|
|
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe-----修掉
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\services.exe-----修掉
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\KV2006\kvolself.exe
D:\查毒辅助软件\HijackThis v1.99 汉化版\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
F3 - REG:win.ini: run=C:\WINDOWS\services.exe-----修掉,这个病毒还挺牛B的,竟在win.ini处加载,结束services.exe进程,删掉windows下的services.exe,病毒无疑。
O2 - BHO: 超级兔子上网精灵 - {7369D35A-5B70-4A5B-B789-B25FE09B4AF3} - D:\魔法兔子\MagicSet\haokanbar.dll-----修掉,这是兔子的东东,没什么用
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\cnshook.dll-----修掉
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - C:\Program Files\KV2006\KvShell.dll (file missing)-----修掉
O3 - Toolbar: 超级兔子上网精灵 - {43869BB3-22FD-4F15-9B46-238106BA2F4E} - D:\魔法兔子\MagicSet\haokanbar.dll-----修掉
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32-----修掉
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k-----修掉
O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe-----修掉
O4 - HKLM\..\RunServices: [services] C:\WINDOWS\services.exe-----修掉
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgswitch] ; C:\WINDOWS\system32\壁纸自动换.exe
O4 - HKCU\..\Run: [KvXP] ; C:\Program Files\KV2006\KvXP.kxp /ScanBoot /ScanSys
O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe-----修掉
O4 - HKCU\..\RunServices: [services] C:\WINDOWS\services.exe-----修掉
O4 - Startup: ofdtwziiong.exe-----修掉,删掉该EXE,病毒无疑。
O4 - Startup: uangzinp.exe-----修掉,删掉该EXE,病毒无疑。
O4 - Startup: yuenang610.exe-----修掉,删掉该EXE,病毒无疑。
O4 - Global Startup: ongsikhx257.exe-----修掉,删掉该EXE,病毒无疑。
O4 - Global Startup: iangkegran691.exe-----修掉,删掉该EXE,病毒无疑。
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000-----修掉,没什么用,让系统清爽些
O9 - Extra button: Yahoo 3.5G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)-----修掉
O9 - Extra button: 名品折扣 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816 (file missing)-----修掉
O9 - Extra button: 雅虎助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)-----修掉
O9 - Extra button: 微软 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.microsoft.com/china/index.htm (file missing)-----修掉
O9 - Extra button: 雅虎WIDGET - {6354ABE6-05F1-49ed-B850-E423120EC338} - http://cn.widget.yahoo.com/index.htm?source=Cns (file missing)-----修掉
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomsg (file missing)-----修掉
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)-----修掉
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)-----修掉
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)-----修掉
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)-----修掉
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock.dll
O10 - Unknown file in Winsock LSP: c:\program files\kv2006\kvsock.dll
O11 - Options group: [!CNS] 中文上网-----修掉
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204-----修掉
O21 - SSODL: MediaCheck - {D1F73845-4BAB-4061-A46B-FCF7ECC19217} - C:\PROGRA~1\Kuree\MService.dll (file missing)-----修掉
[ 本帖最后由 6618 于 2006-11-4 11:14 PM 编辑 ] |
|