我的HJ
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
G:\PROGRAM FILES\RISING\RAV\CCENTER.EXE
G:\PROGRAM FILES\RISING\RAV\RAVMOND.EXE
G:\PROGRAM FILES\RISING\RAV\RAVMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\ESSSPK.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\SAVE\SAVE.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\EVTHTM.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\BCUP.EXE
G:\PROGRAM FILES\RISING\RAV\RAVTIMER.EXE
C:\WINDOWS\SYSTEM\W98EJECT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\CHINANET\VNETCLIENT.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\TENCENT\TT\TTRAVELER.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\PYINTAU.EXE
E:\155847200541134207\HIJACKTHIS.EXE
R3 - Default URLSearchHook is missing
F1 - win.ini: load=essspk.exe
O1 - Hosts: 203.186.92.27 www.567hk.com
O1 - Hosts: 203.186.92.27 567hk.com
O1 - Hosts: 203.186.92.27 fc987.com
O1 - Hosts: 203.186.92.27 www.fc987.com
O1 - Hosts: 203.186.92.27 hk3777.com
O1 - Hosts: 203.186.92.27 www.hk3777.com
O1 - Hosts: 203.186.92.27 32012.com
O1 - Hosts: 203.186.92.27 www.32012.com
O1 - Hosts: 203.186.92.27 www.97118.com
O1 - Hosts: 203.186.92.27 97118.com
O1 - Hosts: 203.186.92.27 16700.net
O1 - Hosts: 203.186.92.27 www.16700.net
O1 - Hosts: 203.186.92.27 85668.com
O1 - Hosts: 203.186.92.27 www.85668.com
O1 - Hosts: 203.186.92.27 tk399.net
O1 - Hosts: 203.186.92.27 www.tk399.net
O1 - Hosts: 203.186.92.27 www.it889.com
O1 - Hosts: 203.186.92.27 it889.com
O1 - Hosts: 203.186.92.27 www.567222.com
O1 - Hosts: 203.186.92.27 567222.com
O1 - Hosts: 203.186.92.27 www.3721.com
O1 - Hosts: 203.186.92.27 3721.com
O1 - Hosts: 203.186.92.27 www.tk9933.com
O1 - Hosts: 203.186.92.27 tk9933.com
O1 - Hosts: 203.186.92.27 www.585688.com
O1 - Hosts: 203.186.92.27 585688.com
O1 - Hosts: 203.186.92.27 www.61380.com
O1 - Hosts: 203.186.92.27 61380.com
O1 - Hosts: 203.186.92.27 www1.61380.com
O1 - Hosts: 203.186.92.27 61380.com
O1 - Hosts: 203.186.92.27 www.82886.com
O1 - Hosts: 203.186.92.27 82886.com
O1 - Hosts: 203.186.92.27 www.hao339.com
O1 - Hosts: 203.186.92.27 hao339.com
O1 - Hosts: 203.186.92.27 www.kai888.com
O1 - Hosts: 203.186.92.27 kai888.com
O1 - Hosts: 203.186.92.27 www.57088.com
O1 - Hosts: 203.186.92.27 57088.com
O1 - Hosts: 203.186.92.27 zhinanzhen.com
O1 - Hosts: 203.186.92.27 www.zhinanzhen.com
O1 - Hosts: 203.186.92.27 www.118y.com
O1 - Hosts: 203.186.92.27 118y.com
O1 - Hosts: 203.186.92.27 www.111168.com
O1 - Hosts: 203.186.92.27 111168.com
O1 - Hosts: 203.186.92.27 www.vv166.com
O1 - Hosts: 203.186.92.27 vv166.com
O1 - Hosts: 203.186.92.27 www1.vv166.com
O1 - Hosts: 203.186.92.27 vv166.com
O1 - Hosts: 203.186.92.27 www2.vv166.com
O1 - Hosts: 203.186.92.27 vv166.com
O1 - Hosts: 203.186.92.27 www3.vv166.com
O1 - Hosts: 203.186.92.27 vv166.com
O1 - Hosts: 203.186.92.27 www4.vv166.com
O1 - Hosts: 203.186.92.27 vv166.com
O1 - Hosts: 203.186.92.27 www5.vv166.com
O1 - Hosts: 203.186.92.27 vv166.com
O1 - Hosts: 203.186.92.27 www6.vv166.com
O1 - Hosts: 203.186.92.27 vv166.com
O1 - Hosts: 203.186.92.27 www7.vv166.com
O1 - Hosts: 203.186.92.27 vv166.com
O1 - Hosts: 203.186.92.27 www8.vv166.com
O1 - Hosts: 203.186.92.27 vv166.com
O1 - Hosts: 203.186.92.27 www9.vv166.com
O1 - Hosts: 203.186.92.27 vv166.com
O1 - Hosts: 203.186.92.27 www.8878668.com
O1 - Hosts: 203.186.92.27 8878668.com
O1 - Hosts: 203.186.92.27 www.7788668.com
O1 - Hosts: 203.186.92.27 7788668.com
O1 - Hosts: 203.186.92.27 www.887898.com
O1 - Hosts: 203.186.92.27 887898.com
O1 - Hosts: 203.186.92.27 www.008521888.net
O1 - Hosts: 203.186.92.27 008521888.net
O1 - Hosts: 203.186.92.27 www.333721.com
O1 - Hosts: 203.186.92.27 333721.com
O1 - Hosts: 203.186.92.27 www.kai888.com
O1 - Hosts: 203.186.92.27 kai888.com
O1 - Hosts: 203.186.92.27 www.hk256.com
O1 - Hosts: 203.186.92.27 hk256.com
O1 - Hosts: 203.186.92.27 www8.cp008.com
O1 - Hosts: 203.186.92.27 cp008.com
O1 - Hosts: 203.186.92.27 www1.cp008.com
O1 - Hosts: 203.186.92.27 cp008.com
O1 - Hosts: 203.186.92.27 www.yy6888.com
O1 - Hosts: 203.186.92.27 yy6888.com
O1 - Hosts: 203.186.92.27 www8.57088.com
O1 - Hosts: 203.186.92.27 57088.com
O1 - Hosts: 203.186.92.27 www8.60066.com
O1 - Hosts: 203.186.92.27 60066.com
O1 - Hosts: 203.186.92.27 www8.ok2188.com
O1 - Hosts: 203.186.92.27 ok2188.com
O1 - Hosts: 203.186.92.27 www.kai888.com
O1 - Hosts: 203.186.92.27 kai888.com
O1 - Hosts: 203.186.92.27 www.3953.com
O1 - Hosts: 203.186.92.27 3953.com
O1 - Hosts: 203.186.92.27 www.tk6788.com
O1 - Hosts: 203.186.92.27 tk6788.com
O1 - Hosts: 203.186.92.27 www.8886988.net
O1 - Hosts: 203.186.92.27 8886988.net
O1 - Hosts: 203.186.92.27 www1.8886988.net
O1 - Hosts: 203.186.92.27 www2.8886988.net
O1 - Hosts: 203.186.92.27 www3.8886988.net
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - G:\FLASHGET\FLASHGET\JCCATCH.DLL
O2 - BHO: CIEStub Class - {EBBFE27C-BDF0-11D2-BBE5-00609419F467} - C:\WINDOWS\SYSTEM\AMCIS.DLL (file missing)
O2 - BHO: (no name) - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: (no name) - {40E3A34A-3282-41F8-AD2C-051BAB96AD4A} - (no file)
O2 - BHO: DragSearch BHO - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\YISOU\YISOUB.DLL
O2 - BHO: Infofo 工具栏 - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\PROGRAM FILES\INFOFO BAR\INFOFOBAR.DLL
O2 - BHO: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\SYSTEM\XUNLEIBHO_V5.DLL
O2 - BHO: InsII - {88F0447D-BAC5-4aa4-B184-3781CD93D605} - C:\WINDOWS\SYSTEM\iisnirb.dll
O3 - Toolbar: (no name) - {AB6BEAD2-325B-4729-BB13-DB24509EFA54} - (no file)
O3 - Toolbar: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\PROGRAM FILES\YISOU\YISOU.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Infofo 工具栏 - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D} - C:\PROGRAM FILES\INFOFO BAR\INFOFOBAR.DLL
O3 - Toolbar: 完美网译通 - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - C:\WINDOWS\WORLD2\TOOLBAR\HMTOOLBAR.DLL
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL
O3 - Toolbar: 博采 - {4DA2EE61-6399-4C39-AEB9-0D990E610D29} - C:\WINDOWS\SYSTEM\BOCAIT~1.DLL
O3 - Toolbar: (no name) - {AB6BEAD2-325B-4729-BB13-DB24509EFA54 - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3 - (no file)
O3 - Toolbar: (no name) - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5 - (no file)
O3 - Toolbar: (no name) - {8E718888-423F-11D2-876E-00A0C9082467 - (no file)
O3 - Toolbar: (no name) - {BB936323-19FA-4521-BA29-ECA6A121BC78 - (no file)
O3 - Toolbar: (no name) - {B5A34A93-D538-43A7-8371-864CB6148D12 - (no file)
O3 - Toolbar: (no name) - {D74EC18E-3DDD-4174-B1B1-949FE3B8366D - (no file)
O3 - Toolbar: (no name) - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0 - (no file)
O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86 - (no file)
O3 - Toolbar: (no name) - {4DA2EE61-6399-4C39-AEB9-0D990E610D29 - (no file)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - G:\FLASHGET\FLASHGET\FGIEBAR.DLL
O3 - Toolbar: 卡卡安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\SYSTEM\KAKATOOL.DLL
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Trickler] "f:\新建文件夹\divx pro codec\gain_trickler_3202.exe"
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [KV3000W] G:\KV3000W\KVWMon.EXE
O4 - HKLM\..\Run: [Sys32] regedit -s C:\$NtUninstallQ5588565$\WINSYS.cer
O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\SAVE\Save.exe
O4 - HKLM\..\Run: [DFVCDROM] G:\东方魔术师\DFVCDROM.EXE /mini
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [cnyisou_com] http://www.458880.com
O4 - HKLM\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\sp4custom.dll
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [EvtHtm] c:\windows\system\evthtm.exe /nocomm
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AxFilter] Rundll32.exe C:\WINDOWS\DOWNLO~1\CONFLICT.1\AXFILTER.DLL,Rundll32
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [KvMonXP] G:\KV2005\KVMonXP.kxp /auto
O4 - HKLM\..\Run: [BCUpdate] C:\WINDOWS\SYSTEM\BCUP.exe
O4 - HKLM\..\Run: [MoveSearch] C:\PROGRAM FILES\WSEARCH\SEARCH.EXE
O4 - HKLM\..\Run: [RavTimer] G:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] G:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [LoadPFW] wmimgr.exe
O4 - HKLM\..\RunServices: [Kingsoft AntiVirus] G:\KAV9X\KAV9X.EXE -SystemStartup -Watcher
O4 - HKLM\..\RunServices: [RsCcenter] G:\PROGRA~1\RISING\RAV\CCENTER.EXE
O4 - HKLM\..\RunServices: [RavMond] G:\PROGRA~1\RISING\RAV\RAVMOND.EXE
O4 - HKLM\..\RunServices: [RavMon] G:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ8877565$\WINSYS.cer
O4 - HKCU\..\Run: [KvXP] G:\KV2005\KvXP.kxp /ScanBoot /ScanSys
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\TENCENT\QQ\QQ.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: w98Eject.lnk = C:\WINDOWS\System\w98eject.exe