瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 Trojan.DL.VBS.Agent.cgk 始终有这个病毒怎么办

1   1  /  1  页   跳转

Trojan.DL.VBS.Agent.cgk 始终有这个病毒怎么办

Trojan.DL.VBS.Agent.cgk 始终有这个病毒怎么办

我的正版瑞星 杀拉 完拉还有怎么回事
最后编辑2006-11-30 14:13:25
分享到:
gototop
 

网页监控报的  直接删除  要我重新启动的我都重新启动拉 就是有时在打开网页 网页监控还继续杀的病毒还是这个 连续杀 能杀10多个
gototop
 

网页监控报的  直接删除  要我重新启动的我都重新启动拉 就是有时在打开网页 网页监控还继续杀的病毒还是这个 连续杀 能杀10多个
gototop
 

Logfile of Kaka v2. 0. 2. 1 Scan Module v1. 0. 0. 41
Scan saved at 13:35:12, on 2006-11-30
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))


R3 - Default URLSearchHook is missing
O2 - BHO: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Program Files\BitComet\tools\BitCometBHO.dll
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\kakatool.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\RunOnce: [KKDelay] C:\Program Files\Rising\KakaToolBar\RunOnce.exe
O4 - Global Startup: 河南网通宽带用户客户端.lnk = C:\Program Files\racer-henan-cnc\racer.exe
O8 - Extra context menu item: &使用BitComet下载 - res://D:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &使用BitComet下载全部链接 - res://D:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &使用BitComet下载本页视频 - res://D:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {285C55C4-B32C-4EC0-8539-BBCE97FDF380} (SuperStream Control) - http://v.cga.com.cn/video/SuperRelease.cab
O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} - http://www.tvkoo.com/update/KooPlayer.ocx
O16 - DPF: {3C38DEE8-BE1A-4DEC-B232-2C78706CC7EA} - http://ps.itv.mop.com/update/update/GUpdate-1.0.0.10-signed.cab
O16 - DPF: {53AF6E02-F18F-4228-AC13-3E79773FBE50} (CMCBooter Object) - http://download.mysee.com/plugin/booter.cab
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) - http://www.99liao.com/talk.cab
O16 - DPF: {6BBB1C53-B652-43D9-A267-F6EAD21137CF} - http://www.cciptv.com/zaixianyanshi/controls/cciptvctrl.cab
O16 - DPF: {CF5599D9-85BC-4EC2-996D-2C9C61D80022} - http://www.cciptv.com/zaixianyanshi/controls/cciptvctrl.cab
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll"
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O23 - Service: Human Interface Device Access (HidServ) -  - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
O23 - Service: iPod Service (iPod Service) - Apple Computer, Inc. - "C:\Program Files\iPod\bin\iPodService.exe"
O23 - Service: Mysee2_Runtime (Mysee2_Runtime) - Microsoft Corporation - C:\WINDOWS\system32\svchost.exe -k mysee2
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\CCenter.exe"
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - "C:\Program Files\Rising\Rav\Ravmond.exe"
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
gototop
 

处理结果发现日期扫描方式路径文件
清除成功2006-11-29 14:52文件监控C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\FHD8KS2Y10587exe[1].htm
跳过脚本2006-11-29 14:52网页/脚本监控C:\DOCUME~1\jdy\LOCALS~1\Temp2260157759192.tmp
跳过脚本2006-11-29 14:53网页/脚本监控C:\DOCUME~1\jdy\LOCALS~1\Temp2260157759192.tmp
删除成功2006-11-29 14:53文件监控C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\BECBFPS5bind_40296exe[1].htm
删除成功2006-11-29 14:53文件监控C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\BECBFPS510024exe[1].htm
跳过脚本2006-11-29 14:53网页/脚本监控C:\DOCUME~1\jdy\LOCALS~1\Temp2260157759192.tmp
删除成功2006-11-29 14:53文件监控C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\M97KDC3Qsetupyefg[1].htm
跳过脚本2006-11-29 14:53网页/脚本监控C:\DOCUME~1\jdy\LOCALS~1\Temp2260157759272.tmp
删除成功2006-11-29 14:53文件监控C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\M97KDC3Q0602328exe[1].htm
跳过脚本2006-11-29 14:53网页/脚本监控C:\DOCUME~1\jdy\LOCALS~1\Temp2260157759672.tmp
删除成功2006-11-29 14:53文件监控C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\VESFB1KP888bar16exe[1].htm
删除成功2006-11-29 14:53文件监控C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\VESFB1KP20311exe[1].htm
删除成功2006-11-29 14:53文件监控C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\VESFB1KP20060901003[2].htm
跳过脚本2006-11-29 14:53网页/脚本监控C:\DOCUME~1\jdy\LOCALS~1\Temp2260157760432.tmp
跳过脚本2006-11-29 14:53网页/脚本监控C:\DOCUME~1\jdy\LOCALS~1\Temp2260157760512.tmp
跳过脚本2006-11-29 14:53网页/脚本监控C:\DOCUME~1\jdy\LOCALS~1\Temp2260157760592.tmp
删除成功2006-11-30 13:21文件监控C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\UV8VITWB888bar16exe[1].htm
跳过脚本2006-11-30 13:21网页/脚本监控C:\DOCUME~1\jdy\LOCALS~1\Temp2616163264264.tmp
删除成功2006-11-30 13:21文件监控C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\UV8VITWB0602328exe[1].htm
删除成功2006-11-30 13:21文件监控C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\RV5ZR5WS20311exe[1].htm
删除成功2006-11-30 13:21文件监控C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\GN7VIO1X10587exe[1].htm
跳过脚本2006-11-30 13:21网页/脚本监控C:\DOCUME~1\jdy\LOCALS~1\Temp2616163264264.tmp
跳过脚本2006-11-30 13:21网页/脚本监控C:\DOCUME~1\jdy\LOCALS~1\Temp2616163264264.tmp
跳过脚本2006-11-30 13:21网页/脚本监控C:\DOCUME~1\jdy\LOCALS~1\Temp2616163264264.tmp
gototop
 

病毒名称处理结果发现日期路径文件
Trojan.DL.VBS.Agent.cfc清除成功2006-11-29 14:52C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\FHD8KS2Y10587exe[1].htm
Trojan.DL.VBS.Agent.cgk删除成功2006-11-29 14:52C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\FHD8KS2Y20161exe[1].htm
Trojan.DL.VBS.Agent.cgm重新启动计算机后删除文件2006-11-29 14:52C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\UV8VITWBin[1].js
Trojan.DL.VBS.Agent.cgm删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\UV8VITWBin[1].js
Trojan.DL.VBS.Agent.cfc删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\BECBFPS5bind_40296exe[1].htm
Trojan.DL.VBS.Agent.cfc删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\BECBFPS510024exe[1].htm
Trojan.DL.VBS.Agent.cfc删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\M97KDC3Qsetupyefg[1].htm
Trojan.DL.VBS.Agent.cfc删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\M97KDC3Q0602328exe[1].htm
Trojan.DL.VBS.Agent.cfo删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\VESFB1KPtubar1211[1].htm
Trojan.DL.VBS.Agent.cfc删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\VESFB1KP888bar16exe[1].htm
Trojan.DL.VBS.Agent.cfc删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\VESFB1KP20311exe[1].htm
Trojan.DL.VBS.Agent.cfc删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\VESFB1KP20060901003[2].htm
Trojan.DL.VBS.Agent.cgk删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\GN7VIO1X2283[1].htm
Trojan.DL.VBS.Agent.cgk删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\C1E7K9YJsna[1].htm
Trojan.DL.VBS.Agent.cgk删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\GN7VIO1Xsetup[1].htm
Trojan.DL.VBS.Agent.cgk删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\GN7VIO1Xcs[1].htm
Trojan.DL.VBS.Agent.cgk删除成功2006-11-29 14:53C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\01674DAF1014[1].htm
Trojan.DL.VBS.Agent.cgm删除成功2006-11-30 13:20C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\RV5ZR5WSin[1].js
Trojan.DL.VBS.Agent.cgk删除成功2006-11-30 13:21C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\FHD8KS2Yb5a510717da61d0f[1].htm
Trojan.DL.VBS.Agent.cfc删除成功2006-11-30 13:21C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\UV8VITWB888bar16exe[1].htm
Trojan.DL.VBS.Agent.cfc删除成功2006-11-30 13:21C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\UV8VITWB0602328exe[1].htm
Trojan.DL.VBS.Agent.cfc删除成功2006-11-30 13:21C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\RV5ZR5WS20311exe[1].htm
Trojan.DL.VBS.Agent.cfc删除成功2006-11-30 13:21C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\GN7VIO1X10587exe[1].htm
Trojan.DL.VBS.Agent.cgk删除成功2006-11-30 13:21C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\GN7VIO1Xv730exe[1].htm
Trojan.DL.VBS.Agent.cgk删除成功2006-11-30 13:21C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\89EBCTUB2283[1].htm
Trojan.DL.VBS.Agent.cgk删除成功2006-11-30 13:21C:\Documents and Settings\jdy\Local Settings\Temporary Internet Files\Content.IE5\BECBFPS51014[1].htm
我天天监控都杀这些病毒 我直接上的论坛 都出这些病毒 不知怎么回事 ....
gototop
 

现在正常  只要 新启动就继续杀这些病毒 怎么回事
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT