下面是扫描的日志文件:
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 22:35:27, 日期 2006-10-4
操作系统: Windows 2000 SP3 (WinNT 5.00.2195)
浏览器: Internet Explorer v6.00 (6.00.2600.0000)
当前运行的进程:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINNT\system32\internat.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Winamp\winamp.exe
C:\WINNT\regedit.exe
C:\WINNT\system32\cmd.exe
C:\WINNT\system32\conime.exe
C:\WINNT\system32\cmd.exe
C:\WINNT\system32\cmd.exe
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\HijackThis1991汉化版\HijackThis1991zww.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
R3 - URLSearchHook: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} -
C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} -
C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} -
C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program
Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} -
C:\PROGRA~1\Yahoo!\ASSIST~1\assist\YDRAGS~1.DLL
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} -
C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: System Helper - {B88DBC3F-41FB-40AE-AFB0-4220E842B710} - C:\WINNT\system32\flash9.dll
O2 - BHO: AssistII - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\Net
Transport\NTIEHelper.dll
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINNT\System32\msdxm.ocx
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -
C:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - IE工具栏增项: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O3 - IE工具栏增项: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} -
C:\PROGRA~1\baidu\bar\baidubar.dll
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} -
C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [nwiz] nwiz.exe /install
O4 - 启动项HKLM\\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - 启动项HKLM\\Run: [NMGameX_AutoRun] C:\WINNT\system32\Rundll32.exe NMGameX.dll,LiveProcess
/aa
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - 启动项HKLM\\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - 启动项HKLM\\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - 启动项HKLM\\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - 启动项HKLM\\Run: [rundll32] rundll32 rscfg.dll s
O4 - 启动项HKLM\\RunOnce: [CnsAssecblk] regsvr32.exe /s
C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YASSEC~1.DLL
O4 - 启动项HKLM\\RunOnce: [YahooC:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll3327074] regsvr32 /s
C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yasbar.dll
O4 - 启动项HKLM\\RunOnce: [YahooC:\PROGRA~1\Yahoo!\ASSIST~1\assist\ywiper.dll3334494] regsvr32 /s
C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ywiper.dll
O4 - 启动项HKLM\\RunOnce: [YahooC:\PROGRA~1\Yahoo!\ASSIST~1\assist\ydragsearch.dll3342486] regsvr32 /s
C:\PROGRA~1\Yahoo!\ASSIST~1\assist\ydragsearch.dll
O4 - 启动项HKLM\\RunOnce: [YahooC:\PROGRA~1\Yahoo!\ASSIST~1\assist\yzsnetproto.dll3343798] regsvr32
/s C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yzsnetproto.dll
O4 - 启动项HKLM\\RunOnce: [YahooC:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll3346712] regsvr32 /s
C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yphtb.dll
O4 - 启动项HKLM\\RunOnce: [YahooC:\PROGRA~1\Yahoo!\ASSIST~1\assist\yangling.dll3350197] regsvr32 /s
C:\PROGRA~1\Yahoo!\ASSIST~1\assist\yangling.dll
O4 - 启动项HKLM\\RunOnce: [YahooC:\PROGRA~1\Yahoo!\ASSIST~1\ynotifier.dll3392167] regsvr32 /s
C:\PROGRA~1\Yahoo!\ASSIST~1\ynotifier.dll
O4 - 启动项HKLM\\RunOnce: [YahooC:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll3392347] regsvr32 /s
C:\PROGRA~1\Yahoo!\ASSIST~1\yscrblock.dll
O4 - 启动项HKLM\\RunOnce: [Register_C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll]
C:\WINNT\system32\regsvr32.exe /s C:\PROGRA~1\Yahoo!\ASSIST~1\YAlive.dll
O4 - 启动项HKLM\\RunOnce: [Register_C:\PROGRA~1\Yahoo!\ASSIST~1\YNOTIF~1.DLL]
C:\WINNT\system32\regsvr32.exe /s C:\PROGRA~1\Yahoo!\ASSIST~1\YNOTIF~1.DLL
O4 - 启动项HKLM\\RunOnce: [Register_C:\PROGRA~1\Yahoo!\ASSIST~1\YSCRBL~1.DLL]
C:\WINNT\system32\regsvr32.exe /s C:\PROGRA~1\Yahoo!\ASSIST~1\YSCRBL~1.DLL
O4 - 启动项HKLM\\RunOnce: [Register_C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll]
C:\WINNT\system32\regsvr32.exe /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O4 - 启动项HKLM\\RunOnce: [Register_C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YZSNET~1.DLL]
C:\WINNT\system32\regsvr32.exe /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YZSNET~1.DLL
O4 - 启动项HKLM\\RunOnce: [Register_C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll]
C:\WINNT\system32\regsvr32.exe /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yphtb.dll
O4 - 启动项HKLM\\RunOnce: [Register_C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL]
C:\WINNT\system32\regsvr32.exe /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O4 - 启动项HKLM\\RunOnce: [Register_C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll]
C:\WINNT\system32\regsvr32.exe /s C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yangling.dll
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe