1   1  /  1  页   跳转

紧急求救~

紧急求救~

Trojan.DL.Agent.fuh这个是什么病毒怎么删不掉
最后编辑2006-04-12 11:16:45
分享到:
gototop
 

【回复“酒醉的小强”的帖子】
病毒文件名称与路径?
gototop
 

C:\WINDOWS\KB759761.LOG
这个路径~
病毒名字Trojan.DL.Agent.fuh
我疯了~我机子怎么突然中了好多病毒
gototop
 

【回复“酒醉的小强”的帖子】
进入注册表
修改
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><KB759761.LOG>

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  <AppInit_DLLs><>

删除
C:\WINDOWS\KB759761.LOG
gototop
 

谢老大~一会帮我看看日志好吗?
gototop
 

Service Pack 是用以下命令行启动的:
***

---- Old Information In The Registry ------
***


Source:C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\New\FXSUI.DLL
Version:
***


Destination:C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\FXSUI.DLL
Version: 5.0.2.0
***




---- New Information In The Registry ------
***


Source:C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\New\FXSUI.DLL
Version:
***


Destination:C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\FXSUI.DLL
Version: 5.0.2.0
***

FetchSourceURL: SetupOpenInfFile Failed to open file: c:\37e38010181ed042eef3eab36c8bb046\sp2\update\update.url
***

DoInstallation: FetchSourceURL for  c:\37e38010181ed042eef3eab36c8bb046\sp2\update\update.inf Failed
***

LoadFileQueues: SetupGetSourceFileLocation for halaacpi.dll failed: 0xe0000102
***

BuildCabinetManifest:SetupOpenInfFile failed with error INVALID_HANDLE_VALUE
***

AnalyzePhaseZero used 0 ticks

***


No c:\windows\INF\updtblk.inf file.

***

SetupFindFirstLine in LoadExclusionList Failed with error: 0xe0000102
***

CreateUninstall = 1,Directory = C:\WINDOWS\$NtUninstallKB824146$
***

AnalyzePhaseOne: used 29750 ticks

***

AnalyzePhaseTwo used 0 ticks

***

AnalyzePhaseThree used 0 ticks

***

AnalyzePhaseFive used 0 ticks

***

AnalyzePhaseSix used 0 ticks

***

AnalyzeComponents used 29859 ticks

***


Downloading 0 files


***

bPatchMode = FALSE

***

Inventory complete: ReturnStatus=0, 29922 ticks

***

Num Ticks for invent : 29937

***

Allocation size of drive C: is 4096 bytes, free space = 13578207232 bytes

***

LoadFileQueues: SetupGetSourceFileLocation for halaacpi.dll failed: 0xe0000102
***

Drive C: free 12949MB req: 11MB w/uninstall 17MB

***

Num Ticks for download : 125

***

CabinetBuild complete

***

Num Ticks for Cabinet build : 0

***

LoadFileQueues: SetupGetSourceFileLocation for halaacpi.dll failed: 0xe0000102
***

Num Ticks for Backup : 188

***

Num Ticks for creating uninst inf : 31

***

Registering Uninstall Program for -> KB824146, KB824146 , 0x0
***

LoadFileQueues: SetupGetSourceFileLocation for halaacpi.dll failed: 0xe0000102
***

System Restore Point set.
***

复制的文件:  C:\WINDOWS\System32\spmsg.dll
***

SfcTurnOff: System is not Win2k < SP2; Not turning off SFC.
***

SfcTurnOff: SFC was not turned off; using MakeSfcFileException.
***

复制的文件:  C:\WINDOWS\System32\ole32.dll
***

复制的文件(延迟):  C:\WINDOWS\System32\SET89.tmp
***

复制的文件:  C:\WINDOWS\System32\rpcrt4.dll
***

复制的文件(延迟):  C:\WINDOWS\System32\SET8A.tmp
***

复制的文件:  C:\WINDOWS\System32\rpcss.dll
***

复制的文件(延迟):  C:\WINDOWS\System32\SET8B.tmp
***

复制的文件:  C:\WINDOWS\System32\DllCache\ole32.dll
***

复制的文件:  C:\WINDOWS\System32\DllCache\rpcrt4.dll
***

复制的文件:  C:\WINDOWS\System32\DllCache\rpcss.dll
***

Num Ticks for Copying files : 3875

***

Num Ticks for Reg update and deleting 0 size files : 16

***

UpdateSpUpdSvcInf: Source [ProcessesToRunAfterReboot] section is empty; nothing to do.
***

---- Old Information In The Registry ------
***


Source:C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\New\FXSUI.DLL
Version:
***


Destination:C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\FXSUI.DLL
Version: 5.0.2.0
***


Source:C:\WINDOWS\System32\SET89.tmp
Version: 5.1.2600.1263
***


Destination:C:\WINDOWS\System32\ole32.dll
Version: 5.0.1.0
***


Source:C:\WINDOWS\System32\SET8A.tmp
Version: 5.1.2600.1254
***


Destination:C:\WINDOWS\System32\rpcrt4.dll
Version: 5.0.1.0
***


Source:C:\WINDOWS\System32\SET8B.tmp
Version: 5.1.2600.1263
***


Destination:C:\WINDOWS\System32\rpcss.dll
Version: 5.0.1.0
***




---- New Information In The Registry ------
***


Source:C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\New\FXSUI.DLL
Version:
***


Destination:C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\FXSUI.DLL
Version: 5.0.2.0
***


Source:C:\WINDOWS\System32\SET89.tmp
Version: 5.1.2600.1263
***


Destination:C:\WINDOWS\System32\ole32.dll
Version: 5.0.1.0
***


Source:C:\WINDOWS\System32\SET8A.tmp
Version: 5.1.2600.1254
***


Destination:C:\WINDOWS\System32\rpcrt4.dll
Version: 5.0.1.0
***


Source:C:\WINDOWS\System32\SET8B.tmp
Version: 5.1.2600.1263
***


Destination:C:\WINDOWS\System32\rpcss.dll
Version: 5.0.1.0
***

RebootNecessary = 1,WizardInput = 1 , DontReboot = 0
***

帮我看下这个文件是不是病毒C:\WINDOWS\KB824146.LOG
gototop
 

老大不好了那个东西又出来了~
gototop
 

【回复“酒醉的小强”的帖子】
C:\WINDOWS\$NtUninstallKB824146$这一项有问题

http://forum.ikaka.com/topic.asp?board=28&artid=6979213
下载HIJACKTHIS
导出全部日志
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT