瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】我的主页被http://www.adarson.com/恶意修改.

1   1  /  1  页   跳转

【求助】我的主页被http://www.adarson.com/恶意修改.

【求助】我的主页被http://www.adarson.com/恶意修改.

日志如果有问题,请赐教解决方法!谢谢!
Logfile of HijackThis v1.99.1
Scan saved at 10:50:52, on 05-9-12
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
G:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
C:\Program Files\CNNIC\Cdn\cdnup.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\services\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
G:\popo2004\popo.exe
C:\WINDOWS\System32\dllhost.exe
G:\Program Files\Kingsoft\PowerWord 2005\Xdict.exe
G:\Program Files\sina\Uc\uc.exe
C:\WINDOWS\System32\inetsrv\DavCData.exe
G:\Program Files\Tencent\Qq\Qq.exe
C:\WINDOWS\SYSTEM32\rundll32.exe
G:\PROGRAM FILES\TENCENT\QQ\TIMPLATFORM.EXE
G:\PROGRA~1\KINGSOFT\FASTAI~1\KTENGINE.EXE
G:\PROGRAM FILES\RISING\RAV\Ravmond.exe
G:\PROGRAM FILES\RISING\RAV\RavStub.exe
G:\HijackThis.exe
G:\Program Files\Tencent\Qq\Qq.exe
G:\PROGRAM FILES\TENCENT\TT\TTraveler.exe
c:\program files\MSN Apps\Updater\01.03.0000.1005\zh-cn\msnappau.exe
G:\Program Files\Tencent\Qq\QQexternal.exe
G:\FIREFOX\REDFOX\FIREFOX.EXE

R3 - URLSearchHook: Tencent Url Search Hook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\TBHMAIN.DLL
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 211.152.51.71 www.papasoft.net
O1 - Hosts: 61.145.117.101 www.foxmail.com.cn
O1 - Hosts: 218.108.248.102 soho17976.home.sunbo.net
O1 - Hosts: 202.197.89.67 www.xysm.net
O1 - Hosts: 222.77.177.58 www.17173.com
O1 - Hosts: 64.233.171.105 gmail.google.com
O1 - Hosts: 61.152.188.39 www.redye.net
O1 - Hosts: 209.219.118.162 ww3.myfreshnet.com
O1 - Hosts: 61.190.168.96 www.hl258.com
O1 - Hosts: 216.180.237.90 www.fortune-mails.com
O1 - Hosts: 61.129.33.82 www.cnysoft.com
O1 - Hosts: 66.193.215.3 www.bbnradio.org
O1 - Hosts: 211.152.51.71 www.papasoft.net
O1 - Hosts: 69.56.219.226 no-minimum.realpaid.net
O1 - Hosts: 72.3.131.10 www.sorryeverybody.com
O1 - Hosts: 218.77.121.108 www.people.com.cn
O1 - Hosts: 61.129.44.1 china.alibaba.com
O1 - Hosts: 60.191.9.66 www.flasharea.net
O1 - Hosts: 211.167.74.151 soho17976.sohounite.net
O1 - Hosts: 211.167.74.151 www.sohounite.com
O1 - Hosts: 61.144.235.16 www.newone.com.cn
O1 - Hosts: 218.2.247.67 www.cmbchina.com
O1 - Hosts: 218.107.207.21 www.diy-xiu.com
O1 - Hosts: 61.144.244.14 www.changyuan.com
O1 - Hosts: 211.152.51.42 www.china-jnx.com
O1 - Hosts: 211.152.51.42 www.china-jnx.com
O1 - Hosts: 61.242.253.60 www.skycn.com
O1 - Hosts: 202.102.48.156 www.onlinedown.net
O1 - Hosts: 218.104.130.18 www.g365.net
O1 - Hosts: 218.22.69.22 xz8.2000y.net
O1 - Hosts: 202.103.69.3 www.ejiawang.com
O1 - Hosts: 216.180.251.234 www.getptr.com
O1 - Hosts: 218.17.246.166 info.cmbchina.com
O1 - Hosts: 218.5.76.121 www.0g0g.com
O1 - Hosts: 61.187.135.131 www.changsha.gov.cn
O1 - Hosts: 61.187.64.119 www.ltzw.com
O1 - Hosts: 218.246.32.208 www.luosoft.com
O1 - Hosts: 221.196.89.100 lm525.oicp.net
O1 - Hosts: 210.51.168.24 www.zlroom.com
O1 - Hosts: 202.165.103.210 assistant.3721,com
O1 - Hosts: 61.145.119.108 www.shbusiness.net
O1 - Hosts: 61.132.138.102 www.188shop.com
O1 - Hosts: 222.36.41.193 www.111mm.com
O1 - Hosts: 218.30.97.236 www.jfart.net
O1 - Hosts: 218.108.247.218 my.taobao.com
O1 - Hosts: 61.151.252.173 www.lymobile.com
O1 - Hosts: 211.196.154.223 www.fda.gov
O1 - Hosts: 211.157.25.132 www.hexun.com
O1 - Hosts: 211.100.15.74 www.ssitmc.com
O1 - Hosts: 210.51.8.60 www.phoenixtv.com
O1 - Hosts: 202.108.39.239 popo.163.com
O1 - Hosts: 61.172.200.165 www.xy19.com
O1 - Hosts: 220.165.143.7 www.netbei.com
O1 - Hosts: 61.129.33.150 download.jz173.com
O1 - Hosts: 218.22.69.24 xz1.2000y.net
O1 - Hosts: 218.109.14.196 bxtyz.home.bj001.net
O1 - Hosts: 61.187.64.118 www.efz.com.cn
O1 - Hosts: 219.129.20.206 www.cat898.com
O1 - Hosts: 219.129.20.228 club.cat898.com
O1 - Hosts: 61.139.126.6 www.tangyj.com
O1 - Hosts: 222.77.176.13 www.fjtc.com.cn
O1 - Hosts: 218.201.44.205 w2620.s4.come.com.cn
O1 - Hosts: 202.128.227.99 www.info.gov.hk
O1 - Hosts: 61.132.138.107 jintian.w11.dvbbs.net
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 207.46.130.104 windows.microsoft.com
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 207.46.245.92 www.microsoft.com
O1 - Hosts: 67.15.12.38 www.beezyclickin.com
O1 - Hosts: 67.18.50.146 www.sosocash.com
O1 - Hosts: 65.98.59.194 www.tigercashmail.com
O1 - Hosts: 72.9.232.170 www.integritypaidemails.com
O1 - Hosts: 66.246.178.176 www.nike-cash.com
O1 - Hosts: 205.214.85.184 www.iglobaltraffic.com
O1 - Hosts: 65.254.51.90 www.500cents-500dollars.com
O1 - Hosts: 64.191.80.85 www.oursharedsuccess.com
O1 - Hosts: 65.98.68.10 www.girlsmails.com
O1 - Hosts: 216.180.237.90 www.fortune-mails.com
O1 - Hosts: 65.254.62.194 ahacash.com
O1 - Hosts: 67.19.164.228 www.lemon-cash.com
O1 - Hosts: 67.19.164.228 www.twodollarsmail.com
O1 - Hosts: 193.138.204.70 worldwide-cash.net
O1 - Hosts: 69.93.165.2 www.carolina-clicks.com
O1 - Hosts: 67.19.103.42 www.1-800-mail.com
O1 - Hosts: 65.98.55.138 penny-rain.com
O1 - Hosts: 67.18.157.194 www.clockwork-payouts.com
O1 - Hosts: 193.138.204.132 www.no-minimum.com
O1 - Hosts: 63.247.93.106 explorer.z-cash.net
O1 - Hosts: 70.84.105.100 www.10dollars-mails.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\新陆建ㄎ文募件夹? (4)\Adobe\Reader\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: IDDTInitObj Class - {15DDE989-CD45-4561-BF99-D22C0D5C2B74} - G:\PROGRA~1\SINA\UC\UCDDT\DDTINIT.DLL
O2 - BHO: CNNIC_IDN - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O2 - BHO: MMSAssist - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O2 - BHO: KillObj Class - {66C28884-4E5D-494B-80C9-CAA27528FD6D} - G:\PROGRA~1\SINA\UC\UCDDT\DDTKILLW.OCX
O2 - BHO: std software - {6A512BF7-EC78-4e8d-9841-6C02E8FA9838} - C:\WINDOWS\System32\stdup.dll
O2 - BHO: HDTBHO Class - {70B3DA2C-E02D-4ce0-B1F8-48320FD443D2} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\T2BHO.DLL
O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - G:\PROGRAM FILES\FLASHGET\JCCATCH.DLL
O2 - BHO: (no name) - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\System32\porynt.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.4000.1001\ZH-CN\MSNTB.DLL
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - G:\TEMP\NAV\NavShExt.dll (file missing)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - (no file)
O2 - BHO: InsIII - {DDDE2452-AF9E-4577-AE6C-465DBCB54D49} - C:\WINDOWS\System32\opngl16.dll
O3 - Toolbar: 金山快译(&K) - {6C3797D2-3FEF-4cd4-B654-D3AE55B4128C} - G:\Program Files\Kingsoft\FastAIT 2005\IEBand.dll
最后编辑2005-09-12 12:50:26
分享到:
gototop
 

O3 - Toolbar: 天下搜索 - {56A7DC70-E102-4408-A34A-AE06FEF01586} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\IEBAR.DLL
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - G:\PROGRAM FILES\FLASHGET\FGIEBAR.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.4000.1001\ZH-CN\MSNTB.DLL
O3 - Toolbar: Dutchemails.com - {403BF536-AF29-4b3e-826B-02A7BFA4BB05} - C:\Program Files\Internet Explorer\PLUGINS\toolbar541461.dll
O3 - Toolbar: MistyAndSamsCash - {85DCC95B-79C5-4988-921C-933ACBF88599} - C:\Program Files\Internet Explorer\PLUGINS\toolbar827328.dll
O3 - Toolbar: 新浪点点通 - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - G:\PROGRA~1\SINA\UC\UCDDT\DDTONG~1.DLL
O3 - Toolbar: 百度超级搜霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRAM FILES\BAIDU\BAR\BAIDUBAR.DLL
O3 - Toolbar: 完美网译通 - {F43BD772-ABDD-43b7-A96A-3E9E61946EC0} - C:\WINDOWS\WORLD2\TOOLBAR\hmtoolbar.dll
O3 - Toolbar: 电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [RavTimer] G:\PROGRA~1\RISING\RAV\RAVTIMER.EXE
O4 - HKLM\..\Run: [RavMon] G:\PROGRA~1\RISING\RAV\RAVMON.EXE -SYSTEM
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB PC Camera 301P
O4 - HKLM\..\Run: [popo2004] G:\popo2004\Start.exe
O4 - HKLM\..\Run: [renewup] C:\Program Files\CNNIC\Cdn\cdnrenew.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [winservice] C:\WINDOWS\services\svchost.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: 金山词霸 2005.lnk = G:\Program Files\Kingsoft\PowerWord 2005\XDICT.EXE
O4 - Global Startup: 新浪UC.lnk = G:\Program Files\sina\UC\uc.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: 腾讯QQ.lnk = G:\Program Files\Tencent\QQ\QQ.EXE
O4 - Global Startup: 桌面传媒.lnk = C:\WINDOWS\SYSTEM32\rundll32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item:  >> 彩信发送 << - res://C:\Program Files\MMSAssist\MMSAssist.dll/mms.htm
O8 - Extra context menu item: !搜一搜 - res://C:\WINDOWS\DOWNLO~1\CnsMinEx.dll/1003
O8 - Extra context menu item: 使用彩信超级自写发送到手机 - http://mms.sina.com.cn/mmsnews.html
O8 - Extra context menu item: 使用新浪下载助手下载 - G:\PROGRA~1\SINA\UC\UCDDT\sinadl.htm
O8 - Extra context menu item: 使用网际快车下载 - G:\PROGRAM FILES\FLASHGET\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - G:\PROGRAM FILES\FLASHGET\jc_all.htm
O8 - Extra context menu item: 发送图片到手机(&M) - http://sms.sina.com.cn/diy/send.html?from=467
O8 - Extra context menu item: 收藏此页到ViVi - http://vivi.sina.com.cn/collect/click.php?agent=ddt
O8 - Extra context menu item: 收藏此页到新浪ViVi - http://vivi.sina.com.cn/collect/click.php?agent=ddt
O8 - Extra context menu item: 新浪搜索 - http://cha.sina.com.cn/ddt.html
O8 - Extra context menu item: 添加到QQ自定义面板 - G:\Program Files\Tencent\Qq\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - G:\Program Files\Tencent\Qq\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - G:\Program Files\Tencent\Qq\SendMMS.htm
O9 - Extra button: 手机短信 - {00000000-0000-0001-0001-596BAEDD1289} - http://sms.3721.com/ie/index.htm (file missing)
O9 - Extra button: 完美卸载 - 清理上网垃圾,包括缓存,CookIE等 - {06926B30-424E-4f1c-8EE3-543CD96573DC} - G:\UNINSTALL\IEBUTTON.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java 控制台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: 新浪UC - {2253922F-1B26-4C74-8B57-E3AEE748DBB8} - G:\Program Files\sina\UC\UC.exe
O9 - Extra button: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra 'Tools' menuitem: 中文上网 - {35980F6E-A137-4E50-953D-813BB8556899} - C:\PROGRA~1\CNNIC\Cdn\cdniehlp.dll
O9 - Extra button: Yahoo 1G电邮 - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.mail.yahoo.com/promo/rd1 (file missing)
O9 - Extra button: 寻宝乐趣多 - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://hot.3721.com/rd/shop_btn.htm (file missing)
O9 - Extra button: 上网助手 - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://assistant.3721.com/index.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O9 - Extra 'Tools' menuitem: MMSAssist工具条设置 - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\MMSASS~1.DLL
O9 - Extra button: MyIM音乐随心听 - {98C3FD76-B058-474F-BB61-70ED205F7A5C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: MyIM音乐随心听 - {98C3FD76-B058-474F-BB61-70ED205F7A5C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Dutchemails.com - {AE818C9D-7289-450c-80DE-B31FCAD3722C} - C:\Program Files\Internet Explorer\PLUGINS\toolbar541461.dll
O9 - Extra 'Tools' menuitem: Dutchemails.com - {AE818C9D-7289-450c-80DE-B31FCAD3722C} - C:\Program Files\Internet Explorer\PLUGINS\toolbar541461.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - G:\PROGRAM FILES\TENCENT\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - G:\PROGRAM FILES\TENCENT\QQ\QQ.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - G:\PROGRAM FILES\FLASHGET\FLASHGET.EXE
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - G:\PROGRAM FILES\FLASHGET\FLASHGET.EXE
O9 - Extra button: 情景聊天 - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 修复浏览器 - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://assistant.3721.com/security1.htm?fb=Cns (file missing)
O9 - Extra button: 新浪点点通 - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - G:\PROGRA~1\SINA\UC\UCDDT\DDTONG~1.DLL
O9 - Extra button: MistyAndSamsCash - {FBFD8C12-7530-4f0b-8E0A-8EEB4A3D503F} - C:\Program Files\Internet Explorer\PLUGINS\toolbar827328.dll
O9 - Extra 'Tools' menuitem: MistyAndSamsCash - {FBFD8C12-7530-4f0b-8E0A-8EEB4A3D503F} - C:\Program Files\Internet Explorer\PLUGINS\toolbar827328.dll
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra 'Tools' menuitem: 清理上网记录 - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://assistant.3721.com/clean1.htm?fb=Cns (file missing)
O9 - Extra button: (no name) - {974AD624-EA50-4831-A6C0-3040F6665396} - G:\PROGRAM FILES\SINA\UC\UCDDT\RSSBAND.DLL (HKCU)
O9 - Extra 'Tools' menuitem: 新浪点点通阅读器 - {974AD624-EA50-4831-A6C0-3040F6665396} - G:\PROGRAM FILES\SINA\UC\UCDDT\RSSBAND.DLL (HKCU)
O9 - Extra button: 新浪点点通阅读器 - {F0646DC8-58CD-4C64-8F6B-525043914685} - G:\PROGRAM FILES\SINA\UC\UCDDT\RSSBAND.DLL (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdnns.dll
O11 - Options group: [!CNS]  网络实名
O11 - Options group: [CDNCLIENT]  中文上网
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} (Edit Class) - https://www.sz1.cmbchina.com/download/CMBEdit.cab
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} (天下搜索) - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125757284828
O16 - DPF: {733652F9-53EF-4BF1-B391-375980675D6F} (V3PROXL Control) - http://scan.online.cq.cn/plugin/myv3light.cab
O16 - DPF: {ACFE8232-03C5-4AEC-AF5E-42B806724096} (KSHScan Control) - http://scan.kingsoft.com/scan/fangyi/KAllScan.CAB
O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - http://bar.baidu.com/update/IESearch.cab
O16 - DPF: {C8BD9ACB-F7EC-48E6-BB2F-DAADC6789E9A} (Kingsoft DUBA OnlineScan) - http://ol.db.kingsoft.com/antiscan/setup/KAVClean.CAB
O16 - DPF: {CF051549-EDE1-40F5-B440-BCD646CF2C25} (Ppinstall Control) - http://popo.163.com/install/ppinstall.cab
O16 - DPF: {D0A29C6C-AA71-4423-8C4A-5998B774C448} (IEDown Class) - http://download.ourgame.com/IEDown2.cab
O16 - DPF: {DA984A6D-508E-11D6-AA49-0050FF3C628D} (Ravonline) - http://download.rising.com.cn/QQ/QQkill/rsonline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{754FDC17-C0BE-4242-8BEC-C67AB27D8001}: Domain = 5
O17 - HKLM\System\CCS\Services\Tcpip\..\{754FDC17-C0BE-4242-8BEC-C67AB27D8001}: NameServer = 202.197.89.69
O17 - HKLM\System\CS1\Services\Tcpip\..\{754FDC17-C0BE-4242-8BEC-C67AB27D8001}: Domain = 5
O17 - HKLM\System\CS1\Services\Tcpip\..\{754FDC17-C0BE-4242-8BEC-C67AB27D8001}: NameServer = 202.197.89.69
O17 - HKLM\System\CS2\Services\Tcpip\..\{754FDC17-C0BE-4242-8BEC-C67AB27D8001}: Domain = 5
O17 - HKLM\System\CS2\Services\Tcpip\..\{754FDC17-C0BE-4242-8BEC-C67AB27D8001}: NameServer = 202.197.89.69
O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\SYSTEM32\mbprot.dll
O18 - Protocol: mbox - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\SYSTEM32\mbprot.dll
O18 - Filter: text/html - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\System32\porynt.dll
O18 - Filter: text/plain - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\System32\porynt.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - G:\PROGRAM FILES\RISING\RAV\Ravmond.exe

gototop
 

谢谢
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT