1   1  /  1  页   跳转

[求助] 关于Trojan.DL.Script.VBS.Agent.ex

关于Trojan.DL.Script.VBS.Agent.ex

前几天瑞星监控发现病毒Trojan.DL.Script.VBS.Agent.ex,自动杀毒了,C:\WINDOWS\system32\a.exe也被我删除了,但是后面任务栏里的瑞星绿色雨伞布见了,现在双击“迅雷5”也没反应,不知道怎么回事?
请各位参考图片


Logfile of HijackThis v1.99.1
Scan saved at 3:42:47, on 2009-2-4
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Rising\AntiSpyware\rstray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRAM FILES\汇信软件\USBAUTOINPUT.EXE
C:\WINDOWS\system32\GP_CLT_Service.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alisoft\WangWang\WangWang.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Rising\AntiSpyware\ras.exe
C:\Program Files\Rising\AntiSpyware\knownsvr.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\Xunlei\HijackThis.exe
O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
O2 - BHO: 卡卡上网安全助手 - {98B7C13A-E9CD-4959-8B46-FBEAB41E42A8} - C:\WINDOWS\system32\urlFilter.dll
O3 - Toolbar: 天印签章 - {a8e7924f-d5ab-4e43-98ef-881ec9bf66df} - C:\Program Files\汇信软件\ieband.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera 301x
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [runeip] "C:\Program Files\Rising\AntiSpyware\rstray.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WangWang] "C:\Program Files\Alisoft\WangWang\WangWang.exe"
O4 - HKCU\..\Run: [USBautoinput] C:\PROGRAM FILES\汇信软件\USBAUTOINPUT.EXE
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O8 - Extra context menu item: 使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: 使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O9 - Extra button: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.icinfo.com.cn
O15 - Trusted Zone: cus.icinfo.com.cn
O15 - Trusted Zone: hzaic.icinfo.com.cn
O15 - Trusted Zone: ssl.icinfo.com.cn
O15 - Trusted Zone: tseal.icinfo.com.cn
O15 - Trusted Zone: tseal2.icinfo.com.cn
O15 - Trusted Zone: www.tseal.com.cn
O15 - Trusted Zone: zjaic.icinfo.com.cn
O15 - Trusted Zone: www.huaic.gov.cn
O15 - Trusted Zone: www.hzaic.gov.cn
O15 - Trusted Zone: www.sxgs.gov.cn
O15 - Trusted Zone: www.zjaic.gov.cn
O15 - Trusted Zone: yw.huaic.gov.cn
O15 - Trusted Zone: www.tseal.cn
O15 - Trusted Zone: easyabc.95599.cn (HKLM)
O15 - Trusted Zone: www.95599.cn (HKLM)
O15 - Trusted Zone: ebank.95599.sh.cn (HKLM)
O15 - Trusted Zone: www.95599.sh.cn (HKLM)
O15 - Trusted Zone: www.abchina.com (HKLM)
O15 - Trusted IP range: 61.130.4.68
O15 - Trusted IP range: 61.153.27.242
O15 - Trusted IP range: 218.75.109.245
O15 - Trusted IP range: 61.130.8.188
O15 - Trusted IP range: 218.75.109.242
O15 - Trusted IP range: 202.75.221.19
O15 - Trusted IP range: 202.75.221.24
O15 - Trusted IP range: 202.101.180.219
O15 - Trusted IP range: 211.140.95.28
O15 - Trusted IP range: 61.175.223.171
O15 - Trusted IP range: 61.153.209.126
O15 - Trusted IP range: 61.153.144.21
O15 - Trusted IP range: 61.130.53.3
O15 - Trusted IP range: 218.75.54.90
O15 - Trusted IP range: 61.175.211.169
O15 - Trusted IP range: 218.75.119.173
O15 - Trusted IP range: 61.153.64.196
O15 - Trusted IP range: 61.153.144.20
O15 - Trusted IP range: 60.190.145.34
O15 - Trusted IP range: 61.241.86.4
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://100.0.0.1:8001/ctais2/wssb/ScriptX.cab
O16 - DPF: {1E0DFFCF-27FF-4574-849B-55007349FEDA} (iTrusPTA Class) - https://img.alipay.com/download/1101/aliedit.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (EditCtrl Class) - https://img.alipay.com/download/2121/aliedit.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/newperbank/AxSafeControls.cab
O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab
O16 - DPF: {8385AE81-6DF1-4B3B-B283-19EB2A8C4283} (FileUploader Class) - http://up22.babidou.com/tools/UFileUploader.cab
O16 - DPF: {BAEA0695-03A4-43BB-8495-C7025E1A8F42} (QQCertCtrl Class) - https://www.tenpay.com/download/qqedit.cab
O16 - DPF: {C09B522F-8AED-4E21-A65C-DC1AB652BAEE} (Tencent Safety Online Base Module) - http://safe.qq.com/cgi-bin/tso/TSOBase.ocx
O16 - DPF: {E0E9F6EF-871B-42AE-89C9-CD6AF7A2E5D3} (EditCtrl Class) - https://www.baifubao.com/download/baiedit.cab
O16 - DPF: {E72CFC93-BAE3-8D60-85D1-129993AAC8B9} (UImageUploader Class) - http://up22.babidou.com/tools/UImageUploaderXP.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{41B9C754-F4E3-45FE-9033-EB17EC36CB5C}: NameServer = 202.101.172.35 202.101.172.47
O20 - AppInit_DLLs: kmon.dll
O23 - Service: GP_CLT_Service - Unknown owner - C:\WINDOWS\system32\GP_CLT_Service.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Information Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe


用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; (R1 1.5))
最后编辑dada8888 最后编辑于 2009-02-04 03:40:06
分享到:
gototop
 

回复:关于Trojan.DL.Script.VBS.Agent.ex

还有更好更直接的方法吗,谢谢提供阿!
gototop
 

回复:关于Trojan.DL.Script.VBS.Agent.ex

我刚升级到瑞星09,杀了没病毒,瑞星雨伞是红色的!好像监控都关闭了
gototop
 

回复 5F aryda 的帖子

你别吓唬我哦,用了这么多天没问题啊,就是现在瑞星的绿雨伞变成关闭的红雨伞了
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT