12   1  /  2  页   跳转

Trojan.DL.Agent.iqx

Trojan.DL.Agent.iqx

偶快被Trojan.DL.Agent.iqx病毒折磨死了,经常无法正常上网,瑞星杀不干净,什么时候碰到要更改注册表时候瑞星才能将C:\WINDOWS\system32\Upsrv.dll删除,但平时起机这个文件是不存在的,不知道可否安全删除
最后编辑2006-06-19 16:20:51
分享到:
gototop
 

参考:http://forum.ikaka.com/topic.asp?board=28&artid=8109186
gototop
 

你好,按您的方法,发现没有您说的.DLL呀,晕,用FIX发现只有4个dll,分别是mswsock,winrnr,nwprovau,rsapsp这4个dll,把那个移到右面删除掉?
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 22:38:13, on 2006-6-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Rav\Ravmond.exe
c:\rising\rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Rav\RavStub.exe
c:\rising\rfw\RfwMain.exe
C:\Program Files\Portrait Displays\forteManager\DTSRVC.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Rav\RavTask.exe
C:\Rav\Ravmon.exe
C:\Program Files\amtium\客户端登录工具\eFlow_c.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.485\LSPFix汉化版.exe
C:\Documents and Settings\Administrator\桌面\ha_hijackthis_1991\HijackThis.exe

R3 - URLSearchHook: (no name) - {BAB1AC41-6FF7-4F2E-A04E-5C592CCFEA7D} - (no file)
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RavTask] "C:\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "C:\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [NvCplDaemon] ; RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NeroFilterCheck] ; C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Skype] ; C:\111\skype\Phone\Skype.exe
O4 - HKLM\..\Run: [runeflow] C:\Program Files\amtium\客户端登录工具\eFlow_c.exe
O4 - HKLM\..\Run: [KService] C:\WINDOWS\system32\KService.exe
O4 - HKLM\..\RunOnce: [RavStub] "C:\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: IE-BAR.lnk = ?
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\2052\OLFSNT40.EXE
O4 - Global Startup: 服务管理器.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: 柯达 EasyShare 软件.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &使用迅雷下载 - C:\讯雷\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\讯雷\Program\GetAllUrl.htm
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1142065027375
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AXSafeControls.cab
O16 - DPF: {E787FD25-8D7C-4693-AE67-9406BC6E22DF} (CPasswordEditCtrl Object) - https://www.tenpay.com/download/qqedit.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} - http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.80_20060123.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Asset Management Daemon - Unknown owner - C:\Program Files\Portrait Displays\forteManager\dtsslsrv.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Portrait Displays\forteManager\DTSRVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\rising\rfw\rfwsrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Rav\Ravmond.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\SiSoftware Sandra Professional 2005\RpcSandraSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

gototop
 

还报那毒 ? 010没项了..
gototop
 

我的意思是:不知道什么时候重新起机就会不能上网,要等到病毒来更改注册表时候,选拒绝,选杀毒,删除掉C:\WINDOWS\system32\Upsrv.dll后才能正常上网,不出上面的情况IE和QQ就是死机状态,真的被他搞晕了,他是不定期的
gototop
 

进入控制面版的添加删除程序中卸载IE-BAR
卸载后重启,删除
C:\Program Files\IE-BAR
最后,你是否知道以下的进程。
O4 - HKLM\..\Run: [KService] C:\WINDOWS\system32\KService.exe
gototop
 

O4 - HKLM\..\Run: [KService] C:\WINDOWS\system32\KService.exe
这个进程不知道是谁的,现在偶没有开任何偶需要使用的软件
gototop
 

这个进程不知道是谁的,要删除吗?怎么删,谢谢
gototop
 

ALT+CTRL+DELETE调出任务管理器,终止所有KService.exe的进程,如果有的话。
关闭所有浏览窗口以及一些不必要的程序
运行Hijackthis,扫描结束后在下列选项前打上勾,然后选"修复
O4 - HKLM\..\Run: [KService] C:\WINDOWS\system32\KService.exe
删除
C:\WINDOWS\system32\KService.exe
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT