扫描结果如下,请高手帮忙.
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 10:06:22, 日期 2005-7-30
操作系统: Windows 2000 SP4 (WinNT 5.00.2195)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\PROGRAM FILES\RISING\RAV\Ravmond.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\Program Files\SkyNet\FireWall\PFW.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\RISING\RAV\RAVMON.EXE
C:\WINNT\system32\ctfmon.exe
C:\Program Files\eMule\eMule.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\Administrator\桌面\临时文件\729\HijackThis1991zww.exe
O1 - Hosts: 218.85.132.177 zs.3721.com
O1 - Hosts: 218.85.132.177 seek.3721.com
O1 - Hosts: 218.85.132.177 auto.search.msn.com
O1 - Hosts: 218.85.132.177 dir.sina.com.cn
O1 - Hosts: 218.85.132.177 pic.sina.com.cn
O1 - Hosts: 218.85.132.177 search.sina.com.cn
O1 - Hosts: 218.85.132.177 dir.sohu.com
O1 - Hosts: 218.85.132.177 dir.sogou.com
O1 - Hosts: 218.85.132.177 dir.yahoo.com
O1 - Hosts: 218.85.132.177 popme.163.com
O1 - Hosts: 218.85.132.177 site.baidu.com
O1 - Hosts: 218.85.132.177 www.432.cn
O1 - Hosts: 218.85.132.177 x.baidu.com
O1 - Hosts: 218.85.132.177 assistant.3721.com
O1 - Hosts: 218.85.132.177 sms.3721.com
O1 - Hosts: 218.85.132.177 cnsmin.3721.com
O1 - Hosts: 218.85.132.177 hot.3721.com
O1 - Hosts: 218.85.132.177 3721.com
O1 - Hosts: 218.85.132.177 www.3721.com
O1 - Hosts: 218.85.132.177 dl.3721.com
O1 - Hosts: 218.85.132.177 www.skycn.com
O1 - Hosts: 218.85.132.177 skycn.com
O1 - Hosts: 218.85.132.177 nmsearch.3721.com
O1 - Hosts: 218.85.132.177 cmail.3721.com
O1 - Hosts: 218.85.132.177 corp.3721.com
O1 - Hosts: 218.85.132.177 download.3721.com
O1 - Hosts: 218.85.132.177 www.hao123.com
O1 - Hosts: 218.85.132.177 www.hao123.net
O1 - Hosts: 218.85.132.177 hao123.com
O1 - Hosts: 218.85.132.177 hao123.net
O1 - Hosts: 218.85.132.177 www.265.com
O1 - Hosts: 218.85.132.177 265.com
O1 - Hosts: 218.85.132.177 www.3tom.com
O1 - Hosts: 218.85.132.177 www.da123.com
O1 - Hosts: 218.85.132.177 www.ttjj.com
O1 - Hosts: 218.85.132.177 www.gjj.cc
O1 - Hosts: 218.85.132.177 www.516.com
O1 - Hosts: 218.85.132.177 union.265.com
O1 - Hosts: 218.85.132.177 wn.265.com
O1 - Hosts: 218.85.132.177 music.265.com
O1 - Hosts: 218.85.132.177 516.com
O1 - Hosts: 218.85.132.177 mp3.516.com
O1 - Hosts: 218.85.132.177 www.sowang.com
O1 - Hosts: 218.85.132.177 www.asiacool.com
O1 - Hosts: 218.85.132.177 www.haodx.com
O1 - Hosts: 218.85.132.177 www.365key.com
O1 - Hosts: 218.85.132.177 www.365key.com
O1 - Hosts: 218.85.132.177 www.5566.net
O1 - Hosts: 218.85.132.177 5566.net
O1 - Hosts: 218.85.132.177 www.v111.com
O1 - Hosts: 218.85.132.177 v111.com
O1 - Hosts: 218.85.132.177 www.tthao.com
O1 - Hosts: 218.85.132.177 www.51115.com
O1 - Hosts: 218.85.132.177 www.K369.com
O1 - Hosts: 218.85.132.177 www.37021.com
O1 - Hosts: 218.85.132.177 www.qqwz.com
O1 - Hosts: 218.85.132.177 www.haokan123.com
O1 - Hosts: 218.85.132.177 www.zhao99.com
O1 - Hosts: 218.85.132.177 www.vv11.com
O1 - Hosts: 218.85.132.177 www.114.com.cn
O1 - Hosts: 218.85.132.177 url.114.com.cn
O1 - Hosts: 218.85.132.177 www.34se.com
O1 - Hosts: 218.85.132.177 www.chinadmoz.net
O1 - Hosts: 218.85.132.177 webspacecn.com
O1 - Hosts: 218.85.132.177 www.seed.cn
O1 - Hosts: 218.85.132.177 www.56ds.com
O1 - Hosts: 218.85.132.177 dianying2009.com
O1 - Hosts: 218.85.132.177 vod.epac.to
O1 - Hosts: 218.85.132.177 www.zhaoshang.net.cn
O1 - Hosts: 218.85.132.177 www.282.com.cn
O1 - Hosts: 218.85.132.177 51.163.com
O1 - Hosts: 218.85.132.177 www.op99.com
O1 - Hosts: 218.85.132.177 op99.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: DownloadBHO T2BHO - {B1D147E7-873E-4909-8127-695D9BB78728} - C:\WINNT\Downloaded Program Files\barhelp22.0.dll
O3 - IE工具栏增项: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [RavTimer] C:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - 启动项HKLM\\Run: [SKYNET Personal FireWall] C:\Program Files\SkyNet\FireWall\PFW.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [RavMon] C:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - 启动项HKLM\\Run: [YDTMain.exe] C:\PROGRA~1\YDT\YDTMain.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStart
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - 浏览器额外的按钮: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的“工具”菜单项: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - 浏览器额外的按钮: 百万图库 - {6713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/p (file missing) (HKCU)
O9 - 浏览器额外的按钮: 铃声图片下载 - {7713E8D2-850A-101B-AFC0-4210102A8DA7} - http://www.26-3.com/sms/index.htm (file missing) (HKCU)
O16 - DPF: {2BFAA61B-5C83-4865-8281-D8BDBF863061} (PGEdit Class) - https://www.gnetpg.com/PG_ATL.cab
O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (CEditCtrl
Object) - https://img.alipay.com/download/aliedit.cab
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} (天下搜索) - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EEB72AEE-B2C1-4793-9FB2-26358FE8FD42}: NameServer = 202.96.128.143,202.96.128.68
O23 - NT 服务: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - rising - C:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\PROGRAM FILES\RISING\RAV\Ravmond.exe