HijackThis_zww汉化版扫描日志 V1.99.1
保存于 11:09:54, 日期 2006-1-15
操作系统: Windows XP SP1 (WinNT 5.01.2600)
浏览器: Internet Explorer v6.00 SP1 (6.00.2800.1106)
当前运行的进程:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
E:\装机软件\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
E:\装机软件\Rav\Ravmond.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
E:\装机软件\Rav\RavStub.exe
E:\装机软件\Rav\RavTask.exe
E:\装机软件\Rav\Ravmon.exe
C:\WINDOWS\System32\ctfmon.exe
E:\TT\TTraveler.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\HijackThis1991zww.exe
R3 - 默认的URLSearchHook丢失。用HijackThis修复
O2 - BHO: ThunderIEHelper Class - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v6.dll
O2 - BHO: QQBrowserHelper
Object Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - E:\Program Files\QQIEHelper.dll
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - E:\PROGRA~1\KuGoo2\KUGOO3~1.OCX
O3 - IE工具栏增项: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\assist\asbar.dll (file missing)
O3 - IE工具栏增项: 超级兔子上网精灵 - {FEDF637B-F631-4583-A210-33CC828D42DB} - E:\PROGRA~1\MagicSet\HAOKAN~1.DLL
O4 - 启动项HKLM\\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [RavTask] "E:\装机软件\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DreamPlayer] "C:\Program Files\PowerInfo\DreamPlayer\DreamPlayer.exe" /i
O8 - IE右键菜单中的新增项目: &使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\geturl.htm
O8 - IE右键菜单中的新增项目: &使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\getAllurl.htm
O8 - IE右键菜单中的新增项目: 使用KuGoo3下载(&K) - E:\Program Files\KuGoo2\KuGoo3DownX.htm
O9 - 浏览器额外的按钮: 红心游戏 - {00000000-DAEB-480d-867B-D746D955765B} - E:\游戏\redheart\GameHall.exe
O9 - 浏览器额外的“工具”菜单项: 红心游戏世界 - {00000000-DAEB-480d-867B-D746D955765B} - E:\游戏\redheart\GameHall.exe
O9 - 浏览器额外的按钮: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - 浏览器额外的“工具”菜单项: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O14 - IERESET.INF: START_PAGE_URL=
about:blank
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAccessVerisign/ie/bridge-c18.cab
O16 - DPF: {448A5F6B-8C03-4B54-A338-F00237C508AD} - http://www.51uc.com/cab/WEBChatRoom_1_39.cab
O16 - DPF: {98A62E3F-A8C5-4EF0-8A00-C70CF9D18A89} (LoaderCore Class) - http://tb.sogou.com/DLLoader.cab
O16 - DPF: {CA828031-4325-11D4-BDB2-00105A776E78} (SMI MapView Control) - http://www.qdfd.com.cn/gisnew/smiwmap.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} (WMService Class) - http://download.overpro.com/WildAppNonUS.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{32881207-93D8-4708-B01B-50701F5E3AD2}: NameServer = 202.102.128.68 202.102.134.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{C68052AF-1DE9-4294-ACC5-B30269309523}: NameServer = 211.97.168.129
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - NT 服务: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\G_Server.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - E:\装机软件\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - E:\装机软件\Rav\Ravmond.exe
“O23 - NT 服务: Gray_Pigeon_Server (GrayPigeonServer) - Unknown owner - C:\WINDOWS\G_Server.exe”修了一下不管用!
可是在windows里没找到G_Server.exe文件呀?在注册表里搜到了关于“GrayPigeonServer”一项还提示删不掉!肯定还有什么.dll文件没找到!俺不是高手,系统里文件太多,不知道哪个.dll是有毒的呀?咋办?只找到一个server.dll删了。以上都是在安全模式进行的!