瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 trojan.dl.ieframe.bm每次杀掉还会再出现,怎么办啊?

12   1  /  2  页   跳转

[求助] trojan.dl.ieframe.bm每次杀掉还会再出现,怎么办啊?

trojan.dl.ieframe.bm每次杀掉还会再出现,怎么办啊?

使这个病毒:trojan.dl.ieframe.bm


用avg查叫做:Hijacker.IFrame.br
每次杀掉之后,过一阵子又会再出现,有时候几个小时,有时候干脆就是几天之后再出现
用诺顿查不出来,用恶意软件清理助手也没有效果
另外,包括用360的安天查木马也不行,查不出来

有的时候会感染很多文件,但基本都是哪些上网的临时文件和cookies之类的

请问大家知道怎么彻底消灭它吗?



avg的纪录:
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\HGZ3AJNZ\homePageBottomImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\HGZ3AJNZ\homePageRightImg2[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\TLS0GMO0\SocietyLeftSmallTop[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\TLS0GMO0\contentFocusImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\TLS0GMO0\homePageLeftImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\TLS0GMO0\homePageMiddleImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\TLS0GMO0\homePageTopTwoImgLeft[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\TLS0GMO0\huarenTopImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\TLS0GMO0\societyTopImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\YTTL808I\SocietyLeftSmallFooter[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\YTTL808I\SocietyMid[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\YTTL808I\contentFocusImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\YTTL808I\homePageRightImg1[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\YTTL808I\homePageTwoImgRight[1].js -> Hijacker.IFrame.br : Cleaned.




瑞星的记录:
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\w8qxabe4      文件名:28942014[1].htm    来源:本机

用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; CIBA)
分享到:
gototop
 

回复:trojan.dl.ieframe.bm每次杀掉还会再出现,怎么办啊?

期待版主们来指点一下,我的方法是不用IE用火狐。然后用防火墙把"C:\Program Files\Internet Explorer\IEXPLORE.EXE"这个文件设成禁止访问网络。不过有一个不足之处就是不能打开QQ空间还有一些要特殊插件的网页
PC蛋蛋
多看少灌水是我的原则。不得不灌又是我的理由
欢迎观看我做的视频晕死挂了一年的签名签错地方了还不知道
gototop
 

回复:trojan.dl.ieframe.bm每次杀掉还会再出现,怎么办啊?

扫SRENG日志发这论坛来
下载SRENG2.6版:http://bbs.ikaka.com/attachment.aspx?attachmentid=399427

1 下载的是压缩包,必须解压缩(建议直接解压到系统Windows文件夹里)
2 运行SREng***.EXE
3 选择主界面左边的:智能扫描=》扫描=》保存报告
4 把报告保存后,直接将日志文件以附件的形式发这论坛来。

一定以附件形式发这论坛来。
点击你自己的主题贴右下角的“引用”或最右下角的那个较大的“回复”然后就应该知道怎么发了。

(同时注意SRENG工具的入口点提示和那个关于<AppInit_DLLs>项的<ieprot.dll>提示都只是常规提示,可以不管它,请不要为这问题反复询问。)

SRENG工具的一些操作,看这贴:http://bbs.ikaka.com/showtopic-8442813.aspx

还有这补丁打了么?
http://bbs.ikaka.com/showtopic-8509685.aspx
百年以后,你的墓碑旁 刻着的名字不是我
gototop
 

回复: trojan.dl.ieframe.bm每次杀掉还会再出现,怎么办啊?

这是日志

附件附件:

文件名:SREngLOG.log
下载次数:129
文件类型:application/octet-stream
文件大小:
上传时间:2008-6-12 9:28:32
描述:log

gototop
 

回复 3F 天月来了 的帖子

楼上是我刚扫的,只是由于该病毒复活的时间间隔不确定,此病毒暂时还没有再次复活
在这种情况下,不知SRENG日志还有没有用 
  谢谢了
gototop
 

回复:trojan.dl.ieframe.bm每次杀掉还会再出现,怎么办啊?

清理临时文件夹:
打开我的电脑-工具-文件夹选项-查看-显示隐藏文件-隐藏受保护的系统文件(勾去掉)-确定
重起进入安全模式(开机不停的按F8,选择安全模式启动) 清空下列临时文件夹中所有内容:
C:\Documents and Settings\用户名\Local Settings\Temporary Internet Files
C:\Documents and Settings\用户名\Local Settings\Temp
C:\WINDOWS\TEMP
友情连接:www.jiake168.com(获得国家专利的私家车车身广告官网)
邮箱:571wind@163.com(只收样本)
gototop
 

回复 6F 日不懂啊 的帖子

已经进行了此操作,但完全没有效果
这是刚才的查毒结果:

AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at:    13:39:45 2008-6-12

+ Scan result:   



C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\D39P8YA7\contentFocusImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\D39P8YA7\contentTopImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\D39P8YA7\homePageBottomImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\D39P8YA7\homePageMiddleImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\D39P8YA7\homePageTwoImgRight[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\D39P8YA7\worldRightImg2[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\D39P8YA7\worldTopTwoImgRight[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\SZ2Q5QA4\worldMiddleTwoImgLeft[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\WWPV5O3K\contentFocusImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\WWPV5O3K\contentFocusImg[2].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\WWPV5O3K\contentTopImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\WWPV5O3K\homePageLeftImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\WWPV5O3K\worldRightImg1[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\YON4WP5J\contentTopImg[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\YON4WP5J\homePageLeftImg1[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\YON4WP5J\homePageTopTwoImgLeft[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\YON4WP5J\worldMiddleTwoImgRight[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\YON4WP5J\worldRightImg3[1].js -> Hijacker.IFrame.br : Cleaned.
C:\Documents and Settings\S.R\Local Settings\Temporary Internet Files\Content.IE5\YON4WP5J\worldTopTwoImgLeft[1].js -> Hijacker.IFrame.br : Cleaned.


::Report end

这个病毒还是会复活,请问是否还有别的方法?
gototop
 

回复:trojan.dl.ieframe.bm每次杀掉还会再出现,怎么办啊?

你是什么网络环境?
是不是局域网?

而且没有安装ARP防火墙吧?
友情连接:www.jiake168.com(获得国家专利的私家车车身广告官网)
邮箱:571wind@163.com(只收样本)
gototop
 

回复 8F 日不懂啊 的帖子

是局域网没错
但一直用360的ARP防火墙,同时还有诺顿的网络特警防火墙,二者是同时使用的
只有几天前偶然关闭了ARP防火墙大约2个小时(似乎就是病毒出现的前后时间吧,但实在记不清了),此外一直都是开着的

windows的补丁和杀毒软件,防火墙的更新也一直都很及时的
不明白为什么会这样
gototop
 

回复:trojan.dl.ieframe.bm每次杀掉还会再出现,怎么办啊?

ARP防火墙,你绑定网关MAC地址了没?

绑定一下

再清空下临时文件夹~~
友情连接:www.jiake168.com(获得国家专利的私家车车身广告官网)
邮箱:571wind@163.com(只收样本)
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT