这个灰鸽子杀了好久都杀不了,那位高手请帮忙一下,所有的专杀都用过了,可是没用,病毒提示在
iexplore.exe>>C:\Program Files\Internet Explorer\iexplore.exe ->Backdoor.Bifrose.ch,可是在Internet Explorer里能杀吗?谢谢@
Logfile of HijackThis v1.99.1
Scan saved at 0:27:21, on 2006-1-1
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\rising\rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Common
Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
D:\BitComet_0.56\BitComet\BitComet\BitComet.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\rising\rfw\rfwmain.exe
C:\Program Files\rising\rav\CopyRun\RavCopy.exe
G:\Temp\hijackthis.zip 的临时目录 4\HijackThis.exe
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-
84F9-1D9571695F55} - C:\WINDOWS\system32
\xunleibho_v6.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-
B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0
\ActiveX\AcroIEHelper.dll
O2 - BHO: NaviHelperObj Class - {3E422F49-1566-40D3-
B43D-077EF739AC32} - C:\WINDOWS\system32\NaviHelper.dll
(file missing)
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-
5587F9B7E191} - (no file)
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-
6C02E8FA9838} - C:\WINDOWS\SYSTEM32\stdup.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-
0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-
0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: MSN 工具栏 - {BDAD1DAD-C946-4A17-ADC1-
64B5B4FF55D0} - C:\Program Files\MSN
Toolbar\01.01.2607.0\zh-cn\msntb.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1
\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program
Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB
PC Camera 301P
O4 - HKLM\..\Run: [NMGameX_AutoRun] C:\WINDOWS\system32
\Rundll32.exe NMGameX.dll,LiveProcess /aa
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%
\system32\dumprep 0 -u
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%
\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RfwMain] "C:\Program
Files\rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "C:\Program
Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\RunServices: [RavMon] C:\Program
Files\rising\rav\RavMon.exe /AUTO
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32
\ctfmon.exe
O8 - Extra context menu item: 使用网际快车下载 -
C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 -
C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 -
C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program
Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 -
C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 豪杰超级解霸V8实时播放 -
C:\Herosoft\HeroV8\MPURLGET.HTM
O9 - Extra button: 豪杰超级解霸V8 - {367E0A21-8601-4986
-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21
-8601-4986-9C9A-153BF5ACA118} - C:\Herosoft\HeroV8
\STHSDVD.EXE
O9 - Extra button: 常用网址 - {36B39F01-7B48-44AD-A165-
5849CD8EF562} - C:\WINDOWS\system32\SHDOCVW.DLL
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF
-5587F9B7E191} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 -
{6671A433-5C3D-463d-A7CF-5587F9B7E191} -
C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-
00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-
11d2-a20b-00aa003c157b} - C:\Program
Files\Tencent\QQ\QQ.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-
0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5
-11d4-8D29-0050BA6940E3} - C:\PROGRA~1
\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E
-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O16 - DPF: {1F831FA1-42FC-11D4-95A6-0080AD30DCE1}
(InstaFred) -
file://C:\Program Files\AutoCAD 2002
\InstFred.ocx
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E}
(WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN
Photo Upload Tool) -
http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD}
(AxInputControl Class) -
https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.c
ab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122}
(AcDcToday 控件) -
file://C:\Program Files\AutoCAD 2002
\AcDcToday.ocx
O16 - DPF: {AE563722-B4F5-11D4-A415-00108302FDFD}
(NOXLATE-BANR) -
file://C:\Program Files\AutoCAD 2002
\InstBanr.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
(MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownl
oader.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153}
(Rising Web Scan
Object) -
http://download.rising.com.cn/register/pcver/autoupgrade
pad/Ver2005/OL2005.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD}
(AcPreview 控件) -
file://C:\Program Files\AutoCAD 2002
\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{273D5668-D45E-
41CE-9CC5-93449BD76359}: NameServer = 218.85.157.99
202.101.115.55
O18 - Protocol: mbox - {7DEE9D05-FA0A-4416-A6F3-
6537D0EAB6A6} - (no file)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-
8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file
missing)
O23 - Service: Kodak Camera Connection Software
(KodakCCS) - Eastman Kodak Company -
C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Rising Personal Firewall Service
(RfwService) - Beijing Rising Technology Co., Ltd. -
c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center
(RsCCenter) - Beijing Rising Technology Co., Ltd. -
C:\Program Files\rising\rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing
Rising Technology Co., Ltd. - C:\Program
Files\Rising\Rav\Ravmond.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony
Corporation - C:\Program Files\Common Files\Sony
Shared\AVLib\SPTISRV.exe