瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 trojan.dl.agent.kby病毒老杀不干净,求救SOS

1   1  /  1  页   跳转

trojan.dl.agent.kby病毒老杀不干净,求救SOS

trojan.dl.agent.kby病毒老杀不干净,求救SOS

病毒名称    处理结果    发现日期    扫描方式    路径    文件
Trojan.DL.Agent.kby    删除成功    2006-07-21 08:25    文件监控    C:\WINDOWS\system32    xadowner1.dll
Trojan.DL.Agent.kby    删除成功    2006-07-22 13:55    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-07-24 08:35    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-07-24 15:28    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-07-25 08:21    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-07-25 14:52    文件监控    C:\WINDOWS\system32    xadtemp.dll
Hack.Exploit.JS.IeWmv.a    删除成功    2006-08-08 12:23    文件监控    D:\Temp\Temporary Internet Files\Content.IE5\AAU8D95O    girl[1].htm
Hack.Exploit.JS.IeWmv.a    跳过脚本    2006-08-08 12:23    网页/脚本监控    C:\DOCUME~1\JIEFU\LOCALS~1\Temp    368454015920.tmp
Trojan.Clicker.Agent.adi    删除成功    2006-08-16 10:26    文件监控    C:\DOCUME~1\JIEFU\LOCALS~1\Temp    10067_SETUP.exe
Trojan.Clicker.Qhost.i    删除成功    2006-08-16 10:26    文件监控    C:\WINDOWS\system32    WinSC.dll
Trojan.Agent.djp    删除成功    2006-08-16 10:26    文件监控    C:\WINDOWS\system    realsched.exe>>Unpack
Trojan.DL.Agent.kby    删除成功    2006-08-19 07:45    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-08-20 07:53    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-08-20 14:15    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.VBS.Agent.q    跳过脚本    2006-08-21 08:43    网页/脚本监控    C:\DOCUME~1\JIEFU\LOCALS~1\Temp    393650345936.tmp
Trojan.DL.VBS.Agent.q    跳过脚本    2006-08-21 08:43    网页/脚本监控    C:\DOCUME~1\JIEFU\LOCALS~1\Temp    393650345936.tmp
Trojan.DL.Agent.kby    删除成功    2006-08-21 08:43    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-08-22 08:09    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-08-23 08:09    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-08-23 09:02    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-08-23 10:21    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-08-24 07:31    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-08-24 14:24    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-08-24 16:09    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-08-25 07:58    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-08-25 15:38    文件监控    C:\WINDOWS\system32    xadtemp.dll
Trojan.DL.Agent.kby    删除成功    2006-08-26 08:25    文件监控    C:\WINDOWS\system32    xadtemp.dll
最后编辑2006-08-26 15:37:20.733000000
分享到:
gototop
 

请到http://forum.ikaka.com/topic.asp?board=28&artid=8105899
下载HijackThis
下载后运行HijackThis.rar,再运行HijackThis.exe
单机"扫描日志并保存日志"
把保存的日志复制粘贴上来
gototop
 

【回复“deadmanzj”的帖子】
HijackThis_815汉化版扫描日志 V1.99.1
保存于      14:31:19, 日期 2006-8-26
操作系统:  Windows XP SP2 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP2 (6.00.2900.2180)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\rising\Rav\RavStub.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\D-Link\D-Link AirPlus G+ Wireless Adapter Utility\DWLGTI.EXE
C:\Program Files\rising\Rav\Ravmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\Tool\Hijackthis1991zww\HijackThis1991zww.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: AdsHlpObj Class - {49A94665-B1F5-4F05-B9C7-FB6E336E49BD} - C:\WINDOWS\system32\AdsObj.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\qq\QQIEHelper.dll
O2 - BHO: AdsObj2 Class - {7DDEA238-3E32-43FD-8223-A5E15D9666FF} - C:\WINDOWS\system32\AdsHlp2.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll
O2 - BHO: AdsHlpObj Class - {C74332D8-097F-41E7-8F8A-2E4D5A07A31E} - C:\WINDOWS\system32\AdsHlp.dll
O3 - IE工具栏增项: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\zh-cn\msntb.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: Acrobat Assistant.lnk = D:\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: D-Link AirPlus G+ Wireless Adapter Utility.lnk = C:\Program Files\D-Link\D-Link AirPlus G+ Wireless Adapter Utility\DWLGTI.EXE
O4 - Global Startup: Microsoft Office.lnk = D:\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = D:\Microsoft Office\Office\2052\OLFSNT40.EXE
O8 - IE右键菜单中的新增项目: &Download by NetAnts - D:\NETANTS\NAGet.htm
O8 - IE右键菜单中的新增项目: Download &All by NetAnts - D:\NETANTS\NAGetAll.htm
O8 - IE右键菜单中的新增项目: 上传到QQ网络硬盘 - D:\qq\AddToNetDisk.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\qq\SendMMS.htm
O9 - 浏览器额外的按钮: NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - D:\NETANTS\NetAnts.exe
O9 - 浏览器额外的“工具”菜单项: &NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - D:\NETANTS\NetAnts.exe
O9 - 浏览器额外的按钮: 卓越 - {8DE0FCD4-5EB5-11D3-AD25-00002100131B} - d:\Kingsoft\XDict\IEPlugin.dll
O9 - 浏览器额外的按钮: 金山词霸 - {C8CE29C5-7589-11D3-B81B-0080C8DC5DC8} - d:\Kingsoft\XDict\IEPlugin.dll
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\qq\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\qq\QQ.EXE
O9 - 浏览器额外的按钮: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-195?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - 浏览器额外的“工具”菜单项: 易趣购物 - {DE60714F-AC17-427e-861A-FD60CBDF119A} - http://adfarm.mediaplex.com/ad/ck/4080-23171-9517-195?cn=song;icon;hp&mpro=http://www.ebay.com.cn (file missing)
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\qq\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\qq\QQIEHelper.dll
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {2354A44B-3CEB-4829-9940-545B03103538} (PowerPlr Control) - http://vod.wx.js.cn/plugin/PowerPlr.ocx
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl Object) - https://img.alipay.com/download/aliedit.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9BED3AC7-E6D4-43E7-B8A1-1FA502F639E1} (XTools Control) - http://player.bugs.co.kr/install/XTools.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/Ver2005/OL2005.cab
O16 - DPF: {F2EB8999-766E-4BF6-AAAD-188D398C0D0B} (PBActiveX40 Control) - http://www4.cmbchina.com/download/pb45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{87AE65AC-48DC-4019-A0D5-D63762E85347}: NameServer = 192.168.1.1
O18 - 列举现有的协议: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - NT 服务: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\Ravmond.exe
O23 - NT 服务: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

gototop
 

这几个比较奇怪:

O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab

O16 - DPF: {9BED3AC7-E6D4-43E7-B8A1-1FA502F639E1} (XTools Control) - http://player.bugs.co.kr/install/XTools.cab

O16 - DPF: {F2EB8999-766E-4BF6-AAAD-188D398C0D0B} (PBActiveX40 Control) - http://www4.cmbchina.com/download/pb45.cab
gototop
 

SOS

在线等
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT