帮忙看看hijackthis扫描记录

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:24:22, on 2007-12-4
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
c:\program files\rising\rfw\rfwproxy.exe
c:\program files\rising\rfw\rfwstub.exe
C:\WINDOWS\Explorer.EXE
c:\program files\rising\rfw\RfwMain.exe
C:\PROGRAM FILES\RISING\RAV\RavStub.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\Program Files\北京城市热点资讯有限公司\Dr.COM 宽带客户端\ishare_user.exe
F:\工具\杀毒\360SAF~1.0B3\safemon\360Tray.exe
F:\工具\Thunder.v5.6.9.344.NoAD-Ayu\Program\Thunder5.exe
C:\Program Files\Maxthon\Maxthon.exe
F:\HiJackThis_v2\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - F:\工具\Thunder.v5.6.9.344.NoAD-Ayu\ComDlls\TDAtOnce_Now.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - F:\工具\Thunder.v5.6.9.344.NoAD-Ayu\ComDlls\xunleiBHO_Now.dll
O4 - HKLM\..\Run: [ravmond] C:\Program Files\rising\Rav\RavMonD.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O8 - Extra context menu item: 使用iTudou下载节目 - C:\Program Files\Tudou\iTudou\iTudou_Link.HTM
O8 - Extra context menu item: 使用迅雷下载 - F:\工具\Thunder.v5.6.9.344.NoAD-Ayu\Program\geturl.htm
O8 - Extra context menu item: 使用迅雷下载全部链接 - F:\工具\Thunder.v5.6.9.344.NoAD-Ayu\Program\getallurl.htm
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://easyabc.95599.cn/perbank/images/whb/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B623A4F-A77A-43CE-B288-40D3076AA0CF}: NameServer = 202.99.104.68,219.150.32.132
O17 - HKLM\System\CS1\Services\Tcpip\..\{5B623A4F-A77A-43CE-B288-40D3076AA0CF}: NameServer = 202.99.104.68,219.150.32.132
O17 - HKLM\System\CS2\Services\Tcpip\..\{5B623A4F-A77A-43CE-B288-40D3076AA0CF}: NameServer = 202.99.104.68,219.150.32.132
O17 - HKLM\System\CS3\Services\Tcpip\..\{5B623A4F-A77A-43CE-B288-40D3076AA0CF}: NameServer = 202.99.104.68,219.150.32.132
O18 - Protocol: dic - {C21F5C32-F57A-4A0D-8E0A-B672691C52D0} - C:\Program Files\Kingsoft\Powerword 2003\XDictExB.dll
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe

--
End of file - 3638 bytes


[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Poco 0.31; Maxthon; .NET CLR 1.1.4322)
最后编辑2007-12-04 18:41:34.530000000