HijackThis@Qoo的扫描日志 V1.97.7
Scan saved at 18:19:56, on 2006-3-8
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\SearchNet\SearchNet.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\system32\ServeHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\new\LOCALS~1\Temp\Rar$EX00.578\HijackThis.exe
C:\KVNET\CtrlSrv.exe
C:\KVNET\KVWSC.exe
C:\KVNET\KVSrvXP.exe
C:\KVNET\KVTray.exe
C:\KVNET\FrogAgent.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\KVNET\KvXp.kxp
C:\KVNET\kvol.exe
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {16A770A0-0E87-4278-B748-2460D64A8386}? - (no file)
O2 - BHO: KOSIE HelperInternet Explorer Web Content Guard - {1B2F92A1-CDAF-4511-9382-91E3F5CE0880}? - (no file)
O2 - BHO: (no name) - {2A0176FE-008B-4706-90F5-BBA532A49731} - C:\Program Files\SearchNet\SNHpr.dll
O2 - BHO: (no name) - {2A0176FE-008B-4706-90F5-BBA532A49731}? - (no file)
O2 - BHO: (no name) - {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} - C:\KVNET\KVBHO.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162}? - (no file)
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B}? - (no file)
O2 - BHO: (no name) - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - C:\KVNET\KVShell.dll
O2 - BHO: (no name) - {B8CCDD47-38E4-4CD2-B7FA-3B4B690F74BD}? - (no file)
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932}? - (no file)
O2 - BHO: ME
objectSDT - {D4D5C535-BA95-4327-870D-A33826FDD17A}? - (no file)
O3 - Toolbar: (no name) - {EF72500A-C234-46C4-BF0A-9AA6913DDF34}? - (no file)
O3 - Toolbar: ????? - {B5A34A93-D538-43A7-8371-864CB6148D12} - C:\KVNET\KVShell.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [_KAVImmuniteSasser] LsassPatch.EXE
O4 - HKLM\..\Run: [SearchNet_Up] "C:\Program Files\SearchNet\ServeUp.exe"
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [HiCIC] Rundll32.exe "C:\WINDOWS\system32\Mefvortitd.dll",Boot
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - HKLM\..\Run: [AddrPlus3] C:\PROGRA~1\TENCENT\AdPlus\Runner.exe C:\PROGRA~1\TENCENT\AdPlus\SSAddr.dll Rundll32
O4 - HKLM\..\Run: [FeiyingUpdate] C:\DOCUME~1\new\LOCALS~1\Temp\~ex50.exe
O4 - HKLM\..\Run: [CdnCtr] 8V?
O4 - HKLM\..\Run: [KVTray] C:\KVNET\KVTray.exe
O4 - HKLM\..\Run: [KvMonXP] C:\KVNET\KVMonXP.kxp /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [KvXP] C:\KVNET\KvXp.kxp /ScanBoot /ScanSys
O4 - Startup: NTUSER.DAT
O4 - Startup: NTUSER.DAT.LOG
O4 - Startup: ntuser.ini
O4 - Global Startup: ntuser.dat
O4 - Global Startup: ntuser.dat.LOG
O9 - Extra button: QQ (HKLM)
O10 - Unknown file in Winsock LSP: c:\kvnet\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\kvnet\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\kvnet\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\kvnet\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\kvnet\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\kvnet\kvsock.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {74447F9C-5691-4A9A-8BE4-564092E40B03} (VnetAnprIns Class) - http://plugin.chinavnet.com/VnetPluginIns.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153} (Rising Web Scan
Object) - http://download.rising.com.cn/register/pcver/autoupgradepad/pcver2006new/OL2006.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{25D3B4FF-4A58-43FA-8495-34B729F4DDFD}: NameServer = 218.85.157.99 202.101.107.55
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - %SystemRoot%\system32\mshtml.dll