12   1  /  2  页   跳转

[求助] trojan.clicker.win32.agent.eja

trojan.clicker.win32.agent.eja

我的电脑瑞星杀毒软甲检查出中了一个病毒,是trojan.clicker.win32.agent.eja,这个是什么啊?我要怎么办?为什么我杀不掉?急啊!那位高人一定要指点指点啊!

用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.0.04506)
分享到:
gototop
 

回复:trojan.clicker.win32.agent.eja

先升级瑞星到最新版本,而后断网杀毒。
如果第一次查杀发现有病毒,则需要重启动计算机,再杀第二遍。
如果第二遍查杀没有病毒了,则说明原病毒是外界传播进来的,需要对系统修补漏洞,加装防火墙,做好防护。
如果第二遍查杀还是有病毒,则说明该病毒是瑞星当前版本无法清除的,需要扫SRENG日志发这论坛来
下载SRENG2.6版工具:http://www.kztechs.com/sreng/download.html
SRENG工具的扫描日志操作,看这贴2楼:http://bbs.ikaka.com/showtopic-8442813.aspx
╭∩╮(︶︿︶)╭∩╮
gototop
 

回复 2F 帅哥阿福 的帖子

我下载了sreng2.6的那个工具,要把哪个日志弄上去啊
gototop
 

回复:trojan.clicker.win32.agent.eja

SRENG工具的扫描日志操作,看这贴2楼:http://bbs.ikaka.com/showtopic-8442813.aspx
将SREngLOG.log文件上报到这里。
╭∩╮(︶︿︶)╭∩╮
gototop
 

回复:trojan.clicker.win32.agent.eja

我晕!这是什么病毒啊!
gototop
 

回复:trojan.clicker.win32.agent.eja

看不懂啊……这个是智能扫描后得到的,是不是啊?

70013    C:\PROGRAM FILES\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\ACROIEHELPER.DLL
70000    C:\PROGRA~1\JUMPST~1\JSWPSAPI.EXE
70012    C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DSBHO_01.DLL
70013    C:\WINDOWS\SYSTEM32\ATIUMDAG.DLL
70000    C:\PROGRAM FILES\COMMON FILES\MACROMEDIA SHARED\SERVICE\MACROMEDIA LICENSING.EXE
70000    C:\PROGRA~1\COMMON~1\ULEADS~1\DVD\ULCDRSVR.EXE
70000    C:\WINDOWS\SYSTEM32\TODDSRV.EXE
70000    E:\下载的~1\STORM\STORMLIV.EXE
70012    C:\WINDOWS\SYSTEM32\RAVEXT.DLL
70004    C:\PROGRAM FILES\360\360SAFE\SAFEMON\360TRAY.EXE
70012    C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_01.DLL
70004    C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\CLISTART.EXE
70013    C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
70004    C:\PROGRAM FILES\TOSHIBA\TOSCDSPD\TOSCDSPD.EXE
70000    C:\PROGRAM FILES\TOSHIBA\SMARTLOGSERVICE\TOSIPCSRV.EXE
70012    C:\WINDOWS\SYSTEM32\MSVCP71.DLL
70004    C:\PROGRAM FILES\ADOBE\READER 9.0\READER\READER_SL.EXE
70015    C:\WINDOWS\SYSTEM32\UXTHEME.DLL
70013    C:\PROGRAM FILES\JAVA\JRE1.6.0_03\BIN\SSV.DLL
70004    C:\PROGRAM FILES\TOSHIBA\FLASHCARDS\TCRDMAIN.EXE
70012    C:\PROGRAM FILES\360\360SAFE\SAFEMON\SAFEMON.DLL
70004    C:\PROGRAM FILES\CAMERA ASSISTANT SOFTWARE FOR TOSHIBA\TRAYBAR.EXE
70004    C:\WINDOWS\DONGBA~1.SCR
70000    C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE
70013    C:\PROGRAM FILES\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\ACROIEHELPERSHIM.DLL
70000    C:\WINDOWS\SYSTEM32\DRIVERS\XAUDIO.EXE
70000    C:\PROGRA~1\RISING\RAV\CCENTER.EXE
70013    C:\WINDOWS\SYSTEM32\ATIUMDVA.DLL
70000    C:\PROGRA~1\RISING\RAV\SCANFRM.EXE
70013    C:\PROGRAM FILES\360\360SAFE\SAFEMON\URLPROC.DLL
70000    C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
70000    C:\PROGRAM FILES\KINGSOFT\KAC\SERVICE\KACCORE.EXE
70015    C:\WINDOWS\SYSTEM32\SHSVCS.DLL
70013    C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\THUNDERAGENT_NOW.DLL
70004    C:\USERS\TOSHIBA\DOWNLOADS\CHINANETSN\BIN\NETKEEPER.EXE
70012    C:\PROGRAM FILES\WINRAR\RAREXT.DLL
70004    C:\PROGRAM FILES\TOSHIBA\SMOOTHVIEW\SMOOTHVIEW.EXE
70004    C:\PROGRAM FILES\360\360SAFEBOX\SAFEBOXTRAY.EXE
70012    C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
70000    C:\WINDOWS\SYSTEM32\BITS\CLIHXWCIL.DLL
70000    C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\DRIVER\11\INTEL 32\IDRIVERT.EXE
70012    C:\WINDOWS\SYSTEM32\MSVCR71.DLL
70004    C:\PROGRAM FILES\RISING\RAV\RSTRAY.EXE
70000    C:\PROGRAM FILES\O2MICRO FLASH MEMORY CARD DRIVER\O2FLASH.EXE
70012    C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\ATIACMXX.DLL
70000    C:\PROGRA~1\TOSHIBA\TO30EC~1\TNAVISRV.EXE
70013    C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH10B.OCX
70012    C:\WINDOWS\SYSTEM32\TUDOUUPLOAD.DLL
70004    C:\WINDOWS\SYSTEM32\NMGAMEX.DLL
70011    C:\WINDOWS\SYSTEM32\CNXTAP32.DLL
70017    C:\WINDOWS\SYSTEM32\GCFCONVERT.DLL
70000    C:\PROGRA~1\RISING\RAV\RAVMOND.EXE
70004    C:\PROGRAM FILES\TENCENT\QQ\BIN\QQ.EXE
70004    C:\PROGRAM FILES\TOSHIBA\TBS\HSON.EXE
70000    C:\PROGRAM FILES\TOSHIBA\POWER SAVER\TOSCOSRV.EXE
70004    C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
70004    C:\PROGRAM FILES\TOSHIBA\POWER SAVER\TPWRMAIN.EXE
70012    C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\ATIAMCHS.DLL
70012    C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\TDATONCE_NOW.DLL
70000    C:\PROGRAM FILES\TOSHIBA\CONFIGFREE\CFSVCS.EXE
70012    C:\WINDOWS\SYSTEM32\SOGOUPY.IME
70013    C:\PROGRAM FILES\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\ACROIEHELPER.DLL
70000    C:\PROGRA~1\JUMPST~1\JSWPSAPI.EXE
70012    C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DSBHO_01.DLL
70013    C:\WINDOWS\SYSTEM32\ATIUMDAG.DLL
70000    C:\PROGRAM FILES\COMMON FILES\MACROMEDIA SHARED\SERVICE\MACROMEDIA LICENSING.EXE
70000    C:\PROGRA~1\COMMON~1\ULEADS~1\DVD\ULCDRSVR.EXE
70000    C:\WINDOWS\SYSTEM32\TODDSRV.EXE
70000    E:\下载的~1\STORM\STORMLIV.EXE
70012    C:\WINDOWS\SYSTEM32\RAVEXT.DLL
70004    C:\PROGRAM FILES\360\360SAFE\SAFEMON\360TRAY.EXE
70012    C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMPONENTS\RESWORKER\DATAPROCESSOR_01.DLL
70004    C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\CLISTART.EXE
70013    C:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
70004    C:\PROGRAM FILES\TOSHIBA\TOSCDSPD\TOSCDSPD.EXE
70000    C:\PROGRAM FILES\TOSHIBA\SMARTLOGSERVICE\TOSIPCSRV.EXE
70012    C:\WINDOWS\SYSTEM32\MSVCP71.DLL
70004    C:\PROGRAM FILES\ADOBE\READER 9.0\READER\READER_SL.EXE
70015    C:\WINDOWS\SYSTEM32\UXTHEME.DLL
70013    C:\PROGRAM FILES\JAVA\JRE1.6.0_03\BIN\SSV.DLL
70004    C:\PROGRAM FILES\TOSHIBA\FLASHCARDS\TCRDMAIN.EXE
70012    C:\PROGRAM FILES\360\360SAFE\SAFEMON\SAFEMON.DLL
70004    C:\PROGRAM FILES\CAMERA ASSISTANT SOFTWARE FOR TOSHIBA\TRAYBAR.EXE
70004    C:\WINDOWS\DONGBA~1.SCR
70000    C:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE
70013    C:\PROGRAM FILES\COMMON FILES\ADOBE\ACROBAT\ACTIVEX\ACROIEHELPERSHIM.DLL
70000    C:\WINDOWS\SYSTEM32\DRIVERS\XAUDIO.EXE
70000    C:\PROGRA~1\RISING\RAV\CCENTER.EXE
70013    C:\WINDOWS\SYSTEM32\ATIUMDVA.DLL
70000    C:\PROGRA~1\RISING\RAV\SCANFRM.EXE
70013    C:\PROGRAM FILES\360\360SAFE\SAFEMON\URLPROC.DLL
70000    C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
70000    C:\PROGRAM FILES\KINGSOFT\KAC\SERVICE\KACCORE.EXE
70015    C:\WINDOWS\SYSTEM32\SHSVCS.DLL
70013    C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\THUNDERAGENT_NOW.DLL
70004    C:\USERS\TOSHIBA\DOWNLOADS\CHINANETSN\BIN\NETKEEPER.EXE
70012    C:\PROGRAM FILES\WINRAR\RAREXT.DLL
70004    C:\PROGRAM FILES\TOSHIBA\SMOOTHVIEW\SMOOTHVIEW.EXE
70004    C:\PROGRAM FILES\360\360SAFEBOX\SAFEBOXTRAY.EXE
70012    C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_NOW.DLL
70000    C:\WINDOWS\SYSTEM32\BITS\CLIHXWCIL.DLL
70000    C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\DRIVER\11\INTEL 32\IDRIVERT.EXE
70012    C:\WINDOWS\SYSTEM32\MSVCR71.DLL
70004    C:\PROGRAM FILES\RISING\RAV\RSTRAY.EXE
70000    C:\PROGRAM FILES\O2MICRO FLASH MEMORY CARD DRIVER\O2FLASH.EXE
70012    C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\ATIACMXX.DLL
70000    C:\PROGRA~1\TOSHIBA\TO30EC~1\TNAVISRV.EXE
70013    C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH10B.OCX
70012    C:\WINDOWS\SYSTEM32\TUDOUUPLOAD.DLL
70004    C:\WINDOWS\SYSTEM32\NMGAMEX.DLL
70011    C:\WINDOWS\SYSTEM32\CNXTAP32.DLL
70017    C:\WINDOWS\SYSTEM32\GCFCONVERT.DLL
70000    C:\PROGRA~1\RISING\RAV\RAVMOND.EXE
70004    C:\PROGRAM FILES\TENCENT\QQ\BIN\QQ.EXE
70004    C:\PROGRAM FILES\TOSHIBA\TBS\HSON.EXE
70000    C:\PROGRAM FILES\TOSHIBA\POWER SAVER\TOSCOSRV.EXE
70004    C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
70004    C:\PROGRAM FILES\TOSHIBA\POWER SAVER\TPWRMAIN.EXE
70012    C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\ATIAMCHS.DLL
70012    C:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\TDATONCE_NOW.DLL
70000    C:\PROGRAM FILES\TOSHIBA\CONFIGFREE\CFSVCS.EXE
70012    C:\WINDOWS\SYSTEM32\SOGOUPY.IME
gototop
 

回复 1F 奕扬の 的帖子

病毒文件名以及完整路径呢?
gototop
 

回复 7F backway 的帖子

病毒名称                                                        处理结果                                                        发现日期                                                        查杀方式                                                        路径                                                            文件                                                            病毒来源                                                       
Trojan.Clicker.Win32.Agent.eja                                  重新启动电脑后删除文件                                          2009-05-11 12:35:54                                            手动查杀                                                        C:\Windows\System32\bits                                        clihxwcil.dll                                                  本地服务器                                                     
Trojan.Clicker.Win32.Agent.eja                                  删除染毒文件成功                                                2009-05-11 12:35:51                                            手动查杀                                                        C:\Windows\System32\bits\5520                                  svchost.exe                                                    本地服务器                                                     
Trojan.Clicker.Win32.Agent.eja                                  删除失败                                                        2009-05-11 11:52:04                                            手动查杀                                                        c:\windows\system32\bits                                        clihxwcil.dll                                                  本地服务器                                                     
Trojan.Clicker.Win32.Agent.eja                                  不处理                                                          2009-05-10 11:15:57                                            空闲时段查杀                                                    c:\windows\system32\bits                                        clihxwcil.dll                                                  本地服务器
gototop
 

回复: trojan.clicker.win32.agent.eja

下载XueTr0.26.rar ,运行后选择“文件”,找到下面的文件右键选择强制删除:

C:\Windows\System32\bits\clihxwcil.dll   
C:\Windows\System32\bits\5520\svchost.exe  (文件找不到就不管了)

问题还没解决的话扫描上传sreng日志

            下载sreng http://www.kztechs.com/sreng/download.html
             
没时间了,别人帮你看日志了。
最后编辑backway 最后编辑于 2009-05-11 13:19:13
gototop
 

回复:trojan.clicker.win32.agent.eja

下午我又重新弄了一下,那位高人再帮我看看是不是病毒没有了?因为我用瑞星检查了一下说没有了……下面的是用srengldr得出的报告……
我的系统的vista的,辛苦了!!!
启动项目


注册表

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
(Sidebar)(C:\Program Files\Windows Sidebar\sidebar.exe /autoRun) [(Verified)Microsoft Windows]
(TOSCDSPD)(C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe) []
(QQ2009)("C:\Program Files\Tencent\QQ\Bin\QQ.exe" /background) [(Verified)Tencent Technology(Shenzhen) Company Limited]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(load)() [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
(Windows Defender)(%ProgramFiles%\Windows Defender\MSASCui.exe -hide) [(Verified)Microsoft Windows]
(NDSTray.exe)(NDSTray.exe) [N/A]
(jswtrayutil)("C:\Program Files\Jumpstart\jswtrayutil.exe") [File is missing]
(StartCCC)("C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe") []
(SynTPEnh)(C:\Program Files\Synaptics\SynTP\SynTPEnh.exe) [(Verified)Microsoft Windows Hardware Compatibility Publisher]
(TPwrMain)(%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE) [(Verified)TOSHIBA CORPORATION]
(HSON)(%ProgramFiles%\TOSHIBA\TBS\HSON.exe) [(Verified)TOSHIBA CORPORATION]
(SmoothView)(%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe) [(Verified)TOSHIBA CORPORATION]
(00TCrdMain)(%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe) [TOSHIBA Corporation]
(Camera Assistant Software)("C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start) [Chicony]
(闪讯1.0)(C:\Users\toshiba\Downloads\ChinaNetSn\bin\NetKeeper.exe) [XI AN XINLI SOFTWARE TECHNOLOGY CO.,LTD]
(360Safebox)("C:\Program Files\360\360safebox\safeboxTray.exe" /r) [(Verified)Qizhi Software (beijing) Co. Ltd]
(360Safetray)(C:\Program Files\360\360Safe\safemon\360tray.exe /start) [(Verified)Qizhi Software (beijing) Co. Ltd]
(Adobe Reader Speed Launcher)("C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe") [(Verified)"Adobe Systems, Incorporated"]
(RavTray)("C:\Program Files\Rising\Rav\RsTray.exe" -system) [(Verified)Beijing Rising Information Technology Corporation Limited]
(NMGameX_AutoRun)(C:\Windows\system32\Rundll32.exe NMGameX.dll,LiveProcess /aa) [NMGameX]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
(shell)(explorer.exe) [(Verified)Microsoft Windows]
(Userinit)(C:\Windows\system32\userinit.exe,) [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
(AppInit_DLLs)() [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
(WebCheck)(C:\Windows\system32\webcheck.dll) [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
({8C7461EF-2B13-11d2-BE35-3078302C2030})(%SystemRoot%\system32\browseui.dll) [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\){22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
(Microsoft Windows Media Player)(C:\Windows\system32\unregmp2.exe /ShowWMP) [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\){26923b43-4d38-484f-9b9e-de460746276c}]
(Internet Explorer)(C:\Windows\system32\ie4uinit.exe -UserIconConfig) [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\){60B49E34-C7CC-11D0-8953-00A0C90347FF}]
(Browser Customizations)(RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP) [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
(Themes Setup)(%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll) [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
(Microsoft Windows Mail 7)("%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE) [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
(Microsoft Windows Media Player)(%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI) [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
(Windows Desktop Update)(regsvr32.exe /s /n /i:U shell32.dll) [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
(Internet Explorer)(C:\Windows\system32\ie4uinit.exe -BaseSettings) [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
(N/A)(C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install) [(Verified)Microsoft Windows]
[HKEY_CURRENT_USER\Control Panel\Desktop]
(SCRNSAVE.EXE)(C:\Windows\DONGBA~1.SCR) []
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT