瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了Trojan.Agent.cze 瑞星删除了两个病毒文件,但...?

1   1  /  1  页   跳转

中了Trojan.Agent.cze 瑞星删除了两个病毒文件,但...?

中了Trojan.Agent.cze 瑞星删除了两个病毒文件,但...?

电脑中了Trojan.Agent.cze 瑞星删除了病毒两个文件,但用“HijackThis”扫苗,有1项可疑进程,C:\WINDOWS\msagent\AgentSvr.exe  能否把它干掉。帮忙看看

Logfile of HijackThis v1.99.1
Scan saved at 16:13:36, on 2006-10-11
Platform: Windows 2003 SP1 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 SP1 (6.00.3790.1830)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dns.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Serv-U\ServUDaemon.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Rising\Rav\RAVTASK.EXE
C:\Program Files\Rising\Rav\Ravmond.exe
C:\Program Files\Rising\Rav\RAVMON.EXE
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\MICROS~1\MSSQL\binn\sqlservr.exe
C:\Program Files\Rising\Rav\rav.exe
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
F:\soft\HijackThis1.99.1\HijackThis.exe

O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [SKYNET Personal FireWall] C:\PROGRA~1\SKYNET\FIREWALL\pfw.exe
O4 - HKLM\..\RunOnce: [RavStub] "C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{9C882304-3684-467D-92E9-71815169B34D}: NameServer = 211.155.23.88,211.155.27.88
O17 - HKLM\System\CS1\Services\Tcpip\..\{9C882304-3684-467D-92E9-71815169B34D}: NameServer = 211.155.23.88,211.155.27.88
O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\SYSTEM32\dimsntfy.dll
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Serv-U FTP 服务器 (Serv-U) - Cat Soft - C:\Program Files\Serv-U\ServUDaemon.exe





再用IceSword扫苗,又发现有两项可疑进程:
C:\WINDOWS\Debug\HXDEF100.EXE    能否把它干掉
C:\WINDOWS\MSAGENT\AgentSvr.exe    能否把它干掉

IceSword进程:

System Idle Process
System
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\System32\DNS.EXE
C:\WINDOWS\System32\SVCHOST.EXE
C:\WINDOWS\System32\RDPCLIP.EXE
C:\WINDOWS\Debug\HXDEF100.EXE
C:\WINDOWS\System32\INETSRV\INETINFO.EXE
F:\soft\IceSword\IceSword.exe
C:\Program Files\Serv-U\ServUDaemon.exe
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\System32\SMSS.EXE
C:\Program Files\Common Files\System\MSSearch\Bin\MSSEARCH.EXE
C:\WINDOWS\System32\CSRSS.EXE
C:\WINDOWS\System32\WINLOGON.EXE
C:\WINDOWS\System32\SERVICES.EXE
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\SQLSERVR.EXE
C:\WINDOWS\System32\LSASS.EXE
C:\WINDOWS\System32\SVCHOST.EXE
C:\WINDOWS\System32\SVCHOST.EXE
C:\WINDOWS\System32\SVCHOST.EXE
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\SVCHOST.EXE
C:\WINDOWS\System32\SVCHOST.EXE
C:\WINDOWS\System32\SVCHOST.EXE
C:\WINDOWS\System32\CTFMON.EXE
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\System32\MSDTC.EXE
C:\WINDOWS\System32\SVCHOST.EXE
C:\Program Files\Rising\Rav\RavMonD.exe
C:\Program Files\SkyNet\FireWall\pfw.exe
C:\WINDOWS\System32\ALG.EXE
C:\WINDOWS\MSAGENT\AgentSvr.exe
C:\WINDOWS\System32\INETSRV\W3WP.EXE
C:\WINDOWS\System32\WBEM\WMIPRVSE.EXE
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\System32\CSRSS.EXE
C:\WINDOWS\System32\WINLOGON.EXE
C:\Program Files\Rising\Rav\RsAgent.exe
C:\Program Files\Rising\Rav\RavMon.exe
C:\WINDOWS\System32\logon.scr
C:\Program Files\Rising\Rav\Rav.exe
最后编辑2006-10-12 14:36:32
分享到:
gototop
 

高手帮忙看看。
gototop
 

??
gototop
 

..
gototop
 

O17 - HKLM\System\CCS\Services\Tcpip\..\{9C882304-3684-467D-92E9-71815169B34D}: NameServer = 211.155.23.88,211.155.27.88
这个怎么会有2个IP呢?


顶一下
gototop
 

这两个是:首选DNS服务器IP 和备用DNS服务器IP。这两项没问题吧!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT