虽然瑞星显示清除了,但每次重启电脑再杀又会有,哪为高人教下怎么根除哦,感染路径是IEXPLORE.EXE>>C:\program files\internet explorer\IEXPLORE.EXE,下面是扫描日志:
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 23:21:03, 日期 2006-9-18
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
d:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
d:\Program Files\Rising\Rav\Ravmond.exe
d:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Sogou PXP\p2psvr.exe
C:\windows\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
d:\program files\rising\rfw\RfwMain.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Rising\Rav\RavTask.exe
D:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\ALCATE~1\LinkSetup\AlcatelMobilePhoneDetect.exe
C:\Program Files\Internet Explorer\iexplore.exe
d:\Program Files\Real\RealPlayer\RealPlay.exe
E:\Downloads\HijackThis1[1].99.1\HijackThis1991zww.exe
O1 - Hosts: 218.88.187.189 nprotect.ryl.com.cn
O1 - Hosts: 218.88.187.189 login.ryl.com.cn
O1 - Hosts: 218.88.187.189 www.ryl.com.cn
O1 - Hosts: 218.88.187.189 patch.ryl.com.cn
O1 - Hosts: 218.88.187.189 list.ryl.com.cn
O1 - Hosts: 218.88.187.189 update.ryl.com.cn
O1 - Hosts: 218.88.187.189 nprotect.wol004.com
O1 - Hosts: 218.88.187.189 patch.wol004.com
O1 - Hosts: 218.88.187.189 www.ryl.in.th
O1 - Hosts: 218.88.187.189 Login.wol004.com
O1 - Hosts: 218.88.187.189 game.ryl.com.my
O1 - Hosts: 218.88.187.189 patch.ryl.com.my
O1 - Hosts: 218.88.187.189 www.ryl.com.my
O1 - Hosts: 218.88.187.189 www.ryl-china.com
O1 - Hosts: 218.88.187.189 reg.ryl-china.com
O2 - BHO: NaviHelperObj Class - {3E422F49-1566-40D3-B43D-077EF739AC32} - C:\WINDOWS\NaviHelper.dll
O2 - BHO: Router Layer - {5EB7CB50-E375-4718-B4C0-9AD12EFA2F84} - C:\WINDOWS\System32\aclayer.dll (file missing)
O2 - BHO: Helper Class - {6E28339B-7A2A-47B6-AEB2-197004272379} - C:\WINDOWS\vchelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - D:\PROGRA~1\KuGoo3\KUGOO3~1.OCX
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\fgiebar.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - 启动项HKLM\\Run: [Phone Detect 4] C:\PROGRA~1\ALCATE~1\LinkSetup\PhoneDetectLaunch.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [KernelFaultCheck] ; %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [DAEMON Tools] "d:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - 启动项HKLM\\Run: [DAEMON Tools-2052] ; "D:\Program Files\D-Tools\daemon.exe" -lang 2052
O4 - 启动项HKLM\\Run: [helper.dll] ; C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - 启动项HKLM\\Run: [RavTask] "d:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [RfwMain] "d:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe
O4 - HKCU\..\Run: [cd9729c21235ab28de41f89afa0d0461] ; "E:\Downloads\xlqy2_Release.exe"
O4 - HKCU\..\Run: [Xplus_spy] ; "d:\Program Files\Xplus\xvcclip.exe" /min