QQ登录

只需一步,快速开始

登录 | 注册 | 找回密码

三维网

 找回密码
 注册

QQ登录

只需一步,快速开始

展开

通知     

全站
9天前
查看: 1508|回复: 3
收起左侧

[求助] 如何删除backdoor.gpigeon.uql病毒

[复制链接]
发表于 2007-1-18 20:08:55 | 显示全部楼层 |阅读模式 来自: 中国河北保定

马上注册,结识高手,享用更多资源,轻松玩转三维网社区。

您需要 登录 才可以下载或查看,没有帐号?注册

x
怎么手工删除backdoor.gpigeon.uql灰鸽子病毒
& a+ Z4 V# L2 @# ~! d4 q$ ?+ a用hijackthis扫描log如下,请高手帮忙确定哪个是可疑文件,如何手工删除,多谢!4 Z0 q, g3 O- y$ y
Logfile of HijackThis v1.99.1: f! Y; y5 T0 z; L; Q2 C
Scan saved at 19:45:41, on 2007-1-18
) h: W3 A- ^& e9 A9 S4 N; D$ ]Platform: Windows XP SP2 (WinNT 5.01.2600)
& l8 W; _$ G6 @9 J% FMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)- C' ^) g# Z# w* {% \$ E
Running processes:4 g7 ^6 M, o; ^0 }0 W& A
C:\WINDOWS\System32\smss.exe
4 ~0 n; w+ Y0 {, T- bC:\WINDOWS\system32\winlogon.exe. z7 W7 M4 m7 I# E
C:\WINDOWS\system32\services.exe
" m' k( H1 q: }: mC:\WINDOWS\system32\lsass.exe. K: V7 ]  m- \4 G$ q
C:\WINDOWS\system32\svchost.exe8 {' ^7 ?9 {4 t/ {+ ^
D:\SOFTWARE\Rising\Rav\CCenter.exe
; ]5 D- T, r4 n& S7 P$ [C:\WINDOWS\System32\svchost.exe
, I" Y( V/ T" V( oC:\Program Files\Ahead\InCD\InCDsrv.exe
' v4 X: q9 w* q* s# ~/ xD:\SOFTWARE\Rising\Rav\Ravmond.exe
5 W8 L3 g5 C' h# j5 |4 p. Y. b4 N/ ^1 OC:\WINDOWS\Explorer.EXE' f7 L; _3 D; _4 `
C:\WINDOWS\system32\spoolsv.exe
' q  h% {0 H: t1 b3 O+ L  VD:\SOFTWARE\Rising\Rav\RavStub.exe: J+ W- O1 j+ }9 i% e" p+ ]4 H
D:\SOFTWARE\Rising\Rav\RavTask.exe
; e2 @& y- d4 B2 B/ DC:\Program Files\Common Files\Real\Update_OB\realsched.exe
" }3 E' p/ U; o& `1 ?* c& j2 ID:\SOFTWARE\Rising\Rav\Ravmon.exe; H% a4 K7 E( {3 g
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe2 O; `) l8 ?1 G  F; B. G/ M
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
: W2 I$ ~5 v. h' S1 eD:\SOFTWARE\DVD\PowerDVD\PDVDServ.exe
* T' D( ^& F) Z: G/ V6 _2 Z+ n# JD:\SOFTWARE\Rising\Rav\rav.exe+ h! f) O( G+ ]5 M3 F; @: k
C:\Program Files\Ahead\InCD\InCD.exe$ D/ R: i# `. h2 {  W2 `. O4 g
D:\SOFTWARE\DVD\fwupdate.exe
( p- a! l- z! |6 i3 hD:\SOFTWARE\Adobe Acrobat 7.0 Professional\Distillr\Acrotray.exe* @1 H- J0 T% g' X7 @4 I: ?
D:\SOFTWARE\xl\WebThunder.exe
4 B/ T8 Q8 q% b  {' }! g& @C:\WINDOWS\system32\ctfmon.exe
3 g$ ~. Y1 k7 q: QC:\Program Files\Skype\Phone\Skype.exe
+ U  M, Y8 ?- b6 x0 \+ n9 |. `D:\SOFTWARE\DVD\Multimedia Launcher\PowerBar.exe- Y; A4 h  B! {7 ]8 J+ Y
C:\WINDOWS\system32\ntvdm.exe
3 p* }, ?! M" t  ?C:\Discuz!EXP\MySQL5\bin\mysqld-nt.exe
5 U9 v# x; K2 `. iC:\Discuz!EXP\Apache2\bin\Apache.exe: p6 n7 _: ^  o/ F3 K3 X) v* g
C:\WINDOWS\system32\inetsrv\inetinfo.exe
( W  ]% l0 x" \7 U* W" dC:\Discuz!EXP\Apache2\bin\Apache.exe
! g0 x% X) G9 z2 v) \  gC:\WINDOWS\system32\wscntfy.exe+ T  t: Q7 K1 S5 K) r, ?6 F. d
C:\Program Files\Internet Explorer\iexplore.exe
$ q, f% Q! C3 `7 b5 I& M( j* U8 HD:\SOFTWARE\Rising\Rav\RsAgent.exe
! c- H! F& I' G7 U; N6 b- V& ^C:\WINDOWS\msagent\AgentSvr.exe
" U) Q- J  g/ B' wC:\TDdownload\HijackThis.exe
& H/ W2 v8 k  e6 X+ _R3 - URLSearchHook: ContextSearch Class - {88351CEF-BAC0-4A9B-8380-31A173E2926F} - C:\PROGRA~1\yok\toolbar.dll
5 O* _$ u: a4 x( R( `) UO2 - BHO: WebThunder Browser Helper - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - D:\SOFTWARE\xl\WebThunderBHO_015.dll
: C7 E6 W7 R- R( W( lO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\SOFTWARE\Adobe Acrobat 7.0 Professional\ActiveX\AcroIEHelper.dll& T5 ^2 [' k; K
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll
9 d" |( u/ D4 ~* u" ~% JO2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll5 S% w' \% X+ T, J% p% b
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL' d7 S' P' y3 z3 Z6 k  ~
O2 - BHO: (no name) - {69D23154-CA31-43E9-BEEB-F78E6D1642B3} - C:\WINDOWS\system32\3721.5.dll (file missing), A: h4 ]5 x! _+ n4 U
O2 - BHO: 珊瑚虫超级搜索 - {75FE2B5A-D3A4-4EFA-AC11-ADC9C9459688} - C:\PROGRA~1\yok\toolbar.dll
0 n" C& d/ M$ [# @$ |7 [O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
0 ^5 D8 x4 ~) t9 e- C; y: M; s: cO2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\SOFTWARE\FLASHGET\jccatch.dll9 O" e% j7 o. I7 y9 A( i2 e
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\SOFTWARE\Adobe Acrobat 7.0 Professional\Acrobat\AcroIEFavClient.dll/ B6 _  d' j  K( e8 y3 ?" @" \
O2 - BHO: AssistHelper - {FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yassist.dll6 z( X, u5 T: x( a* E
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\SOFTWARE\FLASHGET\fgiebar.dll
5 l8 O. X9 i/ y3 vO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
2 x. U; v% Q- L& p& h7 I0 y7 [O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll6 T) W& b( J2 P2 ~' _8 z1 u
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration322 \/ r( o9 b% u! z2 ]) f) k. I
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
& z! Z6 @. b" j0 J5 S4 U8 mO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName$ N8 n5 ]. Z) @# h/ H
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC5 K8 G& [) b7 s
O4 - HKLM\..\Run: [RavTask] "D:\SOFTWARE\Rising\Rav\RavTask.exe" -system% n" a" |* b+ J3 O
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot. b: K# \( X5 i: R( p
O4 - HKLM\..\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"1 q- ]9 e+ `) d0 m6 d/ H! |
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
2 O& ^3 ^+ p% K# W; j( TO4 - HKLM\..\Run: [yok.exe] C:\PROGRA~1\yok\yok.exe  }, D- v0 |4 D; c' f
O4 - HKLM\..\Run: [SOUNDM] win32smd.exe9 s9 B8 u$ b* R7 N
O4 - HKLM\..\Run: [RemoteControl] D:\SOFTWARE\DVD\PowerDVD\PDVDServ.exe
. ]7 ~8 W# {2 M5 EO4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe. O! E* G9 q7 q' _8 D9 I* b# U+ J
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
4 f, I7 [$ N" }O4 - HKLM\..\Run: [LGODDFU] D:\SOFTWARE\DVD\fwupdate.exe# `: L3 b; b& c+ S( ^: h# ?  y
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\SOFTWARE\Adobe Acrobat 7.0 Professional\Distillr\Acrotray.exe"( s" S, a( `( ]( B$ d3 R- V; @
O4 - HKLM\..\Run: [WebThunder] D:\SOFTWARE\xl\WebThunder.exe: N$ A. g8 Z  T& I6 `8 p
O4 - HKLM\..\RunOnce: [RavStub] "D:\SOFTWARE\Rising\Rav\ravstub.exe" /RUNONCE( L; g7 b1 m: [* y* E# x8 F
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
* g' f0 [# e& A( J& YO4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
5 c3 w- Z/ f# {8 nO4 - HKCU\..\Run: [PowerBar] "D:\SOFTWARE\DVD\Multimedia Launcher\PowerBar.exe" /AtBootTime' g3 E0 m' Q' p( r4 M/ U1 N! W8 R2 j
O4 - HKCU\..\Run: [ravshelll] C:\Progra~1\Eset\eexplore.exe
0 x/ v4 k0 Z' l; UO4 - HKCU\..\Run: [myZt2] C:\DOCUME~1\zq\LOCALS~1\Temp\Zt2\SVCH0ST.EXE% g1 ]. X3 q6 u& d1 t# g- o2 X
O4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE. v5 @* J$ e- @+ `; z6 M
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?SystemRoot%\Installer\{AC76BA86-2052-0000-7760-100000000002}\SC_Acrobat.exe/ v+ Z8 q0 o& P5 O
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present0 Y6 ]& J5 E  @& Q( Z& Q
......
* i; K' K& J- }2 U0 k1 ]O14 - IERESET.INF: SEARCH_PAGE_URL=
* o% k- V$ ]9 M' f  AO14 - IERESET.INF: START_PAGE_URL=. J; z" p: x# X' j. O
O17 - HKLM\System\CCS\Services\Tcpip\..\{84AB81AF-1D7F-447B-A14C-35F18C721F58}: NameServer = 202.99.160.68 202.99.166.4
- T" w0 _) y9 y( S; i4 [O21 - SSODL: AdobePDF - {D92D666A-0F7B-5892-A7E8-29340333F07E} - c:\program files\internet explorer\PLUGINS\nppdf.dll (file missing); I% w1 o9 p3 u# Y- w
O23 - Service: Discuz!EXP-DBS - Unknown owner - C:\Discuz!EXP\MySQL5\bin\mysqld-nt.exe& d3 S) F  N5 r0 Y
O23 - Service: Discuz!EXP-WEB - Unknown owner - C:\Discuz!EXP\Apache2\bin\Apache.exe" -k runservice (file missing)
3 @3 L: d! O3 q; r- J1 UO23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
( b  @$ @& e, w0 E' ?, {, @6 UO23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - D:\SOFTWARE\Rising\Rav\CCenter.exe8 t" Z( Q# R; t4 ~4 X. {
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\SOFTWARE\Rising\Rav\Ravmond.exe; t0 I& p' H1 y1 |9 k7 K$ @
O23 - Service: Windows XP Vista         - Unknown owner - C:\WINDOWS\Hacker.com.cn.ini0 @5 R. P# J9 Q) w0 B
2 W4 w- y- T4 {2 [4 Z) T1 B' T
[ 本帖最后由 bdblbyq 于 2007-1-18 20:13 编辑 ]
发表于 2007-1-18 20:16:42 | 显示全部楼层 来自: 中国河南焦作
你是怎么做的,我用赛门铁克在安全模式下搞玩后重启就可以了.
 楼主| 发表于 2007-1-18 21:22:35 | 显示全部楼层 来自: 中国河北保定
原帖由 michelzz 于 2007-1-18 20:16 发表& C  y* w( k0 i0 B
你是怎么做的,我用赛门铁克在安全模式下搞玩后重启就可以了.
) E% V) k: G" {: j0 K& n
我不会做,所以才求助的 ! g# t0 h: q8 W! ~8 d2 o4 T
网上搜索,说用hijackthis扫描,找到可疑服务,然后在安全模式下修改注册表,再删除文件什么的。可哪个是可疑文件呢?
2 w$ b' P. O0 c8 L2 K/ l. R% y, V, z/ R/ @7 |5 I2 A
[ 本帖最后由 bdblbyq 于 2007-1-18 21:24 编辑 ]
发表于 2007-1-18 22:36:32 | 显示全部楼层 来自: 中国浙江杭州
一般的杀毒软件都可以清除
+ p$ P! a- D+ V) O" c不建议手动
发表回复
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Licensed Copyright © 2016-2020 http://www.3dportal.cn/ All Rights Reserved 京 ICP备13008828号

小黑屋|手机版|Archiver|三维网 ( 京ICP备2023026364号-1 )

快速回复 返回顶部 返回列表