1   1  /  1  页   跳转

怎么清除9505上网导航

怎么清除9505上网导航

HijackThis_815汉化版扫描日志 V1.99.1
保存于      12:32:40, 日期 2006-11-17
操作系统:  Windows XP SP1 (WinNT 5.01.2600)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\KV2006\KVSrvXP.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\KV2006\KVMonXP.kxp
C:\Program Files\KVFW\KVFWMCL.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\ctfmon.exe
E:\Hijackthis1991zww\HijackThis1991zww.exe
C:\Program Files\KV2006\TrojDie.kxp
C:\Program Files\KV2006\KRegEx.exe
C:\Program Files\KV2006\UIHost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\KV2006\TrojDie.kxp
D:\新建文件夹\Program\Thunder5.exe
C:\Program Files\KV2006\KvXP.kxp
E:\Hijackthis1991zww\HijackThis1991zww.exe

R3 - 默认的URLSearchHook丢失。用HijackThis修复
O1 - Hosts: 222.88.90.22 www.4199.com
O1 - Hosts: 222.88.90.22 4199.com
O1 - Hosts: 222.88.90.22 www.9505.com
O1 - Hosts: 222.88.90.22 9505.com
O1 - Hosts: 222.88.90.22 7939.com
O1 - Hosts: 222.88.90.22 www.7939.com
O1 - Hosts: 222.88.90.22 www.3448.com
O1 - Hosts: 218.201.94.20 bbs.360safe.com
O1 - Hosts: 218.201.94.20 www.360safe.com
O1 - Hosts: 218.201.94.20 www.piaoxue.com
O1 - Hosts: 218.201.94.20 61.129.58.12
O1 - Hosts: 218.201.94.20 forum.jiangmin.com
O1 - Hosts: 218.201.94.20 luosoft.com
O1 - Hosts: 218.201.94.20 cn.zs.yahoo.com
O1 - Hosts: 218.201.94.20 www.znmq.com
O1 - Hosts: 218.201.94.20 auto.search.msn.com
O1 - Hosts: 218.201.94.20 www.pcav.cn
O1 - Hosts: 218.201.94.20 www.cnhx.com.cn
O1 - Hosts: 218.201.94.20 btbaicai.com
O1 - Hosts: 218.201.94.20 219.239.102.77
O1 - Hosts: 218.201.94.20 hz.mop-hz.com
O1 - Hosts: 218.201.94.20 www.jacai.com
O1 - Hosts: 218.201.94.20 bbs.168safe.com
O1 - Hosts: 218.201.94.20 ok.mop-hz.com
O1 - Hosts: 218.201.94.20 www.haokan123.com
O1 - Hosts: 218.201.94.20 www.7255.com
O1 - Hosts: 218.201.94.20 220.181.34.241
O1 - Hosts: 218.201.94.20 www.my123.com
O2 - BHO: FiltrateWebObj Class - {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} - C:\Program Files\KV2006\KVBHO_1.dll
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - C:\Program Files\KV2006\KvShell.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - IE工具栏增项: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - C:\Program Files\KV2006\KvShell.dll
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [VTTimer] VTTimer.exe
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [KvMonXP] "C:\Program Files\KV2006\KVMonXP.kxp" /auto
O4 - 启动项HKLM\\Run: [Jiangmin KVFW] C:\Program Files\KVFW\KVFWMCL.exe -silent
O4 - 启动项HKLM\\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [KvXP] "C:\Program Files\KV2006\KvXP.kxp" /ScanBoot /ScanSys
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - D:\新建文件夹\Program\GetUrl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - D:\新建文件夹\Program\GetAllUrl.htm
O9 - 浏览器额外的按钮: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\新建文件夹\Thunder.exe
O9 - 浏览器额外的“工具”菜单项: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\新建文件夹\Thunder.exe
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} (Office Update Installation Engine) -
O16 - DPF: {EF6205C1-3F17-4829-BCB5-1336ED89E356} - http://online.jiangmin.com/KvDown.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9CAE7B60-1BB5-459E-BDC5-25C28E8DE762}: NameServer = 85.255.115.29 85.255.112.211
O17 - HKLM\System\CCS\Services\Tcpip\..\{C1063449-545E-4373-A017-D4E47A04251D}: NameServer = 85.255.115.29,85.255.112.211
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.29 85.255.112.211
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.29 85.255.112.211
O23 - NT 服务: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - NT 服务: KVSrvXP - Jiangmin Co. Ltd - C:\Program Files\KV2006\KVSrvXP.exe
O23 - NT 服务: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

最后编辑2006-11-17 12:47:16
分享到:
gototop
 

下载恶意软件清理助手
下载地址
http://www.tommsoft.com/Products.aspx?pid=2
gototop
 

参考http://forum.ikaka.com/topic.asp?board=28&artid=8188839
如果不行
下载 System Repair Engineer,
http://www.kztechs.com/sreng/sreng2.zip
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT