开机提示:加载C:\windows\system32\nqzmas60.dll时出错,另一程序正在使用此文件,进程无法访问.
点确定后,桌面图标才出现
日志如下:
HijackThis_zww汉化版扫描日志 V1.99.1
保存于 14:23:23, 日期 2006-11-2
操作系统: Windows XP SP2 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP2 (6.00.2900.2180)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Rising\Rav\RavStub.exe
c:\program files\rising\rfw\RfwMain.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\hxupdate\hxgame-update.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\安装文件夹\HijackThis1991zww.exe
R3 - 默认的URLSearchHook丢失。用HijackThis修复
F3 - REG:win.ini: load=C:\WINDOWS\system\tpkIM32.exe
O1 - Hosts: 61.135.150.114 www.8000qq.com
O1 - Hosts: 61.135.150.114 www.800f.net
O1 - Hosts: 61.135.150.114 www.1000sf.cn
O1 - Hosts: 61.135.150.114 jfengsha.comfb
O1 - Hosts: 61.135.150.114 www.1000yf.net
O1 - Hosts: 61.135.150.114 www.159sifu.com
O1 - Hosts: 61.135.150.114 www.9s5.cn
O1 - Hosts: 61.135.150.114 www.spbuy.net
O1 - Hosts: 61.135.150.114 www.wym.cn
O1 - Hosts: 61.135.150.114 www.cc4f.cn
O1 - Hosts: 61.135.150.114 mafan.net
O1 - Hosts: 61.135.150.114 www.6688qn.net
O1 - Hosts: 61.135.150.114 www.177z.com
O1 - Hosts: 61.135.150.114 www.131sf.net
O1 - Hosts: 61.135.150.114 tj.cntg.cn
O1 - Hosts: 61.135.150.114 www.spbuy.net
O1 - Hosts: 61.135.150.114 www.china45.net
O1 - Hosts: 61.135.150.114 www.ok22.com
O1 - Hosts: 61.135.150.114 www.17mi.net
O1 - Hosts: 61.135.150.114 www.sf8.com.cn
O1 - Hosts: 61.135.150.114 www.13177.com
O1 - Hosts: 61.135.150.114 ip94.fd4f.com
O1 - Hosts: 61.135.150.114 www.521it.net
O1 - Hosts: 61.135.150.114 www.ytdj.cn
O1 - Hosts: 61.135.150.114 www.fwoool.cn
O1 - Hosts: 61.135.150.114 www.5u37.net
O1 - Hosts: 61.135.150.114 www.87sf.com
O1 - Hosts: 61.135.150.114 ww1.swoool.com
O1 - Hosts: 61.135.150.114 wooljsz.cn
O1 - Hosts: 61.135.150.114 www.57wool.com
O1 - Hosts: 61.135.150.114 www.58816.com
O1 - Hosts: 61.135.150.114 www.spbuy.net
O1 - Hosts: 61.135.150.114 chuanqisjsf.blwool.com
O1 - Hosts: 61.135.150.114 www.woool188.com
O1 - Hosts: 61.135.150.114 www.sf1260.com
O1 - Hosts: 61.135.150.114 linf23.b12.cnwg.cn
O1 - Hosts: 61.135.150.114 www.wooolweb.com
O1 - Hosts: 61.135.150.114 www.yq520.net
O1 - Hosts: 61.135.150.114 www.cs222.com
O1 - Hosts: 61.135.150.114 www.ok22.com
O1 - Hosts: 61.135.150.114 www.7100sf.com
O1 - Hosts: 61.135.150.114 www.1352sf.com
O1 - Hosts: 61.135.150.114 www.458wool.cn
O1 - Hosts: 61.135.150.114 www.555woool.cn
O1 - Hosts: 61.135.150.114 www.kaosf.com
O1 - Hosts: 61.135.150.114 www.siyuwl.com
O1 - Hosts: 61.135.150.114 www.csjsz.cn
O1 - Hosts: 61.135.150.114 www.13177.com
O1 - Hosts: 61.135.150.114 www.458cs.com
O1 - Hosts: 61.135.150.114 www.5573.com
O1 - Hosts: 61.135.150.114 www.02945.com
O1 - Hosts: 61.135.150.114 www.pkchina.net
O1 - Hosts: 61.135.150.114 www.5181314.com
O1 - Hosts: 61.135.150.114 www.fknf2.com
O1 - Hosts: 61.135.150.114 www2.yoursf.com
O1 - Hosts: 61.135.150.114 www.paocs.com
O1 - Hosts: 61.135.150.114 www.sfboke.com
O1 - Hosts: 61.135.150.114 www.tt878.com
O1 - Hosts: 61.135.150.114 ww1.woool188.com
O1 - Hosts: 61.135.150.114 www.cs119.com
O1 - Hosts: 61.135.150.114 www.xdwoool.net
O1 - Hosts: 61.135.150.114 www.tt515.com
O1 - Hosts: 61.135.150.114 www.cs176.com
O1 - Hosts: 61.135.150.114 www.552sf.com
O1 - Hosts: 61.135.150.114 www.ipmir.com
O1 - Hosts: 61.135.150.114 www.898woool.com
O1 - Hosts: 61.135.150.114 www.qqks.com
O1 - Hosts: 61.135.150.114 www.368idc.com
O1 - Hosts: 61.135.150.114 www.csbaba.com
O1 - Hosts: 61.135.150.114 www.4745.cn
O1 - Hosts: 61.135.150.114 www.636400.com
O1 - Hosts: 61.135.150.114 www.oursf.cn
O1 - Hosts: 61.135.150.114 www.laiba173.com
O1 - Hosts: 61.135.150.114 www.14455.com
O1 - Hosts: 61.135.150.114 www.zheshan.net
O1 - Hosts: 61.135.150.114 zt.aaaaasf.cn
O1 - Hosts: 61.135.150.114 www.zt1314.cn
O1 - Hosts: 61.135.150.114 www.zt4f.net
O1 - Hosts: 61.135.150.114 www.zt002.com
O1 - Hosts: 61.135.150.114 www.amir3.com
O1 - Hosts: 61.135.150.114 www.sf1717.com
O1 - Hosts: 61.135.150.114 www.cq333.cn
O1 - Hosts: 61.135.150.114 www.3316.cn
O1 - Hosts: 61.135.150.114 www.sosmir3.com
O1 - Hosts: 61.135.150.114 www.95279.com
O1 - Hosts: 61.135.150.114 www.sf1788.com
O1 - Hosts: 61.135.150.114 www.4fboss.com
O1 - Hosts: 61.135.150.114 www.45net.net
O1 - Hosts: 61.135.150.114 www.ytdj.cn
O1 - Hosts: 61.135.150.114 www.laiba173.com
O1 - Hosts: 61.135.150.114 www.wow1314.com
O1 - Hosts: 61.135.150.114 www.zgwow.com
O1 - Hosts: 61.135.150.114 www.1000wow.net
O1 - Hosts: 61.135.150.114 www.gowowsf.com
O1 - Hosts: 61.135.150.114 www.wowsf.com
O1 - Hosts: 61.135.150.114 www.wxwow.com
O1 - Hosts: 61.135.150.114 520.xinwow.com
O1 - Hosts: 61.135.150.114 www.wowhelp.cn
O1 - Hosts: 61.135.150.114 www.800wow.com
O1 - Hosts: 61.135.150.114 www.56wow.com
O1 - Hosts: 61.135.150.114 www.45wow.com
O2 - BHO: ra
Object Class - {46F194EB-B7DB-4B7A-BD42-5FF39FD17664} - C:\PROGRA~1\pcast\hbcast.dll
O2 - BHO: Windows Shell - {EC98B86F-5478-4805-B1D2-3B32C312FFC1} - C:\WINDOWS\system32\msdatsrc.dll
O3 - IE工具栏增项: 卡卡上网安全助手 - {DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} - C:\WINDOWS\system32\KakaTool.dll
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - 启动项HKLM\\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - 启动项HKLM\\Run: [RichMedia] C:\WINDOWS\system32\Rundll32.exe "C:\PROGRA~1\pcast\hbcast.dll",WaitWindows
O4 - 启动项HKLM\\Run: [hxgame-update] C:\Program Files\hxupdate\hxgame-update.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgswitch] C:\WINDOWS\system32\bgswitch.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O23 - NT 服务: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - NT 服务: Rising Proxy Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe