瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 发现一种最新的病毒《Trojan.DL.Agent.apb》

12   1  /  2  页   跳转

发现一种最新的病毒《Trojan.DL.Agent.apb》

发现一种最新的病毒《Trojan.DL.Agent.apb》

我的机器中了这个病毒Trojan.DL.Agent.apb
不知道是哪方面的,用瑞星检查出来了,说重启既可删除,结果重启了N次也没搞定,也试了在安全模式中关闭系统还原后杀毒,仍然没杀掉,郁闷死了,不知道那个大侠明白啊,帮帮小弟吧
最后编辑2006-09-14 23:50:25.107000000
分享到:
gototop
 

没人知道么?怎么瑞星也干不掉这个病毒啊?郁闷啊
gototop
 

如果谁知道请告诉我,我是菜鸟,请尽量使用最最简单的表达方法。
gototop
 

还有就是,这个病毒的特点是什么啊,我就是因为最近打开网页就总是弹出一些乱七八糟的网页,这个病毒就是干这个的么????
gototop
 

日志发上来``
这个网站有``http://www.kztechs.com/sreng/download.html
点智能扫描``保存日志``再把日志发上来``一页发不下我发几页``
gototop
 

我的QQ:369385103  我和你中的一样
gototop
 

把病毒路径发上来
请下载 System Repair Engineer,使用“智能扫描”,按下“扫描”按钮进行扫描,扫描完成后按下“保存报告”按钮保存报告日志文件(SREng.LOG),把保存的报告日志文件内容复制-粘贴上来
下载网址
http://www.kztechs.com/sreng/sreng2.zip
http://forum.ikaka.com/topic.asp?board=67&artid=5188931
日志一次粘不完,分次粘完,请不要修改
gototop
 

我也中了这种病毒,无法清除
gototop
 

我也中毒,已向瑞星发送报告,没反应
gototop
 

我也中了这个

            附日志


Logfile of HijackThis v1.99.1
Scan saved at 15:44:38, on 2006-9-3
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SoftUpdate.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\system
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\conime.exe
C:\PROGRA~1\Kuree\kpupdate.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatfrom.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Kuree\mpkres.dll
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\qqjt\BitSpirit\BitSpirit.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Thunder Network\Thunder\Thunder.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\winmer.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Admin\LOCALS~1\Temp\Rar$EX00.312\HijackThis.exe

R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: (no name) - {14A21378-5BB1-4BC4-95D5-5D3F51527F6F} - (no file)
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5001.dll (file missing)
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O2 - BHO: shdocvwhlp Class - {BE442802-3911-46E0-B227-076B15A4EAD3} - C:\WINDOWS\system32\shdocvw2.dll
O2 - BHO: (no name) - {E730189A-9973-4121-B046-AD1C161EC3AF} - C:\WINDOWS\system32\37211.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Realplayer.exe] C:\WINDOWS\system32\Realplayer.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [RavAV] C:\WINDOWS\RavMonE.exe
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
O4 - HKLM\..\Run: [Thunder] "C:\Program Files\Thunder Network\Thunder\ThunderShell.exe" /s
O4 - HKLM\..\Run: [WebThunder] C:\Program Files\Thunder Network\WebThunder\WebThunder.exe
O4 - HKLM\..\Run: [WinTelnet] C:\WINDOWS\system32\WinServer.exe
O4 - HKLM\..\Run: [RealplayX(?xe] C:\WINDOWS\system32\Realplayer.exe
O4 - HKLM\..\Run: [HupooShell] "C:\DOCUME~1\Admin\LOCALS~1\Temp\5yad1008.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O4 - Global Startup: IE-Bar.lnk = C:\Program Files\Common Files\IE-Bar\iebar.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: >>彩信发送<< - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra 'Tools' menuitem: 彩E精灵设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra button: 哇哇网址导航 - {f15c22ef-534e-414d-ab5d-1425cd806e41} - http://www.51viva.com/dlplugin/redirect.jsp?refer=dtoolbar&cur=http://114.yesky.com/ (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: 哇哇网址导航 - {f15c22ef-534e-414d-ab5d-1425cd806e41} - http://www.51viva.com/dlplugin/redirect.jsp?refer=dtoolbar&cur=http://114.yesky.com/ (file missing) (HKCU)
O9 - Extra button: 哇哇软件下载 - {f15c22ef-534e-414d-ab5d-1425cd806e42} - http://www.51viva.com/dlplugin/redirect.jsp?refer=dtoolbar&cur=http://www.mydown.com/ (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: 哇哇软件下载 - {f15c22ef-534e-414d-ab5d-1425cd806e42} - http://www.51viva.com/dlplugin/redirect.jsp?refer=dtoolbar&cur=http://www.mydown.com/ (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdnns.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\srvdll.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\srvdll.dll
O11 - Options group: [!CNS]  中文上网
O11 - Options group: [CDNCLIENT]  中文上网
O17 - HKLM\System\CCS\Services\Tcpip\..\{53225A8F-E00F-4975-AE7B-5E6CBFE79850}: NameServer = 219.150.32.132 202.103.224.68
O21 - SSODL: webwork - {4C611512-2C1D-44b2-A044-872AD2AD5A61} - C:\WINDOWS\webwork\webwork.dll
O21 - SSODL: MediaCheck - {D1F73845-4BAB-4061-A46B-FCF7ECC19217} - C:\PROGRA~1\Kuree\MService.dll
O21 - SSODL: DelayRun - {5A6F2F95-3191-433B-8533-EB0B596A7BAC} - C:\WINDOWS\system\27dd4c71.dll (file missing)
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Update Service For Windows (SoftUpdate) - Unknown owner - C:\WINDOWS\SoftUpdate.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Windows XP Vista        - Unknown owner - C:\Program.exe (file missing)
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT