瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】已在论坛求助三天!紧急呼救:backdoor.bifrose.ch该如何彻底杀死

1234   2  /  4  页   跳转

【求助】已在论坛求助三天!紧急呼救:backdoor.bifrose.ch该如何彻底杀死

+ SENS跟踪系统事件,如登录 Windows,网络以及电源事件等。将这些事件通知给 COM+ 事件系统 “订阅者(subscriber)”。Microsoft Corporationd:\windows\system32\svchost.exe

+ SharedAccess为家庭和小型办公网络提供网络地址转换、寻址、名称解析和/或入侵保护服务。Microsoft Corporationd:\windows\system32\svchost.exe

+ ShellHWDetection为自动播放硬件事件提供通知。Microsoft Corporationd:\windows\system32\svchost.exe

+ Spooler将文件加载到内存中以便迟后打印。Microsoft Corporationd:\windows\system32\spoolsv.exe

+ srservice执行系统还原功能。 要停止服务,请从“我的电脑”的属性中的系统还原选项卡关闭系统还原Microsoft Corporationd:\windows\system32\svchost.exe

+ Themes为用户提供使用主题管理的经验。Microsoft Corporationd:\windows\system32\svchost.exe

+ TrkWks在计算机内 NTFS 文件之间保持链接或在网络域中的计算机之间保持链接。Microsoft Corporationd:\windows\system32\svchost.exe

+ W32Time维护在网络上的所有客户端和服务器的时间和日期同步。如果此服务被停止,时间和日期的同步将不可用。如果此服务被禁用,任何明确依赖它的服务都将不能启动。

Microsoft Corporationd:\windows\system32\svchost.exe

+ WebClient使基于 Windows 的程序能创建、访问和修改基于 Internet 的文件。如果此服务被终止,将会失去这些功能。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationd:\windows\system32\svchost.exe

+ winmgmt提供共同的界面和对象模式以便访问有关操作系统、设备、应用程序和服务的管理信息。如果此服务被终止,多数基于 Windows 的软件将无法正常运行。如果此服务被禁用,任何依赖它的服务将无法启动。Microsoft Corporationd:\windows\system32\svchost.exe

+ wscsvc监视系统安全设置和配置。Microsoft Corporationd:\windows\system32\svchost.exe

+ wuauserv允许下载并安装 Windows 更新。如果此服务被禁用,计算机将不能使用 Windows Update 网站的自动更新功能。Microsoft Corporationd:\windows\system32\svchost.exe

+ WZCSVC为您的 802.11 适配器提供自动配置Microsoft Corporationd:\windows\system32\svchost.exe

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components

+ Internet ExplorerWindows NT User Data Migration ToolMicrosoft Corporationd:\windows\system32\shmgrate.exe

+ Internet Explorer 6IE 5.0 Per-User Install UtilityMicrosoft Corporationd:\windows\system32\ie4uinit.exe

+ Microsoft Outlook Express 6Outlook Express Setup LibraryMicrosoft Corporationd:\program files\outlook express\setup50.exe

+ Microsoft Windows Media PlayerMicrosoft Windows Media Player 安装实用程序Microsoft Corporationd:\windows\inf\unregmp2.exe

+ Microsoft Windows Media PlayerADVPACKMicrosoft Corporationd:\windows\system32\advpack.dll

+ NetMeeting 3.01ADVPACKMicrosoft Corporationd:\windows\system32\advpack.dll

+ Outlook ExpressWindows NT User Data Migration ToolMicrosoft Corporationd:\windows\system32\shmgrate.exe

+ Themes SetupMicrosoft(C) Register ServerMicrosoft Corporationd:\windows\system32\regsvr32.exe

+ Windows Messenger 4.7ADVPACKMicrosoft Corporationd:\windows\system32\advpack.dll

+ Windows 桌面更新Microsoft(C) Register ServerMicrosoft Corporationd:\windows\system32\regsvr32.exe

+ 通讯簿 6Outlook Express Setup LibraryMicrosoft Corporationd:\program files\outlook express\setup50.exe

+ 浏览器自定义组件Microsoft Internet Explorer Customization DLLMicrosoft Corporationd:\windows\system32\iedkcs32.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler

+ Browseui 预加载程序Shell Browser UI LibraryMicrosoft Corporationd:\windows\system32\browseui.dll

+ 组件类别缓存程序Shell Browser UI LibraryMicrosoft Corporationd:\windows\system32\browseui.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

+ CDBurnWindows Shell Common DllMicrosoft Corporationd:\windows\system32\shell32.dll

+ PostBootReminderWindows Shell Common DllMicrosoft Corporationd:\windows\system32\shell32.dll

+ SysTraySystray shell service objectMicrosoft Corporationd:\windows\system32\stobject.dll

+ WebCheckWeb Site MonitorMicrosoft Corporationd:\windows\system32\webcheck.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ shell32.dllWindows Shell Common DllMicrosoft Corporationd:\windows\system32\shell32.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Auto Update Property Sheet ExtensionAutomatic Updates Control PanelMicrosoft Corporationd:\windows\system32\wuaucpl.cpl

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.d:\windows\system32\ravext.dll

+ WIBU-SYSTEMS Shell ExtensionWIBU-SYSTEMS Shell Extension HandlerWIBU-SYSTEMS AGd:\program files\wibu-systems\system\wibushellext.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Web 文件夹d:\program files\common files\microsoft shared\web folders\msonsext.dll

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ WIBU-SYSTEMS Shell ExtensionWIBU-SYSTEMS Shell Extension HandlerWIBU-SYSTEMS AGd:\program files\wibu-systems\system\wibushellext.dll

+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871}Windows Shell Common DllMicrosoft Corporationd:\windows\system32\shell32.dll

+ {24F14F01-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationd:\windows\system32\shell32.dll

+ {24F14F02-7B1C-11d1-838f-0000F80461CF}Windows Shell Common DllMicrosoft Corporationd:\windows\system32\shell32.dll

+ {66742402-F9B9-11D1-A202-0000F81FEDEE}Windows Shell Common DllMicrosoft Corporationd:\windows\system32\shell32.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ IeCatch2 Classjccatch ModuleAmaze Softd:\program files\flashget\jccatch.dll

+ NaviHelperObj ClassTODO: <文件说明>TODO: <公司名>d:\windows\system32\navihelper.dll

+ Router LayerFile not found: D:\WINDOWS\System32\aclayer.dll

+ ThunderIEHelper Classxunleibho Moduled:\windows\system32\xunleibho_v4.dll

HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks

+ shdocvw.dllShell Doc Object and Control LibraryMicrosoft Corporationd:\windows\system32\shdocvw.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ FlashGet BarFlashGet IE BarAmaze Softd:\program files\flashget\fgiebar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ &FlashGetFlashGetAmaze Softd:\program files\flashget\flashget.exe

+ Windows MessengerWindows MessengerMicrosoft Corporationd:\program files\messenger\msmsgs.exe

HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute

+ autocheck autochk *Auto Check UtilityMicrosoft Corporationd:\windows\system32\autochk.exe

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

+ Your Image File Name Here without a pathSymbolic Debugger for Windows 2000Microsoft Corporationd:\windows\system32\ntsd.exe

HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls
gototop
 

+ advapi32Advanced Windows 32 Base APIMicrosoft Corporationd:\windows\system32\advapi32.dll

+ comdlg32Common Dialogs DLLMicrosoft Corporationd:\windows\system32\comdlg32.dll

+ gdi32GDI Client DLLMicrosoft Corporationd:\windows\system32\gdi32.dll

+ imagehlpWindows NT Image HelperMicrosoft Corporationd:\windows\system32\imagehlp.dll

+ kernel32Windows NT BASE API Client DLLMicrosoft Corporationd:\windows\system32\kernel32.dll

+ lz32LZ Expand/Compress API DLLMicrosoft Corporationd:\windows\system32\lz32.dll

+ ole32Microsoft OLE for WindowsMicrosoft Corporationd:\windows\system32\ole32.dll

+ oleaut32Microsoft Corporationd:\windows\system32\oleaut32.dll

+ olecli32Object Linking and Embedding Client LibraryMicrosoft Corporationd:\windows\system32\olecli32.dll

+ olecnv32Microsoft OLE for WindowsMicrosoft Corporationd:\windows\system32\olecnv32.dll

+ olesvr32Object Linking and Embedding Server LibraryMicrosoft Corporationd:\windows\system32\olesvr32.dll

+ olethk32Microsoft OLE for WindowsMicrosoft Corporationd:\windows\system32\olethk32.dll

+ rpcrt4Remote Procedure Call RuntimeMicrosoft Corporationd:\windows\system32\rpcrt4.dll

+ shell32Windows Shell Common DllMicrosoft Corporationd:\windows\system32\shell32.dll

+ urlInternet Shortcut Shell Extension DLLMicrosoft Corporationd:\windows\system32\url.dll

+ urlmonOLE32 Extensions for Win32Microsoft Corporationd:\windows\system32\urlmon.dll

+ user32Windows XP USER API Client DLLMicrosoft Corporationd:\windows\system32\user32.dll

+ versionVersion Checking and File Installation LibrariesMicrosoft Corporationd:\windows\system32\version.dll

+ wininetInternet Extensions for Win32Microsoft Corporationd:\windows\system32\wininet.dll

+ wldap32Win32 LDAP API DLLMicrosoft Corporationd:\windows\system32\wldap32.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ AtiExtEventATI External Event Utility DLL ModuleATI Technologies Inc.d:\windows\system32\ati2evxx.dll

+ cscdllOffline Network AgentMicrosoft Corporationd:\windows\system32\cscdll.dll

+ ScCertPropCommon DLL to receive Winlogon notificationsMicrosoft Corporationd:\windows\system32\wlnotify.dll

+ ScheduleCommon DLL to receive Winlogon notificationsMicrosoft Corporationd:\windows\system32\wlnotify.dll

+ SensLognCommon DLL to receive Winlogon notificationsMicrosoft Corporationd:\windows\system32\wlnotify.dll

+ termsrvCommon DLL to receive Winlogon notificationsMicrosoft Corporationd:\windows\system32\wlnotify.dll

+ wlballoonCommon DLL to receive Winlogon notificationsMicrosoft Corporationd:\windows\system32\wlnotify.dll

HKCU\Control Panel\Desktop\Scrnsave.exe

+ D:\WINDOWS\system32\logon.scrLogon Screen SaverMicrosoft Corporationd:\windows\system32\logon.scr

HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{6CA71201-523D-4022-8866-F9227BF5E44D}] DATAGRAM 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationd:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{6CA71201-523D-4022-8866-F9227BF5E44D}] SEQPACKET 4Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationd:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{96A848CC-7D97-4904-BA42-B28D274488F4}] DATAGRAM 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationd:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{96A848CC-7D97-4904-BA42-B28D274488F4}] SEQPACKET 0Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationd:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{9AA1A179-E420-45EA-AE46-58FD46E37A82}] DATAGRAM 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationd:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{9AA1A179-E420-45EA-AE46-58FD46E37A82}] SEQPACKET 2Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationd:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F4CCEF72-A5E6-4933-8519-05D078D8EAA3}] DATAGRAM 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationd:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F4CCEF72-A5E6-4933-8519-05D078D8EAA3}] SEQPACKET 3Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationd:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F774F100-7EC6-4138-81B7-EEAFF3550324}] DATAGRAM 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationd:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{F774F100-7EC6-4138-81B7-EEAFF3550324}] SEQPACKET 1Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationd:\windows\system32\mswsock.dll

+ MSAFD Tcpip [RAW/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationd:\windows\system32\mswsock.dll

+ MSAFD Tcpip [TCP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationd:\windows\system32\mswsock.dll

+ MSAFD Tcpip [UDP/IP]Microsoft Windows Sockets 2.0 Service ProviderMicrosoft Corporationd:\windows\system32\mswsock.dll

+ RSVP TCP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationd:\windows\system32\rsvpsp.dll

+ RSVP UDP Service ProviderMicrosoft Windows Rsvp 1.0 Service ProviderMicrosoft Corporationd:\windows\system32\rsvpsp.dll

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ BJ Language MonitorLangage Monitor for Canon Bubble-Jet PrinterMicrosoft Corporationd:\windows\system32\cnbjmon.dll

+ Local PortLocal Spooler DLLMicrosoft Corporationd:\windows\system32\localspl.dll

+ PJL Language MonitorPJL Language monitorMicrosoft Corporationd:\windows\system32\pjlmon.dll

+ Standard TCP/IP PortStandard TCP/IP Port Monitor DLLMicrosoft Corporationd:\windows\system32\tcpmon.dll

+ USB MonitorStandard Dynamic Printing Port Monitor DLLMicrosoft Corporationd:\windows\system32\usbmon.dll

gototop
 

已经用AUTORUNS输出了日志,请DX详细指点下如何杀毒,不胜感激啊!
gototop
 

引用:
【小笛的贴子】回楼上老大,我也是受害者,我这路径是C:\Program Files\Internet Explorer\iexplore.exe ->Backdoor.Bifrose.ch,请救命
...........................

我的路径也是差不多,因为装双系统, 是在D盘,请多指教!
gototop
 

请大家多帮助!谢谢!
gototop
 

请大家帮忙啊!!!
gototop
 

用HijackThis扫个日志上来~~~
下载地址~~
http://forum.ikaka.com/topic.asp?board=28&artid=6979213
gototop
 

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      20:58:11, 日期 2005-11-12
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\PROGRAM FILES\RISING\RAV\Ravmond.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
D:\PROGRA~1\RISING\RAV\RAVMON.EXE
D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Tencent\TT\TTraveler.exe
D:\Program Files\BitComet\BitComet.exe
D:\Documents and Settings\we00\My Documents\查杀木马\2535952005811174944\HijackThis1991zww.exe

O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - D:\WINDOWS\system32\xunleibho_v4.dll
O2 - BHO: NaviHelperObj Class - {3E422F49-1566-40D3-B43D-077EF739AC32} - D:\WINDOWS\system32\NaviHelper.dll
O2 - BHO: Router Layer - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - D:\WINDOWS\System32\aclayer.dll (file missing)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FLASHGET\jccatch.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\fgiebar.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - 启动项HKLM\\Run: [RavTimer] D:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [RavMon] D:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [StormCodec_Helper] "D:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - 启动项HKLM\\Run: [AtiPTA] atiptaxx.exe
O4 - 启动项HKLM\\Run: [zcom] \zPlatform.exe MIN
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: 核新SSL通讯安全代理.lnk = D:\Program Files\hexin\sslproxy\SSLCnt.exe
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\Program Files\FlashGet\jc_all.htm
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128608836045
O17 - HKLM\System\CCS\Services\Tcpip\..\{6CA71201-523D-4022-8866-F9227BF5E44D}: NameServer = 218.85.157.99 202.101.98.55
O17 - HKLM\System\CCS\Services\Tcpip\..\{96A848CC-7D97-4904-BA42-B28D274488F4}: NameServer = 202.101.98.55,202.101.98.54
O17 - HKLM\System\CS1\Services\Tcpip\..\{6CA71201-523D-4022-8866-F9227BF5E44D}: NameServer = 218.85.157.99 202.101.98.55
O23 - NT 服务: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - D:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - D:\PROGRAM FILES\RISING\RAV\Ravmond.exe

日志已扫描如上,请帮忙分析,万分感谢!
gototop
 

O4 - 启动项HKLM\\Run: [zcom] \zPlatform.exe MIN
没看到鸽子,但看到 个不认识的东西~~~
不像是好东西~~
gototop
 

用什么能把那个屏蔽掉呢?
gototop
 
1234   2  /  4  页   跳转
页面顶部
Powered by Discuz!NT