

上网好好的~~ 瑞星防火墙说什么XXX{灰鸽子} 访问网络~问我是否放行~。。。靠~~当然禁止了~~~~~~~~~~~~~~~~~~~~
用高手门的法子在安全模式下只扫出个~这个~~请问是鸽子么~

HijackThis 扫描结果在3楼
可疑程序在 SYSTEM32下
好心的留个QQ~帮我远程看下~谢谢~ (截图在最下面)
各位高手:
非常感谢您留心我这份系统诊断报告,小菜鸟十万火急等待您的帮助!
该诊断报告由360安全卫士提供 http://www.360safe.com
诊断时间: 2006-08-02 12:53:01
诊断平台: Microsoft Windows XP Service Pack 2
IE版本: Internet Explorer V6.0.2900.2180 Build: 62900.2180
FormVersion: 1.1
100 - Process: smss.exe - \SystemRoot\System32\smss.exe
100 - Process: csrss.exe - C:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestTh薯?
100 - Process: winlogon.exe - winlogon.exe
100 - Process: services.exe - C:\WINDOWS\system32\services.exe
100 - Process: lsass.exe - C:\WINDOWS\system32\lsass.exe
100 - Process: svchost.exe - C:\WINDOWS\system32\svchost -k DcomLaunch
100 - Process: svchost.exe - C:\WINDOWS\system32\svchost -k rpcss
100 - Process: CCenter.exe - "D:\瑞星\Rising\Rav\CCenter.exe"
100 - Process: svchost.exe - C:\WINDOWS\System32\svchost.exe -k netsvcs
100 - Process: svchost.exe - C:\WINDOWS\system32\svchost.exe -k LocalService
100 - Process: RavMonD.exe - "D:\瑞星\Rising\Rav\Ravmond.exe"
100 - Process: rfwsrv.exe - d:\瑞星\rising\rfw\rfwsrv.exe
100 - Process: RavStub.exe - D:\瑞星\Rising\Rav\RavStub.exe /RAVMOND
100 - Process: wdfmgr.exe - C:\WINDOWS\system32\wdfmgr.exe
100 - Process: explorer.exe - C:\WINDOWS\Explorer.EXE
100 - Process: rfwmain.exe - -StartUp
100 - Process: RavTask.exe - "D:\瑞星\Rising\Rav\RavTask.exe" -system
100 - Process: ctfmon.exe - "C:\WINDOWS\system32\ctfmon.exe"
100 - Process: RavMon.exe - "D:\瑞星\Rising\Rav\Ravmon.exe" -SYSTEM
100 - Process: Rav.exe - "D:\瑞星\Rising\Rav\Rav.exe"
100 - Process: IEXPLORE.EXE - "C:\Program Files\Internet Explorer\iexplore.exe" -Embedding
100 - Process: rfwcfg.exe - "d:\瑞星\rising\rfw\RfwCfg.exe" Rising_ShowMain
100 - Process: notepad.exe - "C:\WINDOWS\system32\NOTEPAD.EXE" C:\Documents and Settings\圣骑士\桌面\新建 文本文档.txt
100 - Process: QQ.exe - D:\QQ\QQ.exe
100 - Process: TIMPlatform.exe - D:\QQ\TIMPlatform.exe -Embedding
100 - Process: 360Safe.exe - "D:\360安全卫士\360Safe.exe"
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\system32\blank.htm
O2 - BHO: (QQBrowserHelper
Object Class) - {54EBD53A-9BC1-480B-966A-843A333CA162} - D:\QQ\QQIEHelper.dll
O3 - Toolbar: (卡卡上网安全助手) - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O3 - Toolbar: (第三方IE工具栏) - {1E796980-9CC5-11D1-A83F-00C04FC99D61} -
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [RavTask] "D:\瑞星\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [RfwMain] "D:\瑞星\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Web反病毒保护(HKLM)
O9 - Extra button: QQ炫彩工具条设置(HKLM)
O16 - DPF: {2354A44B-3CEB-4829-9940-545B03103538} (PowerPlr Control) - http://vod.e172.com/DGYY/plugin/PowerPlr.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Flash播放器) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5EED0E01-8242-4494-8B8C-BE063F4F4786}: NameServer = 211.138.200.69 211.103.13.101
O23 - Service: AVP - D:\卡巴杀毒软件\avp.exe
O23 - Service: Dnscache - C:\WINDOWS\system32\dnsrslvr.dll
O23 - Service: EventSystem - C:\WINDOWS\system32\es.dll
O23 - Service: Nla - C:\WINDOWS\system32\mswsock.dll
O23 - Service: RfwProxySrv - d:\瑞星\Rising\Rfw\rfwProxy.exe
O23 - Service: RfwService - d:\瑞星\Rising\Rfw\rfwsrv.exe
O23 - Service: RsCCenter - D:\瑞星\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon - D:\瑞星\Rising\Rav\RavMonD.exe