系统找恶意程序 哪位大侠帮找下

StartupList report, 2007-8-16, 下午 10:01:29
StartupList version: 1.52.2
Started from : D:\提示杀毒\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.5730.0011)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\瑞星\Rising\Rav\CCenter.exe
C:\WINDOWS\system32\svchost.exe
C:\瑞星\RISING\RAV\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\瑞星\RISING\RAV\RavStub.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\IME\Styler\Styler.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\11\D-Tools\daemon.exe
C:\WINDOWS\domino.EXE
C:\WINDOWS\VMSnap5.EXE
C:\瑞星\Rising\Rav\RavTask.exe
C:\Program Files\OCINS\idnsvr.exe
C:\瑞星\Rising\Rav\Ravmon.exe
C:\WINDOWS\Vista\Spctool\UberIcon\UberIcon Manager.exe
C:\WINDOWS\Vista\Spctool\Taskbar\Taskbar.exe
D:\14\UC talk\UCtalk.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\提示杀毒\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Administrator\「开始」菜单\程序\启动]
QQ游戏启动加速程序.lnk = C:\Program Files\11\QQGame\Accel.exe
新浪UC talk.lnk = D:\14\UC talk\UCtalk.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Styler = C:\WINDOWS\system32\IME\Styler\Styler.exe
Vistadrv = C:\WINDOWS\Vista\vip\VistaDrv\vsdrv.exe
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
RTHDCPL = RTHDCPL.EXE
SkyTel = SkyTel.EXE
Alcmtr = ALCMTR.EXE
DAEMON Tools-2052 = "C:\Program Files\11\D-Tools\daemon.exe"  -lang 2052
domino = C:\WINDOWS\domino.EXE
VMSnap5 = C:\WINDOWS\VMSnap5.EXE
BigDog305 = C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
RavTask = "C:\瑞星\Rising\Rav\RavTask.exe" -system
IdnSvr = C:\Program Files\OCINS\idnsvr.exe

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
bgswitch = C:\WINDOWS\system32\bgswitch.exe
UberIcon = "C:\WINDOWS\Vista\Spctool\UberIcon\UberIcon Manager.exe"
Taskbar = C:\WINDOWS\Vista\Spctool\Taskbar\Taskbar.exe

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\FlashGet\jccatch.dll - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7}
(no name) - C:\PROGRA~1\OCINS\ieaux.dll - {7605CC7C-00FD-4A5F-BAFD-828342DE6279}
(no name) - C:\Program Files\FlashGet\getflash.dll - {F156768E-81EF-470C-9057-481BA8380DBA}

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #5: C:\WINDOWS\system32\cdnns.dll (file MISSING)

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll

--------------------------------------------------
End of report, 4,861 bytes
Report generated in 0.016 seconds

Command line options:
  /verbose  - to add additional info on each section
  /complete - to include empty sections and unsuspicious data
  /full    - to include several rarely-important sections
  /force9x  - to include Win9x-only startups even if running on WinNT
  /forcent  - to include WinNT-only startups even if running on Win9x
  /forceall - to include all Win9x and WinNT startups, regardless of platform
  /history  - to list version history only


[用户系统信息]Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
最后编辑2007-08-15 22:33:34.060000000