS\System32\svchost.exe- E9 N: Z4 X  H
C:\Program Files\Ahead\InCD\InCDsrv.exe
3 F/ c5 e9 p" C9 pD:\SOFTWARE\Rising\Rav\Ravmond.exe
8 }+ n. Z' T6 X4 a" {$ G7 zC:\WINDOWS\Explorer.EXE
4 _0 l& p- T  T# p# `C:\WINDOWS\system32\spoolsv.exe
, I5 l5 G: G5 A7 c2 ND:\SOFTWARE\Rising\Rav\RavStub.exe3 [( X; C0 }3 E/ O- H
D:\SOFTWARE\Rising\Rav\RavTask.exe
2 Y9 n, a( l$ L, d# ?7 gC:\Program Files\Common Files\Real\Update_OB\realsched.exe2 ~! u* g6 z8 ?, @( ~4 m
D:\SOFTWARE\Rising\Rav\Ravmon.exe# Z6 A* V4 L% i) [' H
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
) @" g' {% T* H* J" gC:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe1 l% B/ p' E- a$ T8 ~0 q% g
D:\SOFTWARE\DVD\PowerDVD\PDVDServ.exe
6 @4 j9 _2 m. O# }& }$ O& L, OD:\SOFTWARE\Rising\Rav\rav.exe
) B! i* M" p7 P+ ]9 `C:\Program Files\Ahead\InCD\InCD.exe
+ A1 _. D2 q6 g3 ZD:\SOFTWARE\DVD\fwupdate.exe# E( D) ?$ B) o
D:\SOFTWARE\Adobe Acrobat 7.0 Professional\Distillr\Acrotray.exe
; ]3 g1 `" R) L. R) ?0 q+ j5 `D:\SOFTWARE\xl\WebThunder.exe
, O' r# u4 z3 y3 K$ MC:\WINDOWS\system32\ctfmon.exe
6 Q' v$ ]  t: G( M! ]C:\Program Files\Skype\Phone\Skype.exe
! U) K7 y. E* ~$ BD:\SOFTWARE\DVD\Multimedia Launcher\PowerBar.exe
/ ]# f5 j% u+ y7 ^$ P' pC:\WINDOWS\system32\ntvdm.exe
- ?* f! A& O+ [) X" o4 Q$ xC:\Discuz!EXP\MySQL5\bin\mysqld-nt.exe% k; @: y* _6 ]# x# M* p8 L- l
C:\Discuz!EXP\Apache2\bin\Apache.exe9 {0 h) h. r( {+ ^/ s; P
C:\WINDOWS\system32\inetsrv\inetinfo.exe
2 Y0 M. A+ N, j5 i& p6 W7 H; AC:\Discuz!EXP\Apache2\bin\Apache.exe+ V1 g, |1 |% I' j
C:\WINDOWS\system32\wscntfy.exe0 ]5 g( r& }( \6 ]* y5 I' ~! {
C:\Program Files\Internet Explorer\iexplore.exe
: p! l. s% |5 V: ED:\SOFTWARE\Rising\Rav\RsAgent.exe8 ]& f8 O, H/ A6 m: E2 y5 `- z# w* ^
C:\WINDOWS\msagent\AgentSvr.exe" |) |) a2 R) B  |- H
C:\TDdownload\HijackThis.exe
8 A2 b( B& `7 D. JR3 - URLSearchHook: ContextSearch Class - {88351CEF-BAC0-4A9B-8380-31A173E2926F} - C:\PROGRA~1\yok\toolbar.dll
& u8 ?( v* W) m4 d: M8 cO2 - BHO: WebThunder Browser Helper - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - D:\SOFTWARE\xl\WebThunderBHO_015.dll' L" l7 I$ Q+ B7 J8 k! Z5 ^6 @* r; I
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\SOFTWARE\Adobe Acrobat 7.0 Professional\ActiveX\AcroIEHelper.dll
' p) Q. j, M" j, o  }8 AO2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll/ [- L4 @' G/ U+ k- A' L- ^9 G
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll8 m3 l9 T, k1 E
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL$ A9 k/ ?+ ?, D" T; k
O2 - BHO: (no name) - {69D23154-CA31-43E9-BEEB-F78E6D1642B3} - C:\WINDOWS\system32\3721.5.dll (file missing)' X, F- V  D) Z, G4 a
O2 - BHO: 珊瑚虫超级搜索 - {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} - C:\PROGRA~1\yok\toolbar.dll
$ G4 _/ `  x1 T# {: lO2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
- M& C/ _; E% D. O6 KO2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\SOFTWARE\FLASHGET\jccatch.dll7 B, X- P- U- Z, ]! T
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\SOFTWARE\Adobe Acrobat 7.0 Professional\Acrobat\AcroIEFavClient.dll
1 ]  w. ]7 p* p, R0 gO2 - BHO: AssistHelper - {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll7 b, a+ T, j1 {$ ^! I- D1 @: h: b- F
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\SOFTWARE\FLASHGET\fgiebar.dll8 r% \8 X6 N, G& b" s8 o
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll" [, I$ A& e) G
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll
+ [* G- ~: M' @, I) DO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32, K- d2 d8 I8 j4 R
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
1 j( I4 @& x( X3 {8 @4 u* L9 QO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
! ~6 s# u8 V" i0 V9 t5 j# Q. ]; ZO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC* e3 G+ Z0 q- R8 M! E
O4 - HKLM\..\Run: [RavTask] "D:\SOFTWARE\Rising\Rav\RavTask.exe" -system
. l$ H1 J/ w) e* C4 NO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
3 a5 o1 E. N0 }, N8 Q+ ?2 wO4 - HKLM\..\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
  R8 L( G& x$ X  a( I) D6 SO4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe7 Y7 x$ |5 A4 ]' i% v9 P
O4 - HKLM\..\Run: [yok.exe] C:\PROGRA~1\yok\yok.exe
( x  l' ]# i) D8 d7 q5 X+ E6 ZO4 - HKLM\..\Run: [SOUNDM] win32smd.exe
: E1 {$ k$ |: o: [4 U  H1 {O4 - HKLM\..\Run: [RemoteControl] D:\SOFTWARE\DVD\PowerDVD\PDVDServ.exe
; o# ^% {/ o# S. wO4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe; U6 x! A( d( f$ ]6 S2 t
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
8 `7 ^- ^, b7 g8 `) R+ y9 pO4 - HKLM\..\Run: [LGODDFU] D:\SOFTWARE\DVD\fwupdate.exe
0 n: \* `; W4 pO4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\SOFTWARE\Adobe Acrobat 7.0 Professional\Distillr\Acrotray.exe"6 |% `1 v$ C/ S& t  b7 T2 G
O4 - HKLM\..\Run: [WebThunder] D:\SOFTWARE\xl\WebThunder.exe1 I) f2 h$ c! I4 `1 @, q. w% m
O4 - HKLM\..\RunOnce: [RavStub] "D:\SOFTWARE\Rising\Rav\ravstub.exe" /RUNONCE2 @5 I: Z# M) ^" i6 f
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
( }% ?! ^# ~( K. G9 }  {O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
- a; }" S0 y# f7 ]: l4 `/ jO4 - HKCU\..\Run: [PowerBar] "D:\SOFTWARE\DVD\Multimedia Launcher\PowerBar.exe" /AtBootTime, E* M8 H# ?$ O- F1 z4 o
O4 - HKCU\..\Run: [ravshelll] C:\Progra~1\Eset\eexplore.exe
  d* W) Z+ w, G+ {O4 - HKCU\..\Run: [myZt2] C:\DOCUME~1\zq\LOCALS~1\Temp\Zt2\SVCH0ST.EXE
) G; r& Z" K" V* \5 JO4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE
/ g  }) E: W& U$ a- ]! [O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?SystemRoot%\Installer\{AC76BA86-2052-0000-7760-100000000002}\SC_Acrobat.exe
; l$ @" b, R) |8 M6 Y* ?! l: eO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present1 D5 l# h5 A' v3 e+ K6 p& R
......
( I  |: a& B8 G2 N: c  wO14 - IERESET.INF: SEARCH_PAGE_URL=
0 {* S! s& @, H* z" {/ DO14 - IERESET.INF: START_PAGE_URL=
* z) j3 F, K6 W& SO17 - HKLM\System\CCS\Services\Tcpip\..\{84AB81AF-1D7F-447B-A14C-35F18C721F58}: NameServer = 202.99.160.68 202.99.166.47 A; M& }, _" ~9 g  p$ H( `! P
O21 - SSODL: AdobePDF - {D92D666A-0F7B-5892-A7E8-29340333F07E} - c:\program files\internet explorer\PLUGINS\nppdf.dll (file missing)8 W7 R. ^. Z5 n. Z/ T0 G: O
O23 - Service: Discuz!EXP-DBS - Unknown owner - C:\Discuz!EXP\MySQL5\bin\mysqld-nt.exe" g1 l/ p$ j+ Z& k
O23 - Service: Discuz!EXP-WEB - Unknown owner - C:\Discuz!EXP\Apache2\bin\Apache.exe" -k runservice (file missing); ]$ w) {8 i3 o9 S# E5 {* ^3 @
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe; i$ x7 x9 o/ {" G% p9 ]6 V1 A
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\SOFTWARE\Rising\Rav\CCenter.exe: _, k) C. k; r5 u. Q; u& Q3 f/ i
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\SOFTWARE\Rising\Rav\Ravmond.exe
, p$ j/ ~7 R7 b& ]: s6 O3 HO23 - Service: Windows XP Vista         - Unknown owner - C:\WINDOWS\Hacker.com.cn.ini6 A& O, ]: U3 |" Q1 L+ T

/ v# g' R# ]3 v/ K6 Z+ W[ 本帖最后由 bdblbyq 于 2007-1-18 20:13 编辑 ]
发表于 2007-1-18 20:16:42 | 显示全部楼层 来自: 中国河南焦作
你是怎么做的,我用赛门铁克在安全模式下搞玩后重启就可以了.
 楼主| 发表于 2007-1-18 21:22:35 | 显示全部楼层 来自: 中国河北保定
原帖由 michelzz 于 2007-1-18 20:16 发表( Y# |: |: t2 Y  m/ Q+ h* \* C" A
你是怎么做的,我用赛门铁克在安全模式下搞玩后重启就可以了.
* _' F& I  C& G! K' I2 A' W* u1 J/ B
我不会做,所以才求助的
. Y* `" }" }' i) l网上搜索,说用hijackthis扫描,找到可疑服务,然后在安全模式下修改注册表,再删除文件什么的。可哪个是可疑文件呢?- j( P8 c9 X+ B2 h
# q& J; y/ H5 }3 @
[ 本帖最后由 bdblbyq 于 2007-1-18 21:24 编辑 ]
发表于 2007-1-18 22:36:32 | 显示全部楼层 来自: 中国浙江杭州
一般的杀毒软件都可以清除3 O! N: C* Q+ R" Y0 M" `
不建议手动
发表回复
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Licensed Copyright © 2016-2020 http://www.3dportal.cn/ All Rights Reserved 京 ICP备13008828号

小黑屋|手机版|Archiver|三维网 ( 京ICP备2023026364号-1 )

快速回复 返回顶部 返回列表