|
|
日志如下:
Logfile of HijackThis v1.99.1
Scan saved at 20:34:48, on 2006-10-31
Platform: Windows XP SP2, v.2096 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2096)
Running processes:
C:\WINDOWS\System32\smss.exe:L:L:L:L
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\rundll32.exe-----修掉
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\software\迅雷\新建文件夹\Program\Thunder5.exe
C:\Documents and Settings\wufeng\桌面\HijackThis.exe
O1 - Hosts: 218.201.94.20 localhost
O1 - Hosts: 218.201.94.20 www.5566.net-----修掉
O1 - Hosts: 218.201.94.20 www.gjj.cc-----修掉
O1 - Hosts: 218.201.94.20 www.hao123.com-----修掉
O1 - Hosts: 218.201.94.20 www.hao222.com-----修掉
O1 - Hosts: 218.201.94.20 www.9991.com-----修掉
O1 - Hosts: 218.201.94.20 www.2345.com-----修掉
O1 - Hosts: 218.201.94.20 www.7939.com-----修掉
O1 - Hosts: 218.201.94.20 forum.ikaka.com-----修掉
O1 - Hosts: 218.201.94.20 bbs.360safe.com-----修掉
O1 - Hosts: 218.201.94.20 www.360safe.com-----修掉
O1 - Hosts: 218.201.94.20 www.piaoxue.com-----修掉
O1 - Hosts: 218.201.94.20 61.129.58.12-----修掉
O1 - Hosts: 218.201.94.20 forum.jiangmin.com-----修掉
O1 - Hosts: 218.201.94.20 luosoft.com-----修掉
O1 - Hosts: 218.201.94.20 post.baidu.com-----修掉
O1 - Hosts: 218.201.94.20 cn.zs.yahoo.com-----修掉
O1 - Hosts: 218.201.94.20 www.znmq.com-----修掉
O1 - Hosts: 218.201.94.20 auto.search.msn.com-----修掉
O1 - Hosts: 218.201.94.20 www.pcav.cn-----修掉
O1 - Hosts: 218.201.94.20 www.cnhx.com.cn-----修掉
O1 - Hosts: 218.201.94.20 btbaicai.com-----修掉
O1 - Hosts: 218.201.94.20 219.239.102.77-----修掉
O1 - Hosts: 218.201.94.20 hz.mop-hz.com-----修掉
O1 - Hosts: 218.201.94.20 www.jacai.com-----修掉
O1 - Hosts: 218.201.94.20 bbs.168safe.com-----修掉
O1 - Hosts: 218.201.94.20 ok.mop-hz.com-----修掉
O1 - Hosts: 218.201.94.20 s46.cnzz.com-----修掉
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\software\迅雷\新建文件夹\ComDlls\XunLeiBHO_002.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RemoteControl] "d:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [tq] C:\WINDOWS\system32\rundll32.exe 52vsp.dll Rundll32-----修掉,想办法把52vsp.dll 删掉,病毒无疑
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &使用迅雷下载 - D:\software\迅雷\新建文件夹\Program\GetUrl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - D:\software\迅雷\新建文件夹\Program\GetAllUrl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - D:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - D:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - D:\software\迅雷\新建文件夹\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷 - {0062C9BD-B349-40DE-91A0-755F37ACD559} - D:\software\迅雷\新建文件夹\Thunder.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{A22609B9-64B3-480C-BB11-FF1406942BEA}: NameServer = 202.96.128.166,202.96.128.86
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
[ 本帖最后由 6618 于 2006-11-1 01:49 AM 编辑 ] |
|