瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了Backdoor.Bifrose.fw,高手来帮我看看HijackThis的log!

12   2  /  2  页   跳转

中了Backdoor.Bifrose.fw,高手来帮我看看HijackThis的log!

好了高手^-^,我重新导出了日志,你帮我看看。
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ MoveSearchFile not found: C:\Program Files\HuaCi\huaci\zsearch.exe

+ RavTaskRavTimerBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravtask.exe

+ SoundManRealtek Sound ManagerRealtek Semiconductor Corp.c:\winnt\soundman.exe

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components

+ NVMLCFile not found: C:\WINNT\system32\ronvidiat.dll

+ NVSOFTRoNVidiaRoNVidiac:\winnt\system32\nvcsystem.dll

+ WinMediaFile not found: C:\WINNT\system32\nvbworks.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ Rising Execute File Exts hookRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ RISINGRising Shell Ext ModuleBeijing Rising Technology Co., Ltd.c:\winnt\system32\ravext.dll

+ Shell Extensions for RealOne PlayerRealPlayer Shell ExtensionsRealNetworks, Inc.c:\program files\real\realone player\rpshell.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ BandIE ClassBaiduBar ModuleBaidu.com, Inc.c:\program files\baidu\bar\baidubar.dll

+ CNNIC_IDNCndnIEHelper Modulec:\winnt\system32\cdniehlp.dll

+ Google Toolbar HelperGoogle IE Client ToolbarGoogle Inc.c:\program files\google\googletoolbar1.dll

+ IeCatch2 Classjccatch ModuleAmaze Softc:\program files\flashget\jccatch.dll

+ QQBrowserHelperObject ClassQQIEHelper Module深圳市腾讯计算机系统有限公司c:\program files\tencent\qq\qqiehelper.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ FlashGet BarFlashGet IE BarAmaze Softc:\program files\flashget\fgiebar.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ &FlashGetFlashGetAmaze Softc:\program files\flashget\flashget.exe

+ @shdoclc.dll,-864c:\winnt\web\related.htm

+ 清理上网记录File not found: http://assistant.3721.com/clean1.htm?fb=Cns

+ 情景聊天File not found: http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/

+ 上网助手File not found: http://assistant.3721.com/index.htm?fb=Cns

+ 手机短信File not found: http://sms.3721.com/ie/index.htm

+ 腾讯QQQQTENCENTc:\program files\tencent\qq\qq.exe

+ 修复浏览器File not found: http://assistant.3721.com/security1.htm?fb=Cns

HKLM\System\CurrentControlSet\Services

+ RsCCenterCCenterBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ccenter.exe

+ RsRavMonRavMondBeijing Rising Technology Co., Ltd.c:\program files\rising\rav\ravmond.exe

HKLM\System\CurrentControlSet\Services

+ AHOOKc:\winnt\system32\drivers\ahook.sys

+ ALCXWDMRealtek AC'97 Audio Driver (WDM)Realtek Semiconductor Corp.c:\winnt\system32\drivers\alcxwdm.sys

+ AnfadFile not found: system32\drivers\Anfad.sys

+ BaseTDIbasetdiBeijing Rising Technology Co., Ltd.c:\winnt\system32\drivers\basetdi.sys

+ CdnHookc:\winnt\system32\drivers\cdnhook.sys

+ dmioNT Disk Manager I/O DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmio.sys

+ dmloadNT Disk Manager Startup DriverVERITAS Software Corp.c:\winnt\system32\drivers\dmload.sys

+ ExpScanerExpScan.sysc:\program files\rising\rav\expscan.sys

+ FADFAD Filter DriverFile not found: system32\DRIVERS\FAD.sys

+ HOOKAPIHOOKAPI Driver瑞星软件有限公司c:\program files\rising\rav\hookapi.sys

+ HookContTDI HOOK DriverRising tech Co. ltdc:\program files\rising\rav\hookcont.sys

+ HookRegc:\program files\rising\rav\hookreg.sys

+ HookSysHooksysRisingc:\program files\rising\rav\hooksys.sys

+ ialmController Hub for Intel Graphics DriverIntel Corporationc:\winnt\system32\drivers\ialmnt5.sys

+ IPHOOKIP HOOK DriverBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\iphook.sys

+ MEMSCANMemScan Driver瑞星软件有限公司c:\program files\rising\rav\memscan.sys

+ New0c:\winnt\system32\new.sys

+ PtilinkDirect Parallel Link DriverParallel Technologies, Inc.c:\winnt\system32\drivers\ptilink.sys

+ rtl8139NDIS 5.0 driver                                                                  Realtek Semiconductor Corporation                                                c:\winnt\system32\drivers\rtl8139.sys

+ SONYPVM1Sony Memory Stick Disk DriverSony Corporationc:\winnt\system32\drivers\sonypvm1.sys

+ SONYPVU1Sony USB Lower Filter driverSony Corporationc:\winnt\system32\drivers\sonypvu1.sys

+ SR_M180YMDC-3071 MP3 Player Device DriverYountel Corporationc:\winnt\system32\drivers\srm180.sys

+ TDIHOOKTDI HOOK DriverBeijing Rising Technology Corporation Limitedc:\program files\rising\rfw\tdihook.sys

+ WINIOFile not found: C:\Program Files\Winamp\superlyrics\winio.sys

+ {6080A529-897E-4629-A488-ABA0C29B635E}Intel Graphics Platform (SoftBIOS) Driver for Windows 2000(R) & Windows XP(TM)Intel Corporationc:\winnt\system32\drivers\ialmsbw.sys

+ {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}Intel Graphics Chipset (KCH) Driver for Windows 2000(R) & Windows XP(TM)Intel Corporationc:\winnt\system32\drivers\ialmkchw.sys

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ igfxcuiigfxsrvc ModuleIntel Corporationc:\winnt\system32\igfxsrvc.dll

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ Canon BJ Language Monitor S200SPBJ Language MonitorCANON INC.c:\winnt\system32\cnmlm3y.dll

+ EPSON V3 2KMonitor371EPSON Bidirectional MonitorSEIKO EPSON CORPORATIONc:\winnt\system32\e_sl2371.dll

gototop
 

谁帮我看看出了什么问题啊!
gototop
 

杀毒的时候出现在内存的iexplore.exe是病毒!!!帮我看看
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT