遭遇灰鸽子变种、Viking 和 N多木马(第2版)

endurer 原创

2006-09-08 第2版 补充杀毒软件的反应
2006-09-07 第1

有位网友的电脑,总告发现Backdoor.Gpigeon.uql。

于是通过QQ进行远程协助。

http://endurer.ys168.com 下载了HijackThis 扫描log,发现如下可疑项目:


/-------------------------
Logfile of HijackThis v1.99.1
Scan saved at 11:22:51, on 2006-9-7
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:/Program Files/Microsoft/svhost32.exe
C:/Program Files/LetsCool/LetsCool.exe
C:/Program Files/Zcom/ZComService.exe
C:/Program Files/Zcom/skin.dll
C:/Program Files/Internet Explorer/7Sy.exe

R3 - URLSearchHook: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)

F3 - REG:win.ini: load=C:/WINDOWS/rundl132.exe

O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:/PROGRA~1/Yahoo!/ASSIST~1/Assist/yasbar.dll

O2 - BHO: (no name) - {669751ED-D558-49AE-B01A-3B374CC7910E} - C:/WINDOWS/system32/ssup.dll

O2 - BHO: MAngle Class - {9A556B8F-FD02-420E-A1FD-9DB33808254E} - C:/Program Files/MySec/secmouseaan.dll

O3 - Toolbar: My 网蜜(&M) - {102293E4-758B-4483-946B-714EBCEC91B8} - C:/Program Files/MySec/secbaraan.dll

O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - F:/音乐/KuGoo3/KuGoo3DownXControl.ocx

O2 - BHO: Letscool System Helper - {F0C15012-7DBD-4068-95A2-0A82DB03AC35} - C:/WINDOWS/system32/CoolBho.dll

O4 - HKLM/../Run: [ms] C:/Program Files/Microsoft/svhost32.exe

O4 - HKLM/../Run: [LetsCool] C:/Program Files/LetsCool/LetsCool.exe

O4 - HKLM/../Run: [stup.exe] C:/PROGRA~1/TENCENT/Adplus/stup.exe

O4 - HKLM/../Run: [_rx] C:/WINDOWS/rundll32.exe


O23 - Service: systen - Unknown owner - C:/WINDOWS/Hacker.com.cn.exe
-------------------------/

(下面的修复方法可参考:【系统修复系列之】基本操作索引
http://endurer.blogchina.com/2591241.html

停止并禁用服务:systen

http://endurer.ys168.com 下载 ProcView,终止进程:
/-------------------------
C:/Program Files/Microsoft/svhost32.exe
C:/Program Files/LetsCool/LetsCool.exe
C:/Program Files/Zcom/ZComService.exe
C:/Program Files/Zcom/skin.dll
C:/Program Files/Internet Explorer/7Sy.exe
-------------------------/

用WinRAR检查下列文件夹,发现:


c:/
=====================================
internt.hta(Kaspersky 报为 Trojan-PSW.Win32.QQPass.hn
rar.hta(Kaspersky 报为 Trojan-Downloader.JS.Small.cq
vidll.dll(Kaspersky 报为 Worm.Win32.Viking.r,瑞星 报为 Worm.Viking.aa


C:/Documents and Settings/user/Local Settings/temp
=====================================
g0ld.com((Kaspersky 报为 Worm.Win32.Viking.r,DrWeb 报为 Win32.HLLW.Gavir.8瑞星 报为 Worm.Viking.aa
qq4[1].exe(Kaspersky 报为 Trojan.Win32.Delf.rf,DrWeb 报为 Trojan.PWS.Spywoool


C:/Program Files
=====================================
svhost32.exe(DrWeb 报为 Trojan.PWS.Lineage


C:/Program Files/Internet Explorer
=====================================
0Sy.exe(Kaspersky 报为 Trojan.Win32.Delf.rf,DrWeb 报为 Trojan.PWS.Spywoool
3Sy.exe(Kaspersky 报为 Trojan-PSW.Win32.Lineage.aih,DrWeb 报为 Trojan.PWS.Lineage
4Sy.exe(Kaspersky 报为 Trojan.PSW.Win32.Lineage.pj,DrWeb 报为 Trojan.PWS.Lineage
5Sy.exe(Kaspersky 报为 Trojan-PSW.Win32.Agent.ic
6Sy.exe(Kaspersky 报为 Trojan-PSW.Win32.Agent.ic
7Sy.exe(Kaspersky 报为 Trojan-PSW.Win32.Lineage.acw,DrWeb 报为 Trojan.PWS.Lineage

C:/Program Files/LetsCool
=====================================
LetsCool.exe(DrWeb 报为 Adware.Letscool
Picdown.exe(DrWeb 报为 Trojan.DownLoader.12193

C:/Program Files/Microsoft
=====================================
svhost32.exe(DrWeb 报为 Trojan.PWS.Lineage

c:/windows
=====================================
rundll32.exe(图标类似记事本,Kaspersky 报为 Trojan-PSW.Win32.Lineage.aih
rundl132.exe(Kaspersky 报为 Worm.Win32.Viking.r,瑞星 报为 Worm.Viking.aa,DrWeb 报为 Win32.HLLW.Gavir.8

c:/windows/system32
=====================================
a.exe(DrWeb 报为 Tool.DialupPass.243
dllwm.dll(Kaspersky 报为 Trojan-PSW.Win32.Lineage.acw,DrWeb 报为 Trojan.PWS.Lineage
dllz.dll(Kaspersky 报为 Trojan-PSW.Win32.Lineage.aih
Hacker.com.cn.exe(Kaspersky 报为 Backdoor.Win32.Hupigon.cgw,DrWeb 报为 BackDoor.Pigeon.36
msdll.dll(Kaspersky 报为 Trojan-PSW.Win32.Lineage.agl,DrWeb 报为 Trojan.PWS.Lineage
nt.exe(Kaspersky 报为 Trojan-Downloader.Win32.Small.dgc
nt.dll(Kaspersky 报为 Trojan-Downloader.Win32.Agent.apt
svhost32.exe(DrWeb 报为 Trojan.PWS.Lineage
Upzgy.exe

打包备份后删除。


关闭所有文件夹窗口,用HijackThis扫描并修复上面所列项目。

卸载:雅虎助手,LetsCool,Zcom

清空IE临时文件夹

清空 C:/Windows/temp 文件夹

清空 C:/Documents and Settings/user/Local Settings/temp 文件夹 

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 5
    评论
Sure! The Viking Age had a significant impact on Europe and beyond. Here are some of the key ways: 1. Exploration and Trade: The Vikings were skilled seafarers who traveled vast distances, discovering new lands and establishing trade routes. They traded in goods such as furs, timber, and fish, and also brought back luxury goods like silk, spices, and precious metals from their travels. 2. Military Conquest: The Vikings were also known for their military prowess and raided many parts of Europe, leaving a trail of destruction in their wake. They conquered and settled in many areas, including England, Scotland, Ireland, and parts of Russia. 3. Language and Culture: The Vikings had a distinct culture and language that influenced the areas they conquered and settled in. Old Norse words and phrases can still be found in many modern European languages, and traditional Viking art and mythology continue to fascinate people today. 4. Technology and Innovation: The Vikings were skilled at shipbuilding and navigation, and they also developed new weapons and tools. The longship, a type of Viking ship, was particularly innovative and allowed them to travel long distances quickly. 5. Social and Political Changes: The Viking Age also brought about significant social and political changes, with new forms of government and social hierarchy emerging in the areas they conquered and settled in. Overall, the Viking Age had a lasting impact on Europe and the world, shaping language, culture, technology, and politics for centuries to come.

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 5
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

紫郢剑侠

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值