1   1  /  1  页   跳转

【求助】高手求助

【求助】高手求助

Logfile of HijackThis v1.99.1
Scan saved at 20:47:10, on 2006-11-3
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\KV2006\KVSrvXP.exe
F:\Program Files\KV2006\kvwsc.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\KV2006\TrojDie.kxp
F:\WINDOWS\system32\conime.exe
F:\WINDOWS\SERVICES.EXE
F:\Program Files\KV2006\UIHost.exe
F:\WINDOWS\SMSS.EXE
F:\WINDOWS\SVCHOST.EXE
F:\WINDOWS\RUNDLL32.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Internet Explorer\EXPLORER.EXE
F:\WINDOWS\regedit.exe
F:\Documents and Settings\落魄小熊\桌面\IT168.com-4486hijackthis.exe

F3 - REG:win.ini: load=F:\WINDOWS\rundl132.exe
O2 - BHO: FiltrateWebObj Class - {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} - F:\Program Files\KV2006\KVBHO.dll
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - F:\Program Files\KV2006\KvShell.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - F:\Program Files\KV2006\KvShell.dll
O4 - HKLM\..\Run: [KvMonXP] "F:\Program Files\KV2006\KVMonXP.kxp" /auto
O4 - HKLM\..\Run: [MSConfig] F:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [wl] F:\WINDOWS\Download\svhost32.exe
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\CTFMON.EXE
O14 - IERESET.INF: START_PAGE_URL=about:blank
O20 - Winlogon Notify: igfxcui - F:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: KVSrvXP - Jiangmin Co. Ltd - F:\Program Files\KV2006\KVSrvXP.exe
O23 - Service: KVWSC - Jiangmin Co.Ltd - F:\Program Files\KV2006\kvwsc.exe

严重中毒,请高手帮忙解决!
帮我看看里面的日志...
最后编辑2006-11-03 21:18:02
分享到:
gototop
 

运行Hijackthis,把下面的选中打上钩,修复
F3 - REG:win.ini: load=F:\WINDOWS\rundl132.exe
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [wl] F:\WINDOWS\Download\svhost32.exe
重启按F8进入安全模式下修复
显示隐藏文件
删除:               
F:\WINDOWS\Download\svhost32.exe
F:\WINDOWS\SMSS.EXE
F:\WINDOWS\SVCHOST.EXE
F:\WINDOWS\RUNDLL32.exe
F:\WINDOWS\regedit.exe
gototop
 

修复
F3 - REG:win.ini: load=F:\WINDOWS\rundl132.exe
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [wl] F:\WINDOWS\Download\svhost32.exe
删除
F:\WINDOWS\Download\svhost32.exe
F:\WINDOWS\rundl132.exe
F:\WINDOWS\SERVICES.EXE
F:\WINDOWS\RUNDLL32.exe
F:\WINDOWS\SVCHOST.EXE

http://mopery.hits.io/MiscKiller.zip
下载专杀查杀..
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT