瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】今天用hijackthis日志分析下 发现一个可以服务 大家看看!!!!

1   1  /  1  页   跳转

【求助】今天用hijackthis日志分析下 发现一个可以服务 大家看看!!!!

【求助】今天用hijackthis日志分析下 发现一个可以服务 大家看看!!!!

Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\KV2006\KVSrvXP.exe
C:\Program Files\KV2006\kvwsc.exe
E:\软件安装\Outpost Firewall\outpost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\KV2006\KVMonXP.kxp
C:\WINDOWS\system32\ctfmon.exe
E:\软件安装\POPO\popo2004\popo.exe
E:\软件安装\QQ2005\QQ.exe
E:\软件安装\QQ2005\TIMPlatform.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\软件安装\TT\TTraveler.exe
F:\装机软件\hijackthis1991\HijackThis.exe

O2 - BHO: FiltrateWebObj Class - {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} - C:\Program Files\KV2006\kvbho_1.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\软件安装\Spybot\SDHelper.dll
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - C:\Program Files\KV2006\KvShell.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - E:\软砑件安沧装癨\NetTransport 2\NTIEHelper.dll (file missing)
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - C:\Program Files\KV2006\KvShell.dll
O4 - HKLM\..\Run: [KvMonXP] C:\Program Files\KV2006\KVMonXP.kxp /auto
O4 - HKLM\..\Run: [Outpost Firewall] E:\软件安装\Outpost Firewall\outpost.exe /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] E:\软件安装\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: 使用影音传送带下载 - E:\软件安装\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - E:\软件安装\NetTransport 2\NTAddList.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock_3.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock_3.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock_3.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock_3.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock_3.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1122538057389
O20 - AppInit_DLLs: E:\软件安装\OUTPOS~1\wl_hook.dll
O21 - SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KVSrvXP - Jiangmin Co. Ltd - C:\Program Files\KV2006\KVSrvXP.exe
O23 - Service: KVWSC - Jiangmin Co.Ltd - C:\Program Files\KV2006\kvwsc.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - E:\软件安装\Outpost Firewall\outpost.exe


这个东东是什么哦?
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

我把他提取出来了 大家看看。
http://219.134.128.58/cgi-bin/dl/05FF2BE22B4F82A23F74623845556D774F62CA097ED0750895E79FA01DBBC3266F25249A4EB0731CE1ED783FA1ADDAC525C8AC8B030264CC7B8F3A48A375B74194D9165F77ED99C02A4557BE72110EF68D06D7AF341E52ACE411/IDriverT.exe

最后编辑2005-10-29 14:43:39
分享到:
gototop
 

顶上去哦!
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT