Logfile of HijackThis v1.99.1
Scan saved at 10:14:02, on 2006-1-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\spoolsv.exe
C:\Windows\Explorer.EXE
C:\KV2004\KVMonXP.kxp
C:\PROGRA~1\SkyNet\FireWall\pfw.exe
C:\Windows\system32\ctfmon.exe
D:\其他\DesktopSprite2\DesktopSprite.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\KV2004\KVSrvXP.exe
C:\KV2004\KVwsc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\wscntfy.exe
C:\Documents and Settings\gaoshengbo\My Documents\Huawei\PortalServer\PortalClient.exe
C:\Program Files\KC\KC2005.exe
D:\QQ\QQ.exe
D:\QQ\TIMPlatform.exe
D:\QQ\QQ.exe
D:\播放器\TTPlayer\TTPlayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\其他\日志扫描\HijackThis.exe
D:\其他\木马杀客\mmsk.exe
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - C:\KV2004\KvShell.dll
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - C:\KV2004\KvShell.dll
O4 - HKLM\..\Run: [KvMonXP] C:\KV2004\KVMonXP.kxp /auto
O4 - HKLM\..\Run: [SKYNET Personal FireWall] C:\PROGRA~1\SkyNet\FireWall\pfw.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\Windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [DesktopSprite] D:\其他\DesktopSprite2\DesktopSprite.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\微软办~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\QQ\SendMMS.htm
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: System Safety Monitor - C:\Windows\SYSTEM32\SSMWinlogonEx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: KVSrvXP - JiangMin Ltd. - C:\KV2004\KVSrvXP.exe
O23 - Service: KVWSC - Jiangmin Co - C:\KV2004\KVwsc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvsvc32.exe (file missing)
O23 - Service: Svchost (System_Svchost) - Unknown owner - C:\Windows\svchost.exe
一直清除不了此病毒:svchost.exe
在安全模式下删除了,重起后又重新生成!
要怎么才能彻底删除呀~~