HijackThis_zww汉化版扫描日志 V1.99.1
保存于 10:54:46, 日期 2006-1-12
操作系统: Windows 2000 SP4 (WinNT 5.00.2195)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\SearchNet\SearchNet.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\wuauclt.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\system32\BCUP.exe
C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
C:\WINNT\system32\internat.exe
C:\WINNT\system32\conime.exe
C:\WINNT\rundll32.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\DuDu\DDDClient\dudupros.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Program Files\Tencent\QQ\TIMPlatform.exe
F:\共享文件夹\HijackThis1991zww.exe
R3 - URLSearchHook: assist - {1B0E7716-898E-48cc-9690-4E338E8DE1D3} - (no file)
R3 - URLSearchHook: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
R3 - URLSearchHook: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O1 - Hosts: 204.13.64.174 www.tm8668.com
O1 - Hosts: 204.13.64.174 tm8668.com
O1 - Hosts: 204.13.64.174 www.2008com.com
O1 - Hosts: 204.13.64.174 2008com.com
O1 - Hosts: 204.13.64.174 www.53444.com
O1 - Hosts: 204.13.64.174 53444.com
O1 - Hosts: 204.13.64.174 www.53444.net
O1 - Hosts: 204.13.64.174 53444.net
O1 - Hosts: 204.13.64.174 www.878.cc
O1 - Hosts: 204.13.64.174 878.cc
O1 - Hosts: 204.13.64.174 www.92939.com
O1 - Hosts: 204.13.64.174 92939.com
O1 - Hosts: 204.13.64.174 www.796888.com
O1 - Hosts: 204.13.64.174 796888.com
O1 - Hosts: 204.13.64.174 www.hk6738.com
O1 - Hosts: 204.13.64.174 hk6738.com
O1 - Hosts: 204.13.64.174 www.k3377.com
O1 - Hosts: 204.13.64.174 k3377.com
O1 - Hosts: 204.13.64.174 www.ttmm66.com
O1 - Hosts: 204.13.64.174 ttmm66.com
O1 - Hosts: 204.13.64.174 www.7707.hk
O1 - Hosts: 204.13.64.174 7707.hk
O1 - Hosts: 204.13.64.174 www.hk3344.com
O1 - Hosts: 204.13.64.174 hk3344.com
O1 - Hosts: 204.13.64.174 www.9994777.com
O1 - Hosts: 204.13.64.174 9994777.com
O1 - Hosts: 204.13.64.174 www.hk691.com
O1 - Hosts: 204.13.64.174 hk691.com
O1 - Hosts: 204.13.64.174 www.ok0888.com
O1 - Hosts: 204.13.64.174 ok0888.com
O1 - Hosts: 204.13.64.174 www.55677.com
O1 - Hosts: 204.13.64.174 55677.com
O1 - Hosts: 204.13.64.174 www.hh689.com
O1 - Hosts: 204.13.64.174 hh689.com
O1 - Hosts: 204.13.64.174 www.48123.com
O1 - Hosts: 204.13.64.174 48123.com
O1 - Hosts: 204.13.64.174 www.kk811.com
O1 - Hosts: 204.13.64.174 kk811.com
O1 - Hosts: 204.13.64.174 www.7k8k9k.com
O1 - Hosts: 204.13.64.174 7k8k9k.com
O1 - Hosts: 204.13.64.174 www.k678.com
O1 - Hosts: 204.13.64.174 k678.com
O1 - Hosts: 204.13.64.174 www.9999k.com
O1 - Hosts: 204.13.64.174 9999k.com
O1 - Hosts: 204.13.64.174 www.666fff.com
O1 - Hosts: 204.13.64.174 666fff.com
O1 - Hosts: 204.13.64.174 www.kk7878.com
O1 - Hosts: 204.13.64.174 kk7878.com
O1 - Hosts: 204.13.64.174 www.kk321.com
O1 - Hosts: 204.13.64.174 kk321.com
O1 - Hosts: 204.13.64.174 www.18099.cc
O1 - Hosts: 204.13.64.174 18099.cc
O1 - Hosts: 204.13.64.174 www.tm80.net
O1 - Hosts: 204.13.64.174 tm80.net
O1 - Hosts: 204.13.64.174 www.66346.com
O1 - Hosts: 204.13.64.174 66346.com
O1 - Hosts: 204.13.64.174 www.4428.cn
O1 - Hosts: 204.13.64.174 4428.cn
O1 - Hosts: 204.13.64.174 www.v8885.com
O1 - Hosts: 204.13.64.174 v8885.com
O1 - Hosts: 204.13.64.174 www.558868.com
O1 - Hosts: 204.13.64.174 558868.com
O1 - Hosts: 204.13.64.174 www.18899.com
O1 - Hosts: 204.13.64.174 18899.com
O1 - Hosts: 204.13.64.174 www.hp5868.com
O1 - Hosts: 204.13.64.174 hp5868.com
O1 - Hosts: 204.13.64.174 www.hksaimahuilhc.com
O1 - Hosts: 204.13.64.174 hksaimahuilhc.com
O1 - Hosts: 204.13.64.174 www.t838.com
O1 - Hosts: 204.13.64.174 t838.com
O1 - Hosts: 204.13.64.174 www.688555.com
O1 - Hosts: 204.13.64.174 688555.com
O1 - Hosts: 204.13.64.174 www.676888.com
O1 - Hosts: 204.13.64.174 676888.com
O1 - Hosts: 204.13.64.174 www.gg7777.com
O1 - Hosts: 204.13.64.174 gg7777.com
O1 - Hosts: 204.13.64.174 www.kk7999.com
O1 - Hosts: 204.13.64.174 kk7999.com
O1 - Hosts: 204.13.64.174 www.GG444.com
O1 - Hosts: 204.13.64.174 GG444.com
O1 - Hosts: 204.13.64.174 www.xg990.com
O1 - Hosts: 204.13.64.174 xg990.com
O1 - Hosts: 204.13.64.174 www.qq6789.com
O1 - Hosts: 204.13.64.174 qq6789.com
O1 - Hosts: 204.13.64.174 www.ma333.com
O1 - Hosts: 204.13.64.174 ma333.com
O1 - Hosts: 204.13.64.174 www.59659.com
O1 - Hosts: 204.13.64.174 59659.com
O1 - Hosts: 204.13.64.174 www.993999.com
O1 - Hosts: 204.13.64.174 993999.com
O1 - Hosts: 204.13.64.174 www.6306.com
O1 - Hosts: 204.13.64.174 6306.com
O1 - Hosts: 204.13.64.174 www.13444.com
O1 - Hosts: 204.13.64.174 13444.com
O1 - Hosts: 204.13.64.174 www.tm286.com
O1 - Hosts: 204.13.64.174 tm286.com
O1 - Hosts: 204.13.64.174 www.cctv138.com
O1 - Hosts: 204.13.64.174 cctv138.com
O1 - Hosts: 204.13.64.174 www.tm886.com
O1 - Hosts: 204.13.64.174 tm886.com
O1 - Hosts: 204.13.64.174 www.cgokok.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: yPhtb - {33BBE430-0E42-4f12-B075-8D21ACB10DCB} - C:\Program Files\Yahoo!\Assistant\Assist\yphtb.dll
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: Anti Fish - {38928D50-8A48-44C2-945F-D2F23F771410} - C:\Program Files\Yahoo!\Assistant\Assist\yAngling.dll
O2 - BHO: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: YDragSearch - {62EED7C6-9F02-42f9-B634-98E2899E147B} - C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O2 - BHO: DuDu.com - {6BDE1669-B490-48E3-B668-456314F2D6C3} - C:\Program Files\DuDu\DddClient\dddiemon.dll
O2 - BHO: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINNT\system32\drivers\inf\bands.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: YiSou - {EF1D17A9-089F-40cc-8D64-7324CDEBA0DB} - C:\PROGRA~1\yisou\yisoub.dll (file missing)
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll
O3 - IE工具栏增项: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - IE工具栏增项: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
O3 - IE工具栏增项: 一搜工具条 - {115F6E46-FCBC-41ed-B3B5-3BDDD4AAB5E5} - C:\Program Files\yisou\yisou.dll (file missing)
O3 - IE工具栏增项: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - (no file)
O3 - IE工具栏增项: 博采 - {4DA2EE61-6399-4C39-AEB9-0D990E610D29} - C:\WINNT\system32\BoCaiToolbar.dll
O3 - IE工具栏增项: 雅虎助手 - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - C:\Program Files\Yahoo!\Assistant\Assist\yasbar.dll
O4 - 启动项HKLM\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - 启动项HKLM\\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - 启动项HKLM\\Run: [nwiz] nwiz.exe /install
O4 - 启动项HKLM\\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [SDiskDaemon] C:\WINNT\sdiskmon.exe
O4 - 启动项HKLM\\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - 启动项HKLM\\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - 启动项HKLM\\Run: [warehost] warehost.exe
O4 - 启动项HKLM\\Run: [MoveSearch] C:\Program Files\wsearch\Search.exe
O4 - 启动项HKLM\\Run: [BCUpdate] C:\WINNT\system32\BCUP.exe
O4 - 启动项HKLM\\Run: [ADShow] C:\WINNT\system32\bcsysnote.exe
O4 - 启动项HKLM\\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - 启动项HKLM\\Run: [yassistse] "C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"
O4 - 启动项HKLM\\Run: [CnsMin] Rundll32.exe C:\WINNT\downlo~1\CnsMin.dll,Rundll32
O4 - 启动项HKLM\\Run: [SearchNet_Up] "C:\Program Files\SearchNet\ServeUp.exe"
O4 - 启动项HKLM\\Run: [] regedit -s C:\$NtUninstallQ5926809$\spcustom.dll
O4 - 启动项HKLM\\Run: [3721] C:\$NtUninstallQ5926809$\a3721.bat
O4 - 启动项HKLM\\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - 启动项HKLM\\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ5926809$\spcustom.dll
O4 - HKCU\..\Run: [3721] C:\$NtUninstallQ5926809$\a3721.bat
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O4 - Startup: 桌面媒体.lnk = C:\WINNT\system32\rundll32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: DuDu加速器.lnk = C:\Program Files\DuDu\DDDClient\DuDuAcc.exe
O4 - Global Startup: 桌面传媒.lnk = C:\WINNT\system32\rundll32.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(3).lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE