HijackThis_815汉化版扫描日志 V1.99.1
保存于 10:20:21, 日期 2005-11-18
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\Ati2evxx.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\System32\GEARSec.exe
G:\WINDOWS\system32\inetsrv\inetinfo.exe
G:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
G:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
G:\PROGRAM FILES\RISING\RAV\Ravmond.exe
G:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
G:\PROGRAM FILES\RISING\RAV\RavStub.exe
G:\Program Files\UPHClean\uphclean.exe
G:\WINDOWS\system32\Ati2evxx.exe
G:\WINDOWS\system32\dllhost.exe
G:\WINDOWS\Explorer.EXE
G:\WINDOWS\system32\inetsrv\DavCData.exe
G:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
G:\Program Files\AlfaClock\AlfaClock.exe
G:\Program Files\RAM Idle\RAM_XP.exe
G:\PROGRA~1\RISING\RAV\RAVMON.EXE
G:\PROGRA~1\SkyNet\FireWall\PFW.EXE
G:\WINDOWS\system32\CSPContext.exe
G:\Program Files\Foxmail\Foxmail.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\hexin\sslproxy\SSLCnt.exe
G:\Program Files\Maxthon\Maxthon.exe
G:\Program Files\EPSON Print CD\EPSONCD.exe
G:\Program Files\Tencent\TMDlls\TM.exe
G:\Program Files\Tencent\TIMPlatform.exe
G:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10MT2.EXE
G:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10RN2.EXE
G:\Program Files\Internet Explorer\IEXPLORE.EXE
G:\Program Files\DuDu\DddClient\dudupros.exe
G:\Program Files\Internet Explorer\iexplore.exe
G:\Documents and Settings\LYM\桌面\4842302005817230232\HijackThis1991zww.exe
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - G:\WINDOWS\system32\xunleibho_v5.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35980F6E-A137-4E50-953D-813BB8556899} - (no file)
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - G:\Program Files\Tencent\QQIEHelper.dll
O2 - BHO: DDDMon Class - {6BDE1669-B490-48E3-B668-456314F2D6C3} - G:\Program Files\DuDu\DddClient\dddiemon.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - G:\Program Files\JetCar1.65\jccatch.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - G:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - G:\PROGRA~1\JetCar1.65\fgiebar.dll
O4 - 启动项HKLM\\Run: [RavTimer] G:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [100% Clock] G:\Program Files\AlfaClock\AlfaClock.exe
O4 - 启动项HKLM\\Run: [RAM Idle Professional] G:\Program Files\RAM Idle\RAM_XP.exe
O4 - 启动项HKLM\\Run: [RavMon] G:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [SKYNET Personal FireWall] G:\PROGRA~1\SkyNet\FireWall\PFW.EXE
O4 - 启动项HKLM\\Run: [CSPContext] G:\WINDOWS\system32\CSPContext.exe
O4 - 启动项HKLM\\Run: [Update] G:\WINDOWS\system32\Update.exe
O4 - 启动项HKLM\\Run: [NeroFilterCheck] G:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [Foxmail] "G:\Program Files\Foxmail\Foxmail.exe" -min
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Maxthon.lnk = G:\Program Files\Maxthon\Maxthon.exe
O4 - Global Startup: 核新SSL通讯安全代理.lnk = G:\Program Files\hexin\sslproxy\SSLCnt.exe
O8 - IE右键菜单中的新增项目: &使用DuDu 加速器下载 - res://G:\Program Files\DuDu\DddClient\dddmext.dll/202
O8 - IE右键菜单中的新增项目: &使用暴风下载器下载 - G:\Program Files\Ringz Studio\Storm Downloader\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - G:\Program Files\Sandai Technologies Inc\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - G:\Program Files\Sandai Technologies Inc\Thunder\getAllurl.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - G:\Program Files\JetCar1.65\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - G:\Program Files\JetCar1.65\jc_all.htm
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Excel(&x) - res://G:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 导出到 Microsoft Office Excel(&X) - res://G:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - IE右键菜单中的新增项目: 查看 Exif 信息(&V) - res://G:\Program Files\Exif Show\ExShow.dll/EXSHOW.HTML
O8 - IE右键菜单中的新增项目: 豪杰超级解霸V8实时播放 - G:\Herosoft\HeroV8\MPURLGET.HTM
O9 - 浏览器额外的按钮: 网址大全 - {1FBA04EE-3024-11D2-8F1F-0000F87ABD18} - http://www.coc.cc (file missing)
O9 - 浏览器额外的按钮: 中文域名 - {35980F6E-A137-4E50-953D-813BB8556899} - G:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: 中文域名 - {35980F6E-A137-4E50-953D-813BB8556899} - G:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的按钮: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - G:\Herosoft\HeroV8\STHSDVD.EXE
O9 - 浏览器额外的“工具”菜单项: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - G:\Herosoft\HeroV8\STHSDVD.EXE
O9 - 浏览器额外的按钮: 下载管理 - {3DB9F45E-AA74-4373-A466-C18A9F1C500D} - G:\Program Files\DuDu\DddClient\DuDuAcc.exe
O9 - 浏览器额外的“工具”菜单项: 下载管理 - {3DB9F45E-AA74-4373-A466-C18A9F1C500D} - G:\Program Files\DuDu\DddClient\DuDuAcc.exe
O9 - 浏览器额外的按钮: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - 浏览器额外的按钮: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - G:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的“工具”菜单项: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - G:\WINDOWS\system32\shdocvw.dll
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - G:\Program Files\JetCar1.65\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - G:\Program Files\JetCar1.65\flashget.exe
O9 - 浏览器额外的按钮: 易趣购物 - {DE60714F-AC19-427e-861A-FD60ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=1 (file missing)
O9 - 浏览器额外的“工具”菜单项: 易趣购物 - {DE60714F-AC19-427e-861A-FD60ABDF119A} - http://click2.ad4all.net/url2/urlmanage/url.asp?id=1 (file missing)
O9 - 浏览器额外的按钮: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - G:\Program Files\Tencent\QQIEHelper.dll
O9 - 浏览器额外的“工具”菜单项: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - G:\Program Files\Tencent\QQIEHelper.dll
O9 - 浏览器额外的按钮: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O12 - IE插件,支持文件类型.mp3: G:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{4653FB90-089C-41E1-A2AE-0A0598DBDB58}: NameServer = 202.103.44.5,202.103.0.117
O18 - 列举现有的协议: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - G:\WINDOWS\system32\mbprot.dll
O23 - NT 服务: Adobe LM Service - Adobe Systems - G:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - NT 服务: Ati HotKey Poller - Unknown owner - G:\WINDOWS\system32\Ati2evxx.exe
O23 - NT 服务: ATI Smart - Unknown owner - G:\WINDOWS\system32\ati2sgag.exe
O23 - NT 服务: GEARSecurity - GEAR Software - G:\WINDOWS\System32\GEARSec.exe
O23 - NT 服务: Macromedia Licensing Service - Unknown owner - G:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - NT 服务: Norton Ghost - Symantec Corporation - G:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
O23 - NT 服务: PDEngine - Raxco Software, Inc. - G:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - NT 服务: PDScheduler (PDSched) - Raxco Software, Inc. - G:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - G:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - G:\PROGRAM FILES\RISING\RAV\Ravmond.exe
O23 - NT 服务: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - G:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - NT 服务: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - G:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
麻烦大侠!可否与“智能狂拼”有关?今天忽然弹出一个“狂拼”广告!