瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 如何杀Backdoor.Bifrose.ch,请高手请帮忙一下
苏怡echo - 2006-1-1 0:36:00
这个灰鸽子杀了好久都杀不了,那位高手请帮忙一下,所有的专杀都用过了,可是没用,病毒提示在iexplore.exe>>C:\Program Files\Internet Explorer\iexplore.exe ->Backdoor.Bifrose.ch,可是在Internet Explorer里能杀吗?谢谢@

Logfile of HijackThis v1.99.1
Scan saved at 0:27:21, on 2006-1-1
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\rising\rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Common

Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
D:\BitComet_0.56\BitComet\BitComet\BitComet.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\rising\rfw\rfwmain.exe
C:\Program Files\rising\rav\CopyRun\RavCopy.exe
G:\Temp\hijackthis.zip 的临时目录 4\HijackThis.exe

O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-

84F9-1D9571695F55} - C:\WINDOWS\system32

\xunleibho_v6.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-

B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0

\ActiveX\AcroIEHelper.dll
O2 - BHO: NaviHelperObj Class - {3E422F49-1566-40D3-

B43D-077EF739AC32} - C:\WINDOWS\system32\NaviHelper.dll

(file missing)
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-

5587F9B7E191} - (no file)
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-

6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-

0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-

0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: MSN 工具栏 - {BDAD1DAD-C946-4A17-ADC1-

64B5B4FF55D0} - C:\Program Files\MSN

Toolbar\01.01.2607.0\zh-cn\msntb.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1

\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32

\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32

\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program

Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB

PC Camera 301P
O4 - HKLM\..\Run: [NMGameX_AutoRun] C:\WINDOWS\system32

\Rundll32.exe NMGameX.dll,LiveProcess /aa
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%

\system32\dumprep 0 -u
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%

\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common

Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RfwMain] "C:\Program

Files\rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "C:\Program

Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\RunServices: [RavMon] C:\Program

Files\rising\rav\RavMon.exe /AUTO
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32

\ctfmon.exe
O8 - Extra context menu item: 使用网际快车下载 -

C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 -

C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 -

C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program

Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 -

C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 豪杰超级解霸V8实时播放 -

C:\Herosoft\HeroV8\MPURLGET.HTM
O9 - Extra button: 豪杰超级解霸V8 - {367E0A21-8601-4986

-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21

-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8

\STHSDVD.EXE
O9 - Extra button: 常用网址 - {36B39F01-7B48-44AD-A165-

5849CD8EF562} - C:\WINDOWS\system32\SHDOCVW.DLL
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF

-5587F9B7E191} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 -

{6671A433-5C3D-463d-A7CF-5587F9B7E191} -

C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-

00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-

11d2-a20b-00aa003c157b} - C:\Program

Files\Tencent\QQ\QQ.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-

0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5

-11d4-8D29-0050BA6940E3} - C:\PROGRA~1

\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E

-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {1F831FA1-42FC-11D4-95A6-0080AD30DCE1}

(InstaFred) - file://C:\Program Files\AutoCAD 2002

\InstFred.ocx
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E}

(WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN

Photo Upload Tool) -

http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD}

(AxInputControl Class) -

https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.c

ab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122}

(AcDcToday 控件) - file://C:\Program Files\AutoCAD 2002

\AcDcToday.ocx
O16 - DPF: {AE563722-B4F5-11D4-A415-00108302FDFD}

(NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002

\InstBanr.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}

(MsnMessengerSetupDownloadControl Class) -

http://messenger.msn.com/download/MsnMessengerSetupDownl

oader.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153}

(Rising Web Scan Object) -

http://download.rising.com.cn/register/pcver/autoupgrade

pad/Ver2005/OL2005.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD}

(AcPreview 控件) - file://C:\Program Files\AutoCAD 2002

\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{273D5668-D45E-

41CE-9CC5-93449BD76359}: NameServer = 218.85.157.99

202.101.115.55
O18 - Protocol: mbox - {7DEE9D05-FA0A-4416-A6F3-

6537D0EAB6A6} - (no file)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-

8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file

missing)
O23 - Service: Kodak Camera Connection Software

(KodakCCS) - Eastman Kodak Company -

C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Rising Personal Firewall Service

(RfwService) - Beijing Rising Technology Co., Ltd. -

c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center

(RsCCenter) - Beijing Rising Technology Co., Ltd. -

C:\Program Files\rising\rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing

Rising Technology Co., Ltd. - C:\Program

Files\Rising\Rav\Ravmond.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony

Corporation - C:\Program Files\Common Files\Sony

Shared\AVLib\SPTISRV.exe
1
查看完整版本: 如何杀Backdoor.Bifrose.ch,请高手请帮忙一下