我用的是卡巴!有时查出病毒就重启!
日志:Logfile of HijackThis v1.99.1
Scan saved at 19:46:14, on 2007-2-7
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\nvsvc32.exe
E:\ewido anti-spyware 4.0\ewido.exe
E:\360safe\safemon\360tray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
F:\Thunder Network\Thunder\Program\Thunder5.exe
E:\tencent\QQ\QQ.exe
E:\tencent\QQ\TIMPlatform.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.484\HijackThis.exe
R3 - URLSearchHook: b94b - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32
\4975ntos.dll (file missing)
O2 - BHO: (no name) - {0C14C96B-F5FC-448A-8B0D-4E03F37A8DBF} - (no file)
O2 - BHO: (no name) - {0C14C96C-F5FC-448A-8B0D-4E03F37A8DBF} - (no file)
O2 - BHO: (no name) - {0C14C96D-F5FC-448A-8B0D-4E03F37A8DBF} - (no file)
O2 - BHO: (no name) - {0C14C96E-F5FC-448A-8B0D-4E03F37A8DBF} - (no file)
O2 - BHO: (no name) - {0c14c96f-f5fc-448a-8b0d-4e03f37a8dbf} - C:\WINDOWS\system32
\448acfsb.dll (file missing)
O2 - BHO: ThunderBHO - {39F7E361-828A-4B5A-BCAF-5B79BFDFEA60} - F:\Thunder
Network\Thunder\ComDlls\XunLeiBHO_007.dll
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} -
e:\Tencent\QQ\QQIEHelper.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - F:\Thunder
Network\Thunder\ComDlls\XunLeiBHO_007.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: NavigatMon Class - {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -
E:\360safe\safemon\safemon.dll
O2 - BHO: b94b - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\4975ntos.dll
(file missing)
O3 - Toolbar: b94b - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32
\4975ntos.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32
\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SKYNET Personal FireWall] C:\PROGRA~1\SKYNET\FIREWALL\PFW.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [hwdfpa69] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32
\hwdfpa69.dll,DllCanUnloadNow
O4 - HKLM\..\Run: [kav] "E:\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [StormCodec_Helper] "e:\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [!ewido] "E:\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [360Safetray] E:\360safe\safemon\360tray.exe /start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [wsctf.exe] wsctf.exe
O4 - HKCU\..\Run: [Super Rabbit IEPro] E:\Super Rabbit\MagicSet\SRIECLI.EXE /LOAD
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &使用迅雷下载 - F:\Thunder Network\Thunder\Program\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\Thunder
Network\Thunder\Program\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - e:\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://C:\PROGRA~1
\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 导出当前页到超星阅览器(&A) - C:\Program Files\SSREADER36
\ss_all.htm
O8 - Extra context menu item: 导出选中部分到超星阅览器(&S) - C:\Program Files\SSREADER36
\ss_select.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - e:\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - e:\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - e:\Tencent\QQ\SendMMS.htm
O9 - Extra button: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - F:\Thunder
Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} -
F:\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: Web反病毒保护 - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - E:\Kaspersky
Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - e:\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} -
e:\Tencent\QQ\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} -
e:\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} -
e:\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: 财富通 - {C1F0024B-8278-4999-B7E6-2718426D9FE6} - C:\Program Files\财富
通\caifu.dll (HKCU)
O16 - DPF: {165D83D3-359C-4783-9BF0-6FA6DC42A3F1} (XDownload Class) -
http://tpath.5read.com/exe/ssdownload.cab
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) -
https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0DB63870-810B-4A21-BFA6-16E1A8176CB6}: NameServer
= 219.150.32.132,219.146.0.130
O17 - HKLM\System\CS1\Services\Tcpip\..\{0DB63870-810B-4A21-BFA6-16E1A8176CB6}: NameServer
= 219.150.32.132,219.146.0.130
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1
\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1
\MSGRAP~1.DLL
O20 - Winlogon Notify: cryptimg - cryptig.dll (file missing)
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O21 - SSODL: SysChunk - {6C5DC6D8-C9AF-43E6-A412-6AA7C582E5C5} - C:\WINDOWS\system32
\syschunk.dll (file missing)
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common
Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: 卡巴斯基反病毒软件6.0 (AVP) - Unknown owner - E:\Kaspersky Lab\Kaspersky
Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
C:\WINDOWS\system32\nvsvc32.exe
谢谢大家!!!!!!!!!!!!!!!!!!!!!!!!!!!