瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 高手救命!看看我的电脑,自己不会大家帮我!附日志!

1   1  /  1  页   跳转

高手救命!看看我的电脑,自己不会大家帮我!附日志!

高手救命!看看我的电脑,自己不会大家帮我!附日志!

我自己感觉好象中毒了!请大家指点!
Logfile of HijackThis v1.99.1
Scan saved at 20:14:11, on 2007-1-7
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\KV2004\KVMonXP.kxp
C:\WINDOWS\system32\ctfmon.exe
C:\KV2004\KVSrvXP.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\汉化版HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - _{33BBE430-0E42-4f12-B075-8D21ACB10DCB}? - (no file)
O2 - BHO: QQIEHelper - _{54EBD53A-9BC1-480B-966A-843A333CA162}? - (no file)
O2 - BHO: (no name) - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9}? - (no file)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4}? - (no file)
O3 - Toolbar: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD}? - (no file)
O3 - Toolbar: (no name) - {B5A34A93-D538-43A7-8371-864CB6148D12}? - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3}? - (no file)
O4 - HKLM\..\Run: [KvMonXP] C:\KV2004\KVMonXP.kxp /auto
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [kksetup] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\KKUninst.exe /f /d:d:\Program Files\Rising\KakaToolBar /s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118}? - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118}? - C:\Herosoft\HeroV8\STHSDVD.EXE
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b}? - C:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3}? - D:\PROGRA~1\FLASHGET\flashget.exe (file missing)
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3}? - D:\PROGRA~1\FLASHGET\flashget.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.tomatolei.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{0F1A3F1A-D4C9-4CC5-A5D2-4F9AF260A2FE}: NameServer = 202.102.128.68,202.102.134.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{A43F8E75-13CA-466D-B96C-1AC246FA368D}: NameServer = 202.102.154.3 202.102.152.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{0F1A3F1A-D4C9-4CC5-A5D2-4F9AF260A2FE}: NameServer = 202.102.128.68,202.102.134.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{0F1A3F1A-D4C9-4CC5-A5D2-4F9AF260A2FE}: NameServer = 202.102.128.68,202.102.134.68
O20 - AppInit_DLLs: APIHookDll.dll
O23 - Service: KVSrvXP - JiangMin Ltd. - C:\KV2004\KVSrvXP.exe

最后编辑2007-01-07 20:33:15
分享到:
gototop
 

运行Hijackthis,把下面的选中打上钩,修复
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - _{33BBE430-0E42-4f12-B075-8D21ACB10DCB}? - (no file)
O2 - BHO: QQIEHelper - _{54EBD53A-9BC1-480B-966A-843A333CA162}? - (no file)
O2 - BHO: (no name) - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9}? - (no file)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4}? - (no file)
O3 - Toolbar: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD}? - (no file)
O3 - Toolbar: (no name) - {B5A34A93-D538-43A7-8371-864CB6148D12}? - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3}? - (no file)
gototop
 

谢谢了,可是这几项修复后还有
O3 - Toolbar: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD}? - (no file)
O3 - Toolbar: (no name) - {B5A34A93-D538-43A7-8371-864CB6148D12}? - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3}? - (no file)
gototop
 

O4 - HKLM\..\RunOnce: [kksetup] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\KKUninst.exe /f /d:d:\Program Files\Rising\KakaToolBar /s

:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\到安全模式下清空
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT