谢谢你啊 !我也刚看了下别人的帖 但是...还是不太懂~~~
我扫了个 麻烦你帮我再看看~
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 20:41:06, 日期 2005-10-13
操作系统: Windows 2000 SP4 (WinNT 5.00.2195)
浏览器: Internet Explorer v6.00 (6.00.2600.0000)
当前运行的进程:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\qq\QQ.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Chen1\桌面\2535952005811174944\HijackThis1991zww.exe
O1 - Hosts: 61.152.188.191 www.dy885.com
O1 - Hosts: 61.152.188.191 dy885.com
O1 - Hosts: 61.152.188.191 www.kk3838.com
O1 - Hosts: 61.152.188.191 kk3838.com
O1 - Hosts: 61.152.188.191 www.xq8888.com
O1 - Hosts: 61.152.188.191 xq8888.com
O1 - Hosts: 61.152.188.191 www.evercare.com.cn
O1 - Hosts: 61.152.188.191 evercare.com.cn
O1 - Hosts: 61.152.188.191 www.ttjj.com
O1 - Hosts: 61.152.188.191 ttjj.com
O1 - Hosts: 61.152.188.191 www.qwmm.com
O1 - Hosts: 61.152.188.191 qwmm.com
O1 - Hosts: 61.152.188.191 www.yesky.com
O1 - Hosts: 61.152.188.191 yesky.com
O1 - Hosts: 61.152.188.191 dir.sina.com.cn
O1 - Hosts: 61.152.188.191 www.chinasafe.com
O1 - Hosts: 61.152.188.191 chinasafe.com
O1 - Hosts: 61.152.188.191 www.365pic.net
O1 - Hosts: 61.152.188.191 365pic.net
O1 - Hosts: 61.152.188.191 tu.wangyou.com
O1 - Hosts: 61.152.188.191 www.metuo.com
O1 - Hosts: 61.152.188.191 metuo.com
O1 - Hosts: 61.152.188.191 www.asiacool.com
O1 - Hosts: 61.152.188.191 www.qq.com
O1 - Hosts: 61.152.188.191 qq.com
O1 - Hosts: 61.152.188.191 sohu.com
O1 - Hosts: 61.152.188.191 www.sohu.com
O1 - Hosts: 61.152.188.191 www.qq163.com
O1 - Hosts: 61.152.188.191 qq163.com
O1 - Hosts: 61.152.188.191 hao123.com
O1 - Hosts: 61.152.188.191 www.265.com
O1 - Hosts: 61.152.188.191 265.com
O1 - Hosts: 61.152.188.191 669.com
O1 - Hosts: 61.152.188.191 wwww.wo888.com
O1 - Hosts: 61.152.188.191 wo888.com
O1 - Hosts: 61.152.188.191 www.v10000.com
O1 - Hosts: 61.152.188.191 v10000.com
O1 - Hosts: 61.152.188.191 www.huise.com
O1 - Hosts: 61.152.188.191 huise.com
O1 - Hosts: 61.152.188.191 www.06056.com
O1 - Hosts: 61.152.188.191 06056.com
O1 - Hosts: 61.152.188.191 www.07007.com
O1 - Hosts: 61.152.188.191 07007.com
O1 - Hosts: 61.152.188.191 tv.wo98.com
O1 - Hosts: 61.152.188.191 www.leletv.com
O1 - Hosts: 61.152.188.191 leletv.com
O1 - Hosts: 61.152.188.191 www.3yinyue.com
O1 - Hosts: 61.152.188.191 3yinyue.com
O1 - Hosts: 61.152.188.191 www.8848qq.com
O1 - Hosts: 61.152.188.191 8848qq.com
O1 - Hosts: 61.152.188.191 www.56909.com
O1 - Hosts: 61.152.188.191 56909.com
O1 - Hosts: 61.152.188.191 mp3.baidu.com
O1 - Hosts: 61.152.188.191 18dy.com
O1 - Hosts: 61.152.188.191 www.18dy.com
O1 - Hosts: 61.152.188.191 zhao117.com
O1 - Hosts: 61.152.188.191 www.zhao117.com
O1 - Hosts: 61.152.188.191 3.35935.com
O1 - Hosts: 61.152.188.191 www.dhmp3.com
O1 - Hosts: 61.152.188.191 dhmp3.com
O1 - Hosts: 61.152.188.191 mtv520.com
O1 - Hosts: 61.152.188.191 www.mtv520.com
O1 - Hosts: 61.152.188.191 www.st020.com
O1 - Hosts: 61.152.188.191 st020.com
O1 - Hosts: 61.152.188.191 www.tt90.com
O1 - Hosts: 61.152.188.191 ky265.com
O1 - Hosts: 61.152.188.191 www.ky265.com
O1 - Hosts: 61.152.188.191 dy265.com
O1 - Hosts: 61.152.188.191 www.dy265.com
O1 - Hosts: 61.152.188.191 ip138.com
O1 - Hosts: 61.152.188.191 www.hnnn.com
O1 - Hosts: 61.152.188.191 hnnn.com
O1 - Hosts: 61.152.188.191 www.hnnn.net
O1 - Hosts: 61.152.188.191 hnnn.net
O1 - Hosts: 61.152.188.191 hnnn.com.cn
O1 - Hosts: 61.152.188.191 www.llmtv.com
O1 - Hosts: 61.152.188.191 llmtv.com
O1 - Hosts: 61.152.188.191 www.mtv591.com
O1 - Hosts: 61.152.188.191 mtv591.com
O1 - Hosts: 61.152.188.191 mop.com
O1 - Hosts: 61.152.188.191 www.mop.com
O1 - Hosts: 61.152.188.191 www.21cn.com
O1 - Hosts: 61.152.188.191 21cn.com
O1 - Hosts: 61.152.188.191 free.21cn.com
O1 - Hosts: 61.152.188.191 msnbbs.mop.com
O1 - Hosts: 61.152.188.191 566166.com
O1 - Hosts: 61.152.188.191 www.566166.com
O1 - Hosts: 61.152.188.191 1106.net
O1 - Hosts: 61.152.188.191 www.1106.net
O1 - Hosts: 61.152.188.191 zs998.com
O1 - Hosts: 61.152.188.191 www.zs998.com
O1 - Hosts: 61.152.188.191 88263.com
O1 - Hosts: 61.152.188.191 www.88263.com
O1 - Hosts: 61.152.188.191 bj68.com
O1 - Hosts: 61.152.188.191 www.bj68.com
O1 - Hosts: 61.152.188.191 lhc315.com
O1 - Hosts: 61.152.188.191 www.lhc315.com
O1 - Hosts: 61.152.188.191 3626.net
O1 - Hosts: 61.152.188.191 www.3626.net
O1 - Hosts: 61.152.188.191 8678.org
O1 - Hosts: 61.152.188.191 www.8678.org61.152.188.191 yy7.net
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINNT\system32\xunleibho_v5.dll (file missing)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: (no name) - {D032570A-5F63-4812-A094-87D007C23012} - C:\WINNT\system32\IEBHO.dll
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll (file missing)
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - IE工具栏增项: 网络钓鱼克星 - {954F618B-0DEC-4D1A-9317-E0FC96F87865} - C:\WINNT\system32\MainIEBand.dll (file missing)
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [nwiz] nwiz.exe /install
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - 启动项HKLM\\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - 启动项HKLM\\Run: [!xSpeednet] C:\Documents and Settings\Chen1\桌面\加速器\时空游侠网络版1.5版\时空游侠网络版.exe reg
O4 - 启动项HKLM\\Run: [NetUpdate] C:\WINNT\system32\NetUpdate.exe
O4 - 启动项HKLM\\Run: [NTdhcp] C:\WINNT\system32\NTdhcp.exe
O4 - 启动项HKLM\\Run: [internet.exe] C:/system.hta
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 添加到QQ自定义面板 - D:\qq\AddPanel.htm
O8 - IE右键菜单中的新增项目: 添加到QQ表情 - D:\qq\AddEmotion.htm
O8 - IE右键菜单中的新增项目: 用QQ彩信发送该图片 - D:\qq\SendMMS.htm
O9 - 浏览器额外的按钮: 浩方对战平台 - {0A155D3C-68E2-4215-A47A-E800A446447A} - E:\天诛\新建文件夹\浩方对战平台\GameClient.exe (file missing)
O9 - 浏览器额外的按钮: 解霸 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\HEROSOFT\Hero3000\MPLAYER.EXE
O9 - 浏览器额外的“工具”菜单项: 超级解霸 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\HEROSOFT\Hero3000\MPLAYER.EXE
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - 浏览器额外的按钮: 百万图库 - {6713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/p (file missing) (HKCU)
O9 - 浏览器额外的按钮: 铃声图片下载 - {7713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/sms/index.htm (file missing) (HKCU)
O16 - DPF: {2BFAA61B-5C83-4865-8281-D8BDBF863061} (PGEdit Class) - https://www.gnetpg.com/PG_ATL.cab
O18 - 列举现有的协议: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINNT\system32\mbprot.dll
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: Logical Windows Manager System (LWinManager) - Unknown owner - C:\WINNT\system\ns.exe
O23 - NT 服务: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
这个是图
附件:
59793720051013204543.jpg