Logfile of HijackThis v1.99.1
Scan saved at 22:00:25, on 2006-9-25
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\Svchost.exe
C:\WINNT\System32\svchost.exe
C:\win32app\nsr\bin\nsrexecd.exe
C:\WINNT\System32\nvsvc32.exe
D:\orant\bin\OWASTsvr.exe
C:\win32app\nsr\bin\portmap.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
c:\winnt\system32\wbem\smss.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\木马杀客\mmsk.exe
C:\Program Files\Common Files\UPDATE2\Update.exe
C:\WINNT\system32\internat.exe
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\Program Files\Tencent\TT\TTraveler.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\WINNT\explorer.exe
C:\Documents and Settings\Administrator\桌面\hijackthis_16091\HijackThis.exe
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\WINNT\system32\adocbc.exe
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5066.dll
O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386}? - (no file)
O2 - BHO: SYM - {36BF6929-DCBC-4CCD-A620-C5E3BBA77B95} - C:\WINNT\system32\usersrd.dll
O2 - BHO: (no name) - {36BF6929-DCBC-4CCD-A620-C5E3BBA77B95}? - (no file)
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: (no name) - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}? - (no file)
O2 - BHO: Spoolsv Class - {9C363D55-07D7-433d-A13E-D9C105202F6F} - C:\WINNT\system32\drivers\spoolsv.dll
O2 - BHO: (no name) - {9C363D55-07D7-433d-A13E-D9C105202F6F}? - (no file)
O2 - BHO: Class - {EB21FA8C-3CEB-402C-A113-5F173BE954ED} - C:\WINNT\system32\evttdoe.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINNT\system32\KakaTool.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [mmsk] C:\Program Files\木马杀客\mmsk.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE2\Update.exe
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 访问通用网址 - C:\Program Files\CNNIC\Cdn\cnnic.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra button: (no name) - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}? - (no file)
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\gdiplus32.dll
O11 - Options group: [CDNCLIENT] 中文上网
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} (Qzone Media Tools) - http://qz-photo.qq.com/qzone3/QzoneMediaTools.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{61C9348F-A532-48E0-94D8-2B00E00315D7}: NameServer = 192.168.0.250
O17 - HKLM\System\CS1\Services\Tcpip\..\{61C9348F-A532-48E0-94D8-2B00E00315D7}: NameServer = 192.168.0.250
O17 - HKLM\System\CS2\Services\Tcpip\..\{61C9348F-A532-48E0-94D8-2B00E00315D7}: NameServer = 192.168.0.250
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Gray_Pigeon_Server1.23 (GrayPigeonServer1.23) - Unknown owner - C:\WINNT\G_Server1.23.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: NetWorker Backup and Recover Server (nsrd) - Unknown owner - C:\win32app\nsr\bin\nsrd (file missing)
O23 - Service: NetWorker Remote Exec Service (nsrexecd) - Unknown owner - C:\win32app\nsr\bin\nsrexecd (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: OracleClientCache80 - Unknown owner - D:\orant\BIN\ONRSD80.EXE
O23 - Service: OracleWebAssistant - Oracle Corporation - D:\orant\bin\OWASTsvr.exe
O23 - Service: Storage Management Portmapper (portmap) - Unknown owner - C:\win32app\nsr\bin\portmap (file missing)
我试过在安全模式下杀!但是没有效果,也用卡巴杀但是无法访问,瑞新早就瘫痪了!木马杀客在安全模式下显示杀掉了,但是正常启动后卡巴仍然报毒!所以求救!