瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 大虾帮忙
魔界守护神 - 2006-8-4 18:12:00
有个叫cns的病毒删不掉


Logfile of HijackThis v1.99.1
Scan saved at 17:53:10, on 2006-8-4
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\KV2004\KVSrvXP.exe
C:\KV2004\KVwsc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\ylive.exe
F:\Downloads\hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - {D5C8C1E7-C553-4D8C-8F6B-0186AF86B042} - C:\WINDOWS\system32\Aobq.dll
O2 - BHO: (no name) - {04CA0296-8CA8-460E-A60F-0E29A846447D} - C:\WINDOWS\system32\Maioz.dll (file missing)
O2 - BHO: Tencent Browser Helper - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\Adplus\SSAddr.dll (file missing)
O2 - BHO: (no name) - {0CB50251-30E8-4811-8F55-2E514595A16A} - C:\WINDOWS\system32\Xswus.dll
O2 - BHO: (no name) - {0EB855DC-54CB-4BC2-B709-3FEAB61BE48A} - C:\WINDOWS\system32\Hhcigo.dll
O2 - BHO: (no name) - {150D3D9B-AFB8-4A4A-92E2-4BE115D0380D} - C:\WINDOWS\system32\Wzgbxu.dll
O2 - BHO: (no name) - {256091A0-95CB-4C91-813A-5885A7BB56EC} - C:\WINDOWS\system32\Rueca.dll
O2 - BHO: Yahoo!Photo - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll
O2 - BHO: (no name) - {379EA8C7-A17D-4F01-BE53-C8DB30E18EFB} - C:\WINDOWS\system32\Usas.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yangling.dll
O2 - BHO: (no name) - {3AB0A42D-378A-48F2-B7AF-7C41B0B8A9A4} - C:\WINDOWS\system32\Vckdww.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O2 - BHO: (no name) - {4BC519A2-DFDA-46A4-9A25-56CEB3F81B91} - C:\WINDOWS\system32\Dvlmu.dll
O2 - BHO: (no name) - {5241FF89-410A-4080-874F-42DB4A160157} - C:\WINDOWS\system32\Quet.dll (file missing)
O2 - BHO: (no name) - {53AC3D6F-1E93-4277-9D86-8331EBF20C22} - C:\WINDOWS\system32\Fmpnb.dll
O2 - BHO: (no name) - {54496238-53DD-416F-A96B-FAC0DCC7521C} - C:\WINDOWS\system32\Ndmb.dll
O2 - BHO: (no name) - {5EFDCCF4-3DA8-4186-BEA7-E6C530FD3CCF} - C:\WINDOWS\system32\Xlak.dll
O2 - BHO: (no name) - {6103F1E3-96CC-4142-B8BA-ED65202AD99D} - C:\WINDOWS\system32\Twlh.dll (file missing)
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL
O2 - BHO: (no name) - {634A711B-6726-4D8D-996F-8158141D34B8} - C:\WINDOWS\system32\Migyq.dll
O2 - BHO: (no name) - {64643826-02E1-40E6-9283-4D699C1B1832} - C:\WINDOWS\system32\Oxfe.dll
O2 - BHO: (no name) - {669751ED-D558-49AE-B01A-3B374CC7910E} - C:\WINDOWS\system32\ssup.dll
O2 - BHO: (no name) - {66B6EA43-0CA6-41FC-B849-8D674F1ED817} - C:\WINDOWS\system32\Gsjmwe.dll (file missing)
O2 - BHO: (no name) - {79FD3A97-6744-4BCA-AC97-9CDF2988A2F5} - C:\WINDOWS\system32\Dfwt.dll
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - C:\KV2004\KvShell.dll
O2 - BHO: (no name) - {869C05B8-6DDB-4EE4-AFBB-EC2724036493} - C:\WINDOWS\system32\Ngcs.dll (file missing)
O2 - BHO: (no name) - {942A2812-E625-4790-86FB-9DD9AD03EA9E} - C:\WINDOWS\system32\Zxvz.dll
O2 - BHO: (no name) - {A2E544F5-3B8A-44A0-A416-765C1BF35D98} - C:\WINDOWS\system32\Xzuwu.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - C:\PROGRA~1\KuGoo2\KUGOO3~1.OCX
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {B0AEC2AD-7003-491D-AC74-ECF562A9D253} - C:\WINDOWS\system32\Wwfs.dll
O2 - BHO: (no name) - {B61B6832-6699-42C8-BA6E-58B3AD3CCFDC} - C:\WINDOWS\system32\Xztf.dll
O2 - BHO: (no name) - {B7A409D3-5B4E-4479-B4D4-A129A32721E8} - C:\WINDOWS\system32\Hwdidv.dll
O2 - BHO: (no name) - {BA8E64D9-0B6C-46A4-BABE-BAE12716B970} - C:\WINDOWS\system32\Hmfw.dll
O2 - BHO: (no name) - {D5C8C1E7-C553-4D8C-8F6B-0186AF86B042} - C:\WINDOWS\system32\Aobq.dll
O2 - BHO: (no name) - {D9C1412B-87E2-4AE5-BB72-E457C5E881E3} - C:\WINDOWS\system32\Txcze.dll
O2 - BHO: (no name) - {E1165845-6293-4134-A79C-72198F8AF082} - C:\WINDOWS\system32\Htaems.dll
O2 - BHO: (no name) - {E497DE12-F60A-489D-AE9C-C8A6694570BF} - C:\WINDOWS\system32\Rnqwwt.dll
O2 - BHO: (no name) - {ED56FAB8-A55B-4D5A-8B47-F5549D0A0C45} - C:\WINDOWS\system32\Rjaamu.dll (file missing)
O2 - BHO: (no name) - {F5DEEF69-E54C-422C-AEFD-3F78577214ED} - C:\WINDOWS\system32\Idgzax.dll
O2 - BHO: (no name) - {FB8B5398-6280-4484-A41E-F1B2AB3CAF36} - C:\WINDOWS\system32\Mmnko.dll
O2 - BHO: (no name) - {FBA7DFAC-0468-490B-8EFE-E2AAEB6E8046} - C:\WINDOWS\system32\Ocqt.dll
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - C:\KV2004\KvShell.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [KvMonXP] C:\KV2004\KVMonXP.kxp /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] ; "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://D:\OFFIC2~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 百度-搜索MP3 - res://C:\WINDOWS\DOWNLO~1\BaiduBar.dll/BAIDUMP3.HTM
O8 - Extra context menu item: 百度-搜索图片 - res://C:\WINDOWS\DOWNLO~1\BaiduBar.dll/BAIDUIMG.HTM
O8 - Extra context menu item: 百度-搜索新闻 - res://C:\WINDOWS\DOWNLO~1\BaiduBar.dll/BAIDUNEWS.HTM
O8 - Extra context menu item: 百度-搜索歌词 - res://C:\WINDOWS\DOWNLO~1\BaiduBar.dll/BAIDULYRIC.HTM
O8 - Extra context menu item: 百度-搜索网页 - res://C:\WINDOWS\DOWNLO~1\BaiduBar.dll/BAIDUSEARCH.HTM
O8 - Extra context menu item: 百度-搜索贴吧 - res://C:\WINDOWS\DOWNLO~1\BaiduBar.dll/BAIDUPOST.HTM
O10 - Unknown file in Winsock LSP: c:\windows\system32\kvwspxp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\kvwspxp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\kvwspxp.dll
O11 - Options group: [TBH]  搜搜地址栏搜索
O16 - DPF: {F138084D-84D7-48CD-BEA8-04772457516E} (VqqSpeedDlProxy Class) - http://218.85.138.27/vqqsdl1009.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0067868-036C-4DAB-8DE3-D28EAF32B86E}: NameServer = 219.149.194.55 219.146.0.130
O21 - SSODL: DLMon - {590498A3-4131-4D8F-BA4B-36791A0803B1} - C:\WINDOWS\system32\DLMain.dll (file missing)
O23 - Service: KVSrvXP - JiangMin Ltd. - C:\KV2004\KVSrvXP.exe
O23 - Service: KVWSC - Jiangmin Co - C:\KV2004\KVwsc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

1
查看完整版本: 大虾帮忙