这是我的扫描结果,请高手帮忙!
Logfile of HijackThis v1.99.1
Scan saved at 9:02:15, on 05-11-7
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
F:\Recycled\RAVTIMER.EXE
G:\KINGSOFT\HijackThis.exe
O2 - BHO: DownloadValue Class - {616D4040-5712-4F0F-BCF1-5C6420A99E14} - C:\WINNT\system32\winhtp.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: 全能助手广告拦截专家 - {ED51E9A3-16C5-4236-99E0-9F093B021433} - C:\Program Files\TweakAssist\AssistIEBar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SKYNET Personal FireWall] C:\PROGRA~1\SKYNET\FIREWALL\pfw.exe
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O8 - Extra context menu item: 使用影音传送带下载 - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音传送带下载全部链接 - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O16 - DPF: {8C9D5912-EED6-4488-B778-2D74EF9B859D} (CHtmlIp3View
Object) - http://www.drcnet.com.cn/fish_dll/Ip3HtmlView.dll
O16 - DPF: {E75D308D-B903-11D4-BD46-0050BA6E0CA5} (BtecKBase Class) - http://www.drcnet.com.cn/fish_dll/bteckbasec.dll
O16 - DPF: {ECACF05B-8E62-4FAE-89F0-806D09DEDA54} (RunAppFormX Control) - http://oa.zjjmw.gov.cn/RunAppFormProj1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3FBF5E75-FD38-4C68-9CED-365E2BD82B31}: NameServer = 211.90.216.129,211.90.224.100
O17 - HKLM\System\CS1\Services\Tcpip\..\{3FBF5E75-FD38-4C68-9CED-365E2BD82B31}: NameServer = 211.90.216.129,211.90.224.100
O17 - HKLM\System\CS2\Services\Tcpip\..\{3FBF5E75-FD38-4C68-9CED-365E2BD82B31}: NameServer = 211.90.216.129,211.90.224.100
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINNT\system32\mbprot.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
其中开机的进程:F:\Recycled\RAVTIMER.EXE肯定是带毒文件,但无法在此目录中找到文件,请教高手该怎么办。在注册表中也无法找到这个F:\Recycled\RAVTIMER.EXE