今天手动删除病毒后,瑞星的“电子邮件”监控就打不开了。以下
是扫描结果,请帮忙解决一下吧,谢谢!!
Logfile of HijackThis v1.99.1
Scan saved at 22:36:31, on 2006-9-12
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\rising\Rav\RavStub.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft
Shared\VS7Debug\mdm.exe
c:\windows\system\Internet Explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\Program Files\rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Firefox\firefox.exe
C:\DOCUME~1\AVANLE~1\LOCALS~1\Temp\Rar$EX00.292
\HijackThis.exe
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-
0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: Microsoft Solo Browser Helper
Object - {E3DB85B5
-C559-4894-B474-42E89FAA1EFD} -
C:\WINDOWS\system32\winmsd.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-
0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: 超级兔子上网精灵 - {43869BB3-22FD-4F15-
9B46-238106BA2F4E} - C:\Program Files\Super
Rabbit\MagicSet\haokanbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1
\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] ; C:\WINDOWS\system32
\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32
\hkcmd.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program
Files\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [WinampAgent] ; C:\Program
Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Super Rabbit SafeEdit] ; C:\Program
Files\Super Rabbit\MagicSet\SRFC.EXE /Load
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32
\ctfmon.exe
O4 - HKCU\..\Run: [msnnt] ; C:\WINDOWS\Updateb.exe
O6 - HKCU\Software\Policies\Microsoft\Internet
Explorer\Restrictions present
O8 - Extra context menu item: 使用网际快车下载 - C:\Program
Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 -
C:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: 相关站点 - {c95fe080-8f5d-11d2-a20b-
00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: 相关站点 - {c95fe080-8f5d-11d2-
a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file
missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-
0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-
11d4-8D29-0050BA6940E3} - C:\PROGRA~1
\FLASHGET\flashget.exe
O10 - Broken Internet access because of LSP provider
'c:\windows\system32\quartz32.dll' missing
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
(MSN Photo Upload Tool) -
http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
(WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/
en/x86/client/wuweb_site.cab?1111177642756
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
(MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/msnmessengersetupdownl
oader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{550E0336-7DD2
-4A48-85C8-01BD3CC420B2}: NameServer = 202.106.0.20
202.106.46.151
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-
8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll"
(file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32
\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-
95D7-94D524869DB5} - C:\WINDOWS\system32
\WPDShServiceObj.dll
O23 - Service: Macromedia Licensing Service - Unknown owner
- C:\Program Files\Common Files\Macromedia
Shared\Service\Macromedia Licensing.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-
nt.exe (file missing)
O23 - Service: Rising Proxy Service (RfwProxySrv) - Beijing
Rising Technology Co., Ltd. - c:\program
files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) -
Beijing Rising Technology Co., Ltd. - c:\program
files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center
(RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program
Files\rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising
Technology Co., Ltd. - C:\Program
Files\rising\Rav\Ravmond.exe
O23 - Service: Volume Shadddow Copyer (Service332242) -
Unknown owner - c:\windows\system\Internet Explorer.exe
O23 - Service: RSVPE (Smarytcer RSVPE) - Unknown owner -
C:\WINDOWS\system32\Server.bat