12   1  /  2  页   跳转

【求助】惊着了~~高手帮忙看看

【求助】惊着了~~高手帮忙看看

我现在一打开网页  我得木马一扫光就弹出来  提示我 IEXPLORE.EXE对注册表中ie起始页,标题基本设置的位置进行修改设置键值得操作!!!!现在一开就出  !!盼高手指教(木马一扫光已经拦截  但是老是这样蹦  看着让人闹心)
最后编辑2006-09-12 21:35:52
分享到:
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 12:27:56, on 2000-6-25
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\PROGRA~1\KV2005\KVSrvXP.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Iparmor\Iparmor.exe
C:\Program Files\KV2005\KVMonXP_2.kxp
C:\PROGRA~1\SkyNet\FireWall\pfw.exe
C:\WINNT\system32\Internat.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\KV2005\TrojDie.kxp
C:\Program Files\KV2005\KRegEx.exe
C:\WINNT\system32\DllHost.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\桌面\HijackThis V1[1].99.1汉化版\HijackThis.exe

O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINNT\system32\xunleibho_v6.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - C:\Program Files\KV2005\KvShell_2.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: tscgm Class - {D11D0862-0390-4884-A95C-4702D0D4C11A} - C:\WINNT\system32\coredrv32.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - C:\Program Files\KV2005\KvShell_2.dll
O3 - Toolbar: BitComet工具栏 - {3F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\BitComet\BitCometBar\BitCometBar0.6.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [iparmor] C:\Program Files\Iparmor\Iparmor.exe mini
O4 - HKLM\..\Run: [KvMonXP] "C:\Program Files\KV2005\KVMonXP_2.kxp" /auto
O4 - HKLM\..\Run: [SKYNET Personal FireWall] C:\PROGRA~1\SkyNet\FireWall\pfw.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [Internat.exe] Internat.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: 视频聊天 - {6924091F-CD97-41E1-B1D4-D9079409D413} - http://www.liantang.net (file missing)
O9 - Extra 'Tools' menuitem: 视频聊天 - {6924091F-CD97-41E1-B1D4-D9079409D413} - http://www.liantang.net (file missing)
O9 - Extra button: 寻论网--中学作业解答 - {6924091F-CD97-41E1-B1D4-D9079409D423} - http://www.xunlun.com (file missing)
O9 - Extra 'Tools' menuitem: 中学作业 - {6924091F-CD97-41E1-B1D4-D9079409D423} - http://www.xunlun.com (file missing)
O9 - Extra button: kele8 - {84920E5F-3788-49cd-A274-E365578DF174} - http://www.kele8.com/ (file missing)
O9 - Extra 'Tools' menuitem: kele8 - {84920E5F-3788-49cd-A274-E365578DF174} - http://www.kele8.com/ (file missing)
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\kvwspxp_1.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\kvwspxp_1.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\kvwspxp_1.dll
O16 - DPF: {2D4851FD-0BFE-11D4-9260-9AF666D52059} (GameX Class) - http://202.108.34.243/game/system/activex/gamex.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} (WebActivater Control) - http://game.qq.com/QQGame2.cab
O16 - DPF: {3F618E1F-D981-4905-A757-4D237441B5B3} (GolfInstallCheck2 Class) - http://download.ourgame.com/GolfInstallCheck2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124098019544
O16 - DPF: {9242BB35-0DB0-43AC-8DFC-8EA07E63B92A} (LiveMediaOcx Control) - http://dl_dir.qq.com/qqtv/QQLiveOcxSetup.exe
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown4.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3CA8826C-27E1-4EC7-B7D3-61689E1A2F7F}: NameServer = 202.102.154.3 202.102.152.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{3CA8826C-27E1-4EC7-B7D3-61689E1A2F7F}: NameServer = 202.102.154.3 202.102.152.3
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: KVSrvXP - JiangMin New Tech Ltd. - C:\PROGRA~1\KV2005\KVSrvXP.exe
O23 - Service: KVSrvXP_1 - JiangMin New Tech Ltd. - (no file)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe

gototop
 

谢谢阿  现在很着急
gototop
 

自己在顶一下~~~~
gototop
 

再顶~~~~~~~~~~~~~~~~~~~~~~
gototop
 

开一个网页  木马一扫光  就提示一次  。。。。。。。。。。
gototop
 

秋日  我用你说的又扫描一次  你看看怎么解决好
2006-09-26,02:01:27

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <Internat.exe><Internat.exe>  [Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Synchronization Manager><mobsync.exe /logon>  [Microsoft Corporation]
    <TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot>  [RealNetworks, Inc.]
    <iparmor><C:\Program Files\Iparmor\Iparmor.exe mini>  []
    <KvMonXP><"C:\Program Files\KV2005\KVMonXP_2.kxp" /auto>  [JiangMin Co.Ltd]
    <SKYNET Personal FireWall><C:\PROGRA~1\SkyNet\FireWall\pfw.exe>  [广州众达天网技术有限公司]
    <NvCplDaemon><RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup>  [NVIDIA Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINNT\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []

==================================
启动文件夹
服务
[Logical Disk Manager Administrative Service / dmadmin]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[InstallDriver Table Manager / IDriverT]
  <"C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"><Macrovision Corporation>
[KVSrvXP / KVSrvXP]
  <C:\PROGRA~1\KV2005\KVSrvXP.exe -Service><JiangMin New Tech Ltd.>
[KVSrvXP_1 / KVSrvXP_1]
  <><N/A>
[NVIDIA Display Driver Service / NVSvc]
  <C:\WINNT\system32\nvsvc32.exe><NVIDIA Corporation>
[StdService / StdService]
  <C:\WINNT\system32\rundll32.exe C:\WINNT\system32\STDSVER.DLL,Service><N/A>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINNT\system32\xunleibho_v6.dll, >
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[DragSearch BHO]
  {62EED7C6-9F02-42f9-B634-98E2899E147B} <C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL, >
[BrowseHelper Class]
  {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} <C:\Program Files\KV2005\KvShell_2.dll, JiangMin Lmt>
[IeCatch2 Class]
  {A5366673-E8CA-11D3-9CD9-0090271D075B} <C:\PROGRA~1\FlashGet\jccatch.dll, Amaze Soft>
[tscgm Class]
  {D11D0862-0390-4884-A95C-4702D0D4C11A} <C:\WINNT\system32\coredrv32.dll, >
[视频聊天]
  {6924091F-CD97-41E1-B1D4-D9079409D413} <http://www.liantang.net, N/A>
[寻论网--中学作业解答]
  {6924091F-CD97-41E1-B1D4-D9079409D423} <http://www.xunlun.com, N/A>
[kele8]
  {84920E5F-3788-49cd-A274-E365578DF174} <http://www.kele8.com/, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <C:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
[FlashGet]
  {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} <C:\PROGRA~1\FlashGet\flashget.exe, Amaze Soft>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <C:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[@msdxmLC.dll,-1@2052,电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\system32\msdxm.ocx, Microsoft Corporation>
[FlashGet Bar]
  {E0E899AB-F487-11D5-8D29-0050BA6940E3} <C:\PROGRA~1\FlashGet\fgiebar.dll, Amaze Soft>
[江民杀毒工具栏]
  {B5A34A93-D538-43A7-8371-864CB6148D12} <C:\Program Files\KV2005\KvShell_2.dll, JiangMin Lmt>
[BitComet工具栏]
  {3F1ABCDB-A875-46c1-8345-B72A4567E486} <C:\Program Files\BitComet\BitCometBar\BitCometBar0.6.dll, N/A>
[GameX Class]
  {2D4851FD-0BFE-11D4-9260-9AF666D52059} <C:\WINNT\Downloaded Program Files\gamex.dll, 北京线线通科技开发有限公司>
[Cult3D ActiveX Player]
  {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} <C:\WINNT\system32\Cult3D\IECult.dll, Cycore AB>
[WebActivater Control]
  {3D8F74EE-8692-4F8F-B8D2-7522E732519E} <C:\WINNT\system32\WEBACT~1.OCX, QQ>
[GolfInstallCheck2 Class]
  {3F618E1F-D981-4905-A757-4D237441B5B3} <C:\WINNT\Downloaded Program Files\CONFLICT.1\GolfInstallCheck2.dll, >
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINNT\system32\wuweb.dll, Microsoft Corporation>
[LiveMediaOcx Control]
  {9242BB35-0DB0-43AC-8DFC-8EA07E63B92A} <C:\PROGRA~1\Tencent\QQLive\QQLive.ocx, Tencent>
[IEDown Class]
  {D0A29C6C-AA71-4423-8C4A-5998B774C448} <C:\WINNT\system32\GLIEDown2.dll, N/A>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash9.ocx, Adobe Systems, Inc.>
[&使用下载加速专家下载]
  <, N/A>
[上传到QQ网络硬盘]
  <C:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
[使用网际快车下载]
  <C:\Program Files\FlashGet\jc_link.htm, N/A>
[使用网际快车下载全部链接]
  <C:\Program Files\FlashGet\jc_all.htm, N/A>
[添加到QQ自定义面板]
  <C:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
[添加到QQ表情]
  <C:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <C:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

==================================
正在运行的进程
[PID: 156][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.00.2195.6601>
[PID: 184][\??\C:\WINNT\system32\csrss.exe]  <Microsoft Corporation><5.00.2195.6601>
[PID: 204][\??\C:\WINNT\system32\winlogon.exe]  <Microsoft Corporation><5.00.2195.6997>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 232][C:\WINNT\system32\services.exe]  <Microsoft Corporation><5.00.2195.7035>
    [C:\WINNT\system32\dmserver.dll]  <VERITAS Software Corp.><2195.6605.297.3>
    [C:\WINNT\system32\KvWspXp_1.dll]  <JiangMin Ltd.><9, 0, 5, 324>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 244][C:\WINNT\system32\lsass.exe]  <Microsoft Corporation><5.00.2195.7011>
    [C:\WINNT\system32\KvWspXp_1.dll]  <JiangMin Ltd.><9, 0, 5, 324>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 424][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
    [C:\WINNT\system32\KvWspXp_1.dll]  <JiangMin Ltd.><9, 0, 5, 324>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 452][C:\WINNT\system32\spoolsv.exe]  <Microsoft Corporation><5.00.2195.7059>
    [C:\WINNT\system32\KvWspXp_1.dll]  <JiangMin Ltd.><9, 0, 5, 324>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 484][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 500][C:\PROGRA~1\KV2005\KVSrvXP.exe]  <JiangMin New Tech Ltd.><9, 0, 5, 720>
    [C:\PROGRA~1\KV2005\UpdateX.dll]  <JiangMin Ltd.><8, 0, 0, 0>
    [C:\Program Files\KV2005\KVEnhD.dll]  <JiangMin Ltd.><9, 1, 5, 423>
    [C:\Program Files\KV2005\KvSPI.dll]  <JiangMin New Tech. Ltd.><9, 0, 5, 720>
    [C:\PROGRA~1\KV2005\PProtect.dll]  <北京江民新科技术公司><1.0.121>
gototop
 

[C:\Program Files\KV2005\KVEnhP_1.dll]  <JiangMin Ltd.><9, 0, 5, 405>
    [C:\Program Files\KV2005\KVEnhM.dll]  <JiangMin Ltd.><9.0.0.500>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\KV2005\KvSpiPS.dll]  <JiangMin Ltd.><9.0.0.501>
    [C:\WINNT\system32\KvWspXp_1.dll]  <JiangMin Ltd.><9, 0, 5, 324>
    [C:\Program Files\KV2005\KVEnhC.DLL]  <JiangMin Ltd.><9, 1, 5, 603>
    [C:\Program Files\KV2005\KVEnhO.dll]  <JiangMin New Tech Ltd.><9, 0, 5, 507>
    [C:\Program Files\KV2005\KVEnhS.dll]  <JiangMin New Tech Ltd.><9, 0, 5, 607>
    [C:\Program Files\KV2005\KVEnhJ.dll]  <JiangMin New Tech. Ltd.><9, 1, 5, 508>
    [C:\Program Files\KV2005\KVExtCab.dll]  <JiangMin New Tech. Ltd.><9, 0, 5, 621>
    [C:\Program Files\KV2005\KVExtEml.dll]  <JiangMin New Tech. Ltd.><9, 0, 0, 503>
    [C:\Program Files\KV2005\KVExtGz.dll]  <Jiangmin New Tech.><9, 0, 5, 420>
    [C:\Program Files\KV2005\KVExtLZH.dll]  <N/A><N/A>
    [C:\Program Files\KV2005\KvExtRar.dll]  <JiangMin Ltd.><9, 1, 0, 804>
    [C:\Program Files\KV2005\KVExtTar.dll]  <Jiangmin New Tech.><9, 0, 5, 420>
    [C:\Program Files\KV2005\KVExtZ.dll]  <Jiangmin New Tech.><9.1.0.503>
    [C:\Program Files\KV2005\KvExtZip.dll]  <JiangMin Ltd.><9, 0, 5, 420>
    [C:\Program Files\KV2005\KVEnhK.dll]  <JiangMin Ltd.><9, 1, 5, 507>
    [C:\Program Files\KV2005\lang\PrivateCfg0804.lng]  <TODO: <Company name>><1.0.0.1>
[PID: 552][C:\WINNT\system32\nvsvc32.exe]  <NVIDIA Corporation><6.14.10.8204>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 592][C:\WINNT\system32\regsvc.exe]  <Microsoft Corporation><5.00.2195.6701>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 652][C:\WINNT\system32\MSTask.exe]  <Microsoft Corporation><4.71.2195.6972>
    [C:\WINNT\system32\KvWspXp_1.dll]  <JiangMin Ltd.><9, 0, 5, 324>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 820][C:\WINNT\Explorer.EXE]  <Microsoft Corporation><5.00.3700.6690>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\KV2005\KvShell_2.dll]  <JiangMin Lmt><9, 0, 5, 1205>
    [C:\Program Files\KV2005\UpdateX.dll]  <JiangMin Ltd.><8, 0, 0, 0>
    [C:\Program Files\KV2005\lang\Kvxp0804_1.lng]  <N/A><N/A>
    [C:\Program Files\KV2005\APIImpl.dll]  <JiangMin Ltd.><9.0.0.500>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [C:\Program Files\KV2005\GUIExt.dll]  <JiangMin Ltd.><9.0.0.501>
    [C:\Program Files\KV2005\lang\GUIExt0804.lng]  <JiangMin Ltd.><7, 1, 0, 200>
    [C:\WINNT\system32\xunleibho_v6.dll]  <><4, 4, 0, 31>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  <><1, 2, 6, 1005>
    [C:\PROGRA~1\FlashGet\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\WINNT\system32\nvtuicpl.cpl]  <N/A><N/A>
    [C:\WINNT\system32\NVWRSZHC.DLL]  <NVIDIA Corporation><6.14.10.11003>
[PID: 900][C:\Program Files\Common Files\Real\Update_OB\realsched.exe]  <RealNetworks, Inc.><0.1.0.3208>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 908][C:\Program Files\Iparmor\Iparmor.exe]  <N/A><N/A>
    [C:\Program Files\Iparmor\getportlistxp.dll]  <><1, 0, 0, 1>
    [C:\Program Files\Iparmor\socketinit.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\hookhookdll.dll]  <N/A><N/A>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\KV2005\KVMonXP_2.kxp]  <JiangMin Co.Ltd><9, 2, 0, 60118>
    [C:\Program Files\KV2005\UpdateX.dll]  <JiangMin Ltd.><8, 0, 0, 0>
    [C:\Program Files\KV2005\lang\Kvxp0804_1.lng]  <N/A><N/A>
    [C:\Program Files\KV2005\GUIExt.dll]  <JiangMin Ltd.><9.0.0.501>
    [C:\Program Files\KV2005\lang\GUIExt0804.lng]  <JiangMin Ltd.><7, 1, 0, 200>
    [C:\Program Files\KV2005\KVEnhP_1.dll]  <JiangMin Ltd.><9, 0, 5, 405>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\KV2005\KvSpiPS.dll]  <JiangMin Ltd.><9.0.0.501>
    [C:\Program Files\KV2005\KvOffice.dll]  <JiangMin New Tech.><9.0.0.1213>
    [C:\Program Files\KV2005\lang\KVOffice0804.lng]  <N/A><N/A>
    [C:\Program Files\KV2005\VirusUpload.dll]  <N/A><2, 0, 0, 0>
    [C:\Program Files\KV2005\lang\PrivateCfg0804.lng]  <TODO: <Company name>><1.0.0.1>
    [C:\Program Files\KV2005\PProtect.dll]  <北京江民新科技术公司><1.0.121>
[PID: 920][C:\PROGRA~1\SkyNet\FireWall\pfw.exe]  <广州众达天网技术有限公司><2.7.7.1000>
    [C:\PROGRA~1\SkyNet\FireWall\SKYMISC.DLL]  <N/A><N/A>
    [C:\PROGRA~1\SkyNet\FireWall\COMPRESSWRAP.DLL]  <N/A><N/A>
    [C:\WINNT\system32\KvWspXp_1.dll]  <JiangMin Ltd.><9, 0, 5, 324>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 940][C:\WINNT\system32\Internat.exe]  <Microsoft Corporation><5.00.2920.0000>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 668][C:\WINNT\system32\stisvc.exe]  <Microsoft Corporation><5.00.2195.6656>
    [C:\WINNT\system32\VM31bSTI.dll]  <VM><4.2.510.21>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 584][C:\WINNT\System32\WBEM\WinMgmt.exe]  <Microsoft Corporation><1.50.1085.0100>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
[PID: 948][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
    [C:\WINNT\system32\KvWspXp_1.dll]  <JiangMin Ltd.><9, 0, 5, 324>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\KV2005\TrojDie.kxp]  <Jiangmin Co.Ltd><9, 0, 5, 916>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\Program Files\KV2005\UpdateX.dll]  <JiangMin Ltd.><8, 0, 0, 0>
    [C:\Program Files\KV2005\lang\TrojDie0804.lng]  <N/A><N/A>
    [C:\Program Files\KV2005\GUIExt.dll]  <JiangMin Ltd.><9.0.0.501>
    [C:\Program Files\KV2005\lang\GUIExt0804.lng]  <JiangMin Ltd.><7, 1, 0, 200>
    [C:\Program Files\KV2005\PProtect.dll]  <北京江民新科技术公司><1.0.121>
    [C:\Program Files\KV2005\ComUIPS.dll]  <N/A><9. 5. 5. 20>
[PID: 760][C:\Program Files\KV2005\KRegEx.exe]  <Jiangmin><1.0.1.0413>
    [C:\Program Files\KV2005\KRegEx.dll]  <N/A><N/A>
    [C:\Program Files\KV2005\KRegTrust.dll]  <Jiangmin Co. Ltd.><9.0.0.825>
[PID: 868][C:\WINNT\system32\DllHost.exe]  <Microsoft Corporation><5.00.2195.6692>
    [C:\Program Files\KV2005\ComUI.dll]  <Jiangmin Ltd.><9. 5. 5. 20>
    [C:\Program Files\KV2005\UpdateX.dll]  <JiangMin Ltd.><8, 0, 0, 0>
    [C:\Program Files\KV2005\ComUIPS.dll]  <N/A><9. 5. 5. 20>
    [C:\Program Files\KV2005\GUIExt.dll]  <JiangMin Ltd.><9.0.0.501>
    [C:\Program Files\KV2005\lang\GUIExt0804.lng]  <JiangMin Ltd.><7, 1, 0, 200>
[PID: 824][C:\Program Files\Internet Explorer\IEXPLORE.EXE]  <Microsoft Corporation><6.00.2800.1106>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\WINNT\system32\xunleibho_v6.dll]  <><4, 4, 0, 31>
    [C:\Program Files\Tencent\QQ\QQIEHelper.dll]  <深圳市腾讯计算机系统有限公司><1, 1, 0, 5>
    [C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]  <><1, 2, 6, 1005>
    [C:\Program Files\KV2005\KvShell_2.dll]  <JiangMin Lmt><9, 0, 5, 1205>
    [C:\Program Files\KV2005\UpdateX.dll]  <JiangMin Ltd.><8, 0, 0, 0>
    [C:\Program Files\KV2005\lang\Kvxp0804_1.lng]  <N/A><N/A>
    [C:\Program Files\KV2005\APIImpl.dll]  <JiangMin Ltd.><9.0.0.500>
    [C:\PROGRA~1\FlashGet\jccatch.dll]  <Amaze Soft><1, 1, 4, 0>
    [C:\WINNT\system32\coredrv32.dll]  <><1, 0, 0, 1>
    [C:\WINNT\system32\KvWspXp_1.dll]  <JiangMin Ltd.><9, 0, 5, 324>
    [C:\WINNT\system32\Macromed\Flash\Flash9.ocx]  <Adobe Systems, Inc.><9,0,16,0>
[PID: 1196][C:\WINNT\system32\rundll32.exe]  <Microsoft Corporation><5.00.2134.1>
    [C:\WINNT\system32\coredrv32.dll]  <><1, 0, 0, 1>
[PID: 1412][C:\PROGRA~1\KV2005\kvolself.exe]  <Jiangmin ><9, 0, 2, 60518>
[PID: 1016][C:\Documents and Settings\Administrator\桌面\sreng2\SREng2\SREng.exe]  <Smallfrogs Studio><2.0.21.505>
    [C:\Program Files\Iparmor\SocketArmor.dll]  <N/A><N/A>
    [C:\WINNT\system32\KvWspXp_1.dll]  <JiangMin Ltd.><9, 0, 5, 324>

==================================
文件关联
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINNT\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]
gototop
 

我看了  你给得那个连接  他的症状和我不一样
我的网页没有任何异常  因为木马一扫光我已经设置了不允许她做任何调整(已拦截此操作)  所以一打开一个网页他就会提示我 这个坏东西要求改变
gototop
 

人太多了  自己在顶一下  贴字上去~~~~~~~~~~~~
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT