瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 这几个木马怎么杀啊?win32.agent.acf

12   1  /  2  页   跳转

这几个木马怎么杀啊?win32.agent.acf

这几个木马怎么杀啊?win32.agent.acf

Trojan-Downloader.win32.agent.acf
Trojan-Downloader.win32.agent.aah
Trojan-Downloader.win32.small.azx
Trojan-Dropper.win32.agent.ael
Trojan-spy.win32.agent.iw
最后编辑2006-01-12 12:08:46
分享到:
gototop
 

把HJ日志贴上来
gototop
 

用卡巴查到过这些但是说对像无法删除。
gototop
 

哦等等,还在查毒。
gototop
 

HijackThis_zww汉化版扫描日志 V1.99.1
保存于      10:54:46, 日期 2006-1-12
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\SearchNet\SearchNet.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\wuauclt.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\system32\BCUP.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\WINNT\system32\internat.exe
C:\WINNT\system32\conime.exe
C:\WINNT\rundll32.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\DuDu\DDDClient\dudupros.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
F:\共享文件夹\HijackThis1991zww.exe

R3 - URLSearchHook: assist - {1B0E7716-898E-48cc-9690-4E338E8DE1D3} - (no file)
R3 - URLSearchHook: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O1 - Hosts: 204.13.64.174 www.tm8668.com
O1 - Hosts: 204.13.64.174 tm8668.com
O1 - Hosts: 204.13.64.174 www.2008com.com
O1 - Hosts: 204.13.64.174 2008com.com
O1 - Hosts: 204.13.64.174 www.53444.com
O1 - Hosts: 204.13.64.174 53444.com
O1 - Hosts: 204.13.64.174 www.53444.net
O1 - Hosts: 204.13.64.174 53444.net
O1 - Hosts: 204.13.64.174 www.878.cc
O1 - Hosts: 204.13.64.174 878.cc
O1 - Hosts: 204.13.64.174 www.92939.com
O1 - Hosts: 204.13.64.174 92939.com
O1 - Hosts: 204.13.64.174 www.796888.com
O1 - Hosts: 204.13.64.174 796888.com
O1 - Hosts: 204.13.64.174 www.hk6738.com
O1 - Hosts: 204.13.64.174 hk6738.com
O1 - Hosts: 204.13.64.174 www.k3377.com
O1 - Hosts: 204.13.64.174 k3377.com
O1 - Hosts: 204.13.64.174 www.ttmm66.com
O1 - Hosts: 204.13.64.174 ttmm66.com
O1 - Hosts: 204.13.64.174 www.7707.hk
O1 - Hosts: 204.13.64.174 7707.hk
O1 - Hosts: 204.13.64.174 www.hk3344.com
O1 - Hosts: 204.13.64.174 hk3344.com
O1 - Hosts: 204.13.64.174 www.9994777.com
O1 - Hosts: 204.13.64.174 9994777.com
O1 - Hosts: 204.13.64.174 www.hk691.com
O1 - Hosts: 204.13.64.174 hk691.com
O1 - Hosts: 204.13.64.174 www.ok0888.com
O1 - Hosts: 204.13.64.174 ok0888.com
O1 - Hosts: 204.13.64.174 www.55677.com
O1 - Hosts: 204.13.64.174 55677.com
O1 - Hosts: 204.13.64.174 www.hh689.com
O1 - Hosts: 204.13.64.174 hh689.com
O1 - Hosts: 204.13.64.174 www.48123.com
O1 - Hosts: 204.13.64.174 48123.com
O1 - Hosts: 204.13.64.174 www.kk811.com
O1 - Hosts: 204.13.64.174 kk811.com
O1 - Hosts: 204.13.64.174 www.7k8k9k.com
O1 - Hosts: 204.13.64.174 7k8k9k.com
O1 - Hosts: 204.13.64.174 www.k678.com
O1 - Hosts: 204.13.64.174 k678.com
O1 - Hosts: 204.13.64.174 www.9999k.com
O1 - Hosts: 204.13.64.174 9999k.com
O1 - Hosts: 204.13.64.174 www.666fff.com
O1 - Hosts: 204.13.64.174 666fff.com
O1 - Hosts: 204.13.64.174 www.kk7878.com
O1 - Hosts: 204.13.64.174 kk7878.com
O1 - Hosts: 204.13.64.174 www.kk321.com
O1 - Hosts: 204.13.64.174 kk321.com
O1 - Hosts: 204.13.64.174 www.18099.cc
O1 - Hosts: 204.13.64.174 18099.cc
O1 - Hosts: 204.13.64.174 www.tm80.net
O1 - Hosts: 204.13.64.174 tm80.net
O1 - Hosts: 204.13.64.174 www.66346.com
O1 - Hosts: 204.13.64.174 66346.com
O1 - Hosts: 204.13.64.174 www.4428.cn
O1 - Hosts: 204.13.64.174 4428.cn
O1 - Hosts: 204.13.64.174 www.v8885.com
O1 - Hosts: 204.13.64.174 v8885.com
O1 - Hosts: 204.13.64.174 www.558868.com
O1 - Hosts: 204.13.64.174 558868.com
O1 - Hosts: 204.13.64.174 www.18899.com
O1 - Hosts: 204.13.64.174 18899.com
O1 - Hosts: 204.13.64.174 www.hp5868.com
O1 - Hosts: 204.13.64.174 hp5868.com
O1 - Hosts: 204.13.64.174 www.hksaimahuilhc.com
O1 - Hosts: 204.13.64.174 hksaimahuilhc.com
O1 - Hosts: 204.13.64.174 www.t838.com
O1 - Hosts: 204.13.64.174 t838.com
O1 - Hosts: 204.13.64.174 www.688555.com
O1 - Hosts: 204.13.64.174 688555.com
O1 - Hosts: 204.13.64.174 www.676888.com
O1 - Hosts: 204.13.64.174 676888.com
O1 - Hosts: 204.13.64.174 www.gg7777.com
O1 - Hosts: 204.13.64.174 gg7777.com
O1 - Hosts: 204.13.64.174 www.kk7999.com
O1 - Hosts: 204.13.64.174 kk7999.com
O1 - Hosts: 204.13.64.174 www.GG444.com
O1 - Hosts: 204.13.64.174 GG444.com
O1 - Hosts: 204.13.64.174 www.xg990.com
O1 - Hosts: 204.13.64.174 xg990.com
O1 - Hosts: 204.13.64.174 www.qq6789.com
O1 - Hosts: 204.13.64.174 qq6789.com
O1 - Hosts: 204.13.64.174 www.ma333.com
O1 - Hosts: 204.13.64.174 ma333.com
O1 - Hosts: 204.13.64.174 www.59659.com
O1 - Hosts: 204.13.64.174 59659.com
O1 - Hosts: 204.13.64.174 www.993999.com
O1 - Hosts: 204.13.64.174 993999.com
O1 - Hosts: 204.13.64.174 www.6306.com
O1 - Hosts: 204.13.64.174 6306.com
O1 - Hosts: 204.13.64.174 www.13444.com
O1 - Hosts: 204.13.64.174 13444.com
O1 - Hosts: 204.13.64.174 www.tm286.com
O1 - Hosts: 204.13.64.174 tm286.com
O1 - Hosts: 204.13.64.174 www.cctv138.com
O1 - Hosts: 204.13.64.174 cctv138.com
O1 - Hosts: 204.13.64.174 www.tm886.com
O1 - Hosts: 204.13.64.174 tm886.com
O1 - Hosts: 204.13.64.174 www.cgokok.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O2 - BHO: DuDu.com - {6BDE1669-B490-48E3-B668-456314F2D6C3} - C:\Program Files\DuDu\DddClient\dddiemon.dll
O2 - BHO: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINNT\system32\drivers\inf\bands.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\yisou\yisoub.dll (file missing)
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - IE工具栏增项: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O3 - IE工具栏增项: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\Program Files\yisou\yisou.dll (file missing)
O3 - IE工具栏增项: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O3 - IE工具栏增项: 博采 - {4DA2EE61-6399-4C39-AEB9-0D990E610D29} - C:\WINNT\system32\BoCaiToolbar.dll
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [nwiz] nwiz.exe /install
O4 - 启动项HKLM\\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [SDiskDaemon] C:\WINNT\sdiskmon.exe
O4 - 启动项HKLM\\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [warehost] warehost.exe
O4 - 启动项HKLM\\Run: [MoveSearch] C:\Program Files\wsearch\Search.exe
O4 - 启动项HKLM\\Run: [BCUpdate] C:\WINNT\system32\BCUP.exe
O4 - 启动项HKLM\\Run: [ADShow] C:\WINNT\system32\bcsysnote.exe
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - 启动项HKLM\\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [CnsMin] Rundll32.exe C:\WINNT\downlo~1\CnsMin.dll,Rundll32
O4 - 启动项HKLM\\Run: [SearchNet_Up] "C:\Program Files\SearchNet\ServeUp.exe"
O4 - 启动项HKLM\\Run: [] regedit -s C:\$NtUninstallQ5926809$\spcustom.dll
O4 - 启动项HKLM\\Run: [3721] C:\$NtUninstallQ5926809$\a3721.bat
O4 - 启动项HKLM\\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - 启动项HKLM\\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\spcustom.dll
O4 - HKCU\..\Run: [3721] C:\$NtUninstallQ5926809$\a3721.bat
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O4 - Startup: 桌面媒体.lnk = C:\WINNT\system32\rundll32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: DuDu加速器.lnk = C:\Program Files\DuDu\DDDClient\DuDuAcc.exe
O4 - Global Startup: 桌面传媒.lnk = C:\WINNT\system32\rundll32.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(3).lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
gototop
 

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: !搜一搜(&S) - res://C:\Program Files\yisou\yisou.dll/232
O8 - IE右键菜单中的新增项目: &使用DuDu 加速器下载 - res://C:\Program Files\DuDu\DddClient\dddmext.dll/202
O8 - IE右键菜单中的新增项目: &使用DuDu 加速器下载全部链接 - res://C:\Program Files\DuDu\DddClient\dddmext.dll/203
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - IE右键菜单中的新增项目: 百度-搜索MP3 - res://C:\WINNT\DOWNLO~1\BaiDuBar.dll/BAIDUMP3.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索图片 - res://C:\WINNT\DOWNLO~1\BaiDuBar.dll/BAIDUIMG.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索新闻 - res://C:\WINNT\DOWNLO~1\BaiDuBar.dll/BAIDUNEWS.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索歌词 - res://C:\WINNT\DOWNLO~1\BaiDuBar.dll/BAIDULYRIC.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索网页 - res://C:\WINNT\DOWNLO~1\BaiDuBar.dll/BAIDUSEARCH.HTM
O8 - IE右键菜单中的新增项目: 百度-搜索贴吧 - res://C:\WINNT\DOWNLO~1\BaiDuBar.dll/BAIDUPOST.HTM
O8 - IE右键菜单中的新增项目: 百度-词典搜索 - res://C:\WINNT\DOWNLO~1\BaiDuBar.dll/BAIDU_DIC.HTM
O8 - IE右键菜单中的新增项目: 访问通用网址 - C:\Program Files\CNNIC\Cdn\cnnic.htm
O8 - IE右键菜单中的新增项目: 雅虎搜索 - res://C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll/246
O9 - 浏览器额外的按钮: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=201010_1006 (file missing)
O9 - 浏览器额外的按钮: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - 浏览器额外的“工具”菜单项: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - 浏览器额外的按钮: 下载管理 - {3DB9F45E-AA74-4373-A466-C18A9F1C500D} - C:\Program Files\DuDu\DddClient\DuDuAcc.exe
O9 - 浏览器额外的“工具”菜单项: 下载管理 - {3DB9F45E-AA74-4373-A466-C18A9F1C500D} - C:\Program Files\DuDu\DddClient\DuDuAcc.exe
O9 - 浏览器额外的按钮: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - 浏览器额外的按钮: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - 浏览器额外的按钮: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - 浏览器额外的按钮: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - 浏览器额外的“工具”菜单项: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O10 - 未知的文件在 Winsock LSP: c:\winnt\system32\cdnns.dll
O11 - Options group: [!CNS]  上网助手-地址栏搜索
O11 - Options group: [CDNCLIENT]  中文上网
O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - http://bar.baidu.com/update/IESearch.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview 控件) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O18 - 列举现有的协议: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINNT\system32\mbprot.dll
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - NT 服务: Remote Log - Unknown owner - C:\WINNT\system32\ServeHost.exe (file missing)
gototop
 

刚刚杀了几个毒。
gototop
 

我也要杀
gototop
 






gototop
 

【回复“梦遊的鱼”的帖子】
O4 - 启动项HKLM\\Run: [SDiskDaemon] C:\WINNT\sdiskmon.exe
O4 - 启动项HKLM\\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - 启动项HKLM\\Run: [SearchNet_Up] "C:\Program Files\SearchNet\ServeUp.exe"
O4 - 启动项HKLM\\Run: [] regedit -s C:\$NtUninstallQ5926809$\spcustom.dll
O4 - 启动项HKLM\\Run: [3721] C:\$NtUninstallQ5926809$\a3721.bat
O4 - 启动项HKLM\\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\spcustom.dll
O4 - HKCU\..\Run: [3721] C:\$NtUninstallQ5926809$\a3721.bat
O23 - NT 服务: Remote Log - Unknown owner - C:\WINNT\system32\ServeHost.exe (file missing)

晕死啊!!这系统够热闹!
用HJ修复这些项目。建议在安全模式下删除相应文件。如果不能搞掂,请将那些文件打包,发到:baohelin@yahoo.com.cn。
——————————

O4 - Global Startup: DuDu加速器.lnk = C:\Program Files\DuDu\DDDClient\DuDuAcc.exe

这破玩意儿是“嘟嘟加速器”,强烈建议卸载它!
————————
用HJ修复所有O1项(你的HOSTS文件已经被篡改的乱七八糟了)。
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT