1   1  /  1  页   跳转

最近中的病毒

最近中的病毒

最近总是中病毒,杀毒软件总是提示有恶意脚本活动,一般是提示“explore.exe"试图修改本地文件,外然后桌面出现一个图标,如下图1,这些是什么?病毒吗?

附件附件:

下载次数:270
文件类型:image/pjpeg
文件大小:
上传时间:2006-9-28 9:39:30
描述:



最后编辑2006-09-28 19:30:03
分享到:
gototop
 

以下是扫描的日志文件,
Logfile of HijackThis v1.99.1
Scan saved at 9:25:23, on 2006-9-28
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\program files\internet explorer\IEXPLORE.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Program Files\SkyNet\FireWall\PFWMain.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\KV2004\KVMonXP.kxp
C:\WINNT\system32\internat.exe
C:\KV2004\KVSrvXP.exe
D:\qq\QQ.exe
D:\qq\TIMPlatform.exe
C:\WINNT\system32\conime.exe
D:\My Documents\电脑\ha_hijackthis_1991\HijackThis.exe

O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - C:\KV2004\KvShell.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - D:\NetTransportV1.94\NTIEHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - C:\KV2004\KvShell.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SKYNET Personal FireWall] C:\Program Files\SkyNet\FireWall\PFWMain.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [KvMonXP] C:\KV2004\KVMonXP.kxp /auto
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Google 搜索(&G) - res://c:\program files\google\GoogleToolbar4.dll/cmsearch.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\qq\AddToNetDisk.htm
O8 - Extra context menu item: 使用影音传送带下载 - D:\NetTransportV1.94\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - D:\NetTransportV1.94\NTAddList.html
O8 - Extra context menu item: 反向链接 - res://c:\program files\google\GoogleToolbar4.dll/cmbacklinks.html
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\qq\AddEmotion.htm
O8 - Extra context menu item: 类似网页 - res://c:\program files\google\GoogleToolbar4.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 - res://c:\program files\google\GoogleToolbar4.dll/cmcache.html
O8 - Extra context menu item: 翻译英文字词(&T) - res://c:\program files\google\GoogleToolbar4.dll/cmwordtrans.html
O10 - Unknown file in Winsock LSP: c:\winnt\system32\kvwspxp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\kvwspxp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\kvwspxp.dll
O16 - DPF: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} - http://game.qq.com/QQGame2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1129187745109
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129254565906
O16 - DPF: {88734439-46D0-42C0-A13F-7E881EE550CF} (Filetran Control) - http://www.bluesky.cn/download/filetran.cab
O23 - Service: DHCP Client svchost - Unknown owner - C:\WINNT\SYTEM (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: KVSrvXP - JiangMin Ltd. - C:\KV2004\KVSrvXP.exe
O23 - Service: Nero - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\MSINFO\Nero.exe (file missing)
O23 - Service: Nerot - Unknown owner - C:\WINNT\Nerot.exe

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT