我的HIJACKTHIS日志
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\rising\Rav\RavStub.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\rising\rfw\Rfw.EXE
C:\Program Files\rising\Rav\RavTask.exe
C:\Program Files\rising\Rav\Ravmon.exe
C:\WINDOWS\System32\ctfmon.exe
D:\ɱľÂí\¾«Áé\ɱľÂí\System Mechanic Pro\StartupGuard.exe
C:\WINDOWS\NOTEPAD.EXE
C:\Documents and Settings\aa\×ÀÃæ\Game Of The HenFinD\HijackThis.exe
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - D:\MYMUSI~1\kugoo\KuGoo\KUGOO3~1.OCX
O2 - BHO: HB
Object Class - {AE22AFE5-1EF4-4D25-9E23-D2825FB17DA1} - C:\WINDOWS\DOWNLO~1\hbhelper.dll
O4 - HKLM\..\Run: [rfw] C:\Program Files\rising\rfw\Rfw.EXE
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RichMedia] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\DOWNLO~1\hbhelper.dll",WaitWindows
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [System Mechanic Æô¶¯ÎÀÊ¿] "D:\ɱľÂí\¾«Áé\ɱľÂí\System Mechanic Pro\StartupGuard.exe"
O4 - HKCU\..\Run: [iolo ʵÓù¤¾ßÀ¸] "D:\ɱľÂí\¾«Áé\ɱľÂí\System Mechanic Pro\SMUtilityBar.exe"
O8 - Extra context menu item: &ʹÓÃѸÀ×ÏÂÔØ - D:\b\º«¹úKRO1207Õýʽ¶Ë\Thunder\geturl.htm
O8 - Extra context menu item: &ʹÓÃѸÀ×ÏÂÔØÈ«²¿Á´½Ó - D:\b\º«¹úKRO1207Õýʽ¶Ë\Thunder\getAllurl.htm
O8 - Extra context menu item: ʹÓÃKuGoo3ÏÂÔØ(&K) - D:\MYMUSI~1\kugoo\KUGOO\KuGoo3DownX.htm
O8 - Extra context menu item: Ìí¼Óµ½QQ×Ô¶¨ÒåÃæ°å - D:\QQ\AddPanel.htm
O8 - Extra context menu item: Ìí¼Óµ½QQ±íÇé - D:\QQ\AddEmotion.htm
O8 - Extra context menu item: ÓÃQQ²ÊÐÅ·¢Ë͸ÃͼƬ - D:\QQ\SendMMS.htm
O9 - Extra button: ºÆ·½¶Ôսƽ̨ - {0A155D3C-68E2-4215-A47A-E800A446447A} - D:\CGA\ºÆ·½¶Ôսƽ̨\GameClient.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\hbmter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hbmter.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/
O17 - HKLM\System\CCS\Services\Tcpip\..\{B19564BE-6D11-455B-A88E-98B24460B43F}: NameServer = 202.96.128.166 202.96.128.86
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: PsShutdown (PsShutdownSvc) - Unknown owner - C:\WINDOWS\System32\PSSDNSVC.EXE
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\Ravmond.exe