Logfile of HijackThis v1.99.1
Scan saved at 0:01:03, on 2006-2-7
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MSMPREXE.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
D:\杀毒软件\RISING\RAV\CCENTER.EXE
D:\杀毒软件\RISING\RAV\RAVMOND.EXE
D:\杀毒软件\RISING\RAV\RAVMON.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
D:\!SUNV\DFVCD\DFVCDROM.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
D:\杀毒软件\RISING\RAV\RAVTASK.EXE
C:\LXHOME\LXREMOTE\KEY_REMOTE.EXE
C:\LXHOME\LXREMOTE\USBCTRL.EXE
C:\LXHOME\LXQUICK\LXQUICK.EXE
D:\WINDVD\COMMON\BIN\WINCINEMAMGR.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\WINDOWS\MSAGENT\AGENTSVR.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\LXHOME\LXREMOTE\USBKBCNT.EXE
C:\LXHOME\LXREMOTE\IRDARCVR.EXE
C:\LXHOME\LXREMOTE\TGEUSBKB.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\北京通信\宽带E线—ADSL\APP\ENTERNET.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
D:\杀毒软件\RISING\RAV\RAV.EXE
D:\杀毒软件\RISING\RAV\RSAGENT.EXE
D:\杀毒软件\RISING\RAV\SCANBD.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL (file missing)
O2 - BHO: (no name) - {9FC30A58-40B1-406D-ADEF-F4BD3A95755B} - C:\WINDOWS\SYSTEM\F20DEK1.dll
O2 - BHO: (no name) - {3D898C55-74CC-4B7C-B5F1-45913F368388} - C:\WINDOWS\SYSTEM\COMM32.DLL
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - C:\PROGRA~1\KUGOO3\KUGOO3~1.OCX
O3 - Toolbar: @msdxmLC.dll,-1@0,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: 东方卫士 - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EF} - C:\WINDOWS\SYSTEM\DFVS\DFVSOL\DFVSIEBR.DLL
O3 - Toolbar: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL (file missing)
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IrMon] irmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Hide] C:\HWR\Hide.exe
O4 - HKLM\..\Run: [DFVCDROM] d:\!Sunv\DFVCD\DFVCDROM.EXE /mini
O4 - HKLM\..\Run: [Super Rabbit IELock] D:\笑2\IELOCK\IELOCK.exe /load
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CNSMIN.DLL,Rundll32
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [kingamp] D:\新建文件夹 (2)\KINGAMP.EXE
O4 - HKLM\..\Run: [MoveSearch] C:\PROGRAM FILES\WSEARCH\SEARCH.EXE
O4 - HKLM\..\Run: [YDTMain.exe] C:\PROGRA~1\YDT\YDTMain.exe
O4 - HKLM\..\Run: [csrss32] C:\WINDOWS\SYSTEM\csrss32.exe
O4 - HKLM\..\Run: [dl_accel] C:\PROGRAM FILES\3721\DLACCEL\YDownloader.exe
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\YAHOO!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [zysoft] C:\WINDOWS\DESKTOP\梦幻桌面\FantasyDeskTop.exe
O4 - HKLM\..\Run: [Antiy Auto Update] C:\PROGRAM FILES\ANTIY LABS\ALIVE\ALIVECENTER0.EXE
O4 - HKLM\..\Run: [NMGameX_AutoRun] C:\WINDOWS\Rundll32.exe NMGAMEX.DLL,LiveProcess /aa
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE\Update.exe
O4 - HKLM\..\Run: [RavTask] "D:\杀毒软件\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RavScanBD] "D:\杀毒软件\RISING\RAV\SCANBD.EXE" /INST
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [RNBOStart] C:\WINDOWS\SYSTEM\RNBOSENT\SENTSTRT.EXE
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [persfw] D:\杀毒软件\Personal Firewall\persfw.exe
O4 - HKLM\..\RunServices: [RavMon] "D:\杀毒软件\Rising\Rav\RavMon.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [IEXPLOER.EXE] C:\WINDOWS\IEXPLOER.EXE
O4 - HKCU\..\Run: [KuGoo3] "C:\PROGRAM FILES\KUGOO3\KUGOO.EXE"
O4 - Startup: 联想智能控制中心.lnk = C:\lxhome\lxremote\key_remote.exe
O4 - Startup: 键盘驱动.lnk = C:\lxhome\lxremote\USBCTRL.exe
O4 - Startup: 幸福之家工具条.lnk = C:\lxhome\lxquick\lxquick.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: InterVideo WinCinema Manager.lnk = D:\WinDVD\Common\Bin\WinCinemaMgr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &使用下载加速专家下载 - C:\PROGRAM FILES\3721\DLACCEL\geturl.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\PROGRAM FILES\TENCENT\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\PROGRAM FILES\TENCENT\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\PROGRAM FILES\TENCENT\QQ\SendMMS.htm
O8 - Extra context menu item: 使用新浪下载助手下载 - C:\WINDOWS\DOWNLO~1\sinadl.htm
O8 - Extra context menu item: 雅虎搜索 - res://C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL/246
O8 - Extra context menu item: 使用KuGoo3下载(&K) - C:\PROGRAM FILES\KUGOO3\KuGoo3DownX.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {57E91B47-F40A-11D1-B792-444553542001} - F:\WINDOWS优化大师 3.2A\WINDOWS优化大师.EXE (file missing)
O9 - Extra 'Tools' menuitem: &Windows优化大师 - {57E91B47-F40A-11D1-B792-444553542001} - F:\WINDOWS优化大师 3.2A\WINDOWS优化大师.EXE (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java 控制台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm?pid=U_168101_17124 (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: 东方卫士 - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CE} - C:\WINDOWS\SYSTEM\DFVS\DFVSOL\DFVSIEBR.DLL
O9 - Extra 'Tools' menuitem: 东方卫士工具条 - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CE} - C:\WINDOWS\SYSTEM\DFVS\DFVSOL\DFVSIEBR.DLL
O9 - Extra button: 在线杀毒 - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9EE} - http://www.i110.com/dfvsonline/ (file missing)
O9 - Extra 'Tools' menuitem: 东方卫士 - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9EE} - http://www.i110.com/dfvsonline/ (file missing)
O9 - Extra button: 新浪点点通阅读器 - {F0646DC8-58CD-4C64-8F6B-525043914685} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\RSSBAND.DLL (HKCU)
O9 - Extra button: (no name) - {974AD624-EA50-4831-A6C0-3040F6665396} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\RSSBAND.DLL (HKCU)
O9 - Extra 'Tools' menuitem: 新浪点点通阅读器 - {974AD624-EA50-4831-A6C0-3040F6665396} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\RSSBAND.DLL (HKCU)
O11 - Options group: [!CNS] 网络实名
O14 - IERESET.INF: START_PAGE_URL=http://www.lcs.legend.com.cn
O16 - DPF: {3D8F74EE-8692-4F8F-A8D2-7522B732519E} (WebActivater Control) - http://game.qq.com/QQGame.cab
O16 - DPF: {F381FC65-D92D-4410-B865-E4E9713994E8} (Cytd Encipherment Memory) - http://202.99.42.177/sso/ccitpay.CAB
O16 - DPF: {9BBD100C-E820-4930-9937-E8F3AA40E584} (DFVSScanFile Control) - http://antivirus3.sunv.com/dfvsolDown/dfvsol.cab
我有试,不行了,版本99。1,该死的BACKDOOR