高人帮我看一下日志启动总是弹出窗口谢谢★★★

启动IE总是弹出如下2个窗口:
1.http://221.204.254.166/index.html——病毒网站!
2.http;//www.94lm.com/index.html——手机铃声下载网站!
而且不明白为啥会出现第17项中的IP地址,是谁让它们写入注册表的,不解!


HijackThis_815汉化版扫描日志 V1.99.1
保存于      0:51:02, 日期 2006-4-18
操作系统:  Windows 2003 SP1 (WinNT 5.02.3790)
浏览器:    Internet Explorer v6.00 SP1 (6.00.3790.1830)

当前运行的进程:         
F:\WINNT\System32\smss.exe
F:\WINNT\system32\winlogon.exe
F:\WINNT\system32\services.exe
F:\WINNT\system32\lsass.exe
F:\WINNT\system32\svchost.exe
F:\Program Files\rising\Rav\CCenter.exe
F:\Program Files\rising\Rav\Ravmond.exe
F:\WINNT\System32\svchost.exe
f:\program files\rising\rfw\rfwsrv.exe
F:\WINNT\system32\spoolsv.exe
F:\WINNT\System32\snmp.exe
F:\WINNT\System32\svchost.exe
F:\WINNT\Explorer.EXE
F:\WINNT\soundman.exe
F:\WINNT\system32\ctfmon.exe
f:\program files\rising\rfw\RfwMain.exe
F:\WINNT\System32\svchost.exe
F:\Program Files\FlashGet\flashget.exe
F:\Program Files\Maxthon\Maxthon.exe
F:\WINNT\system32\conime.exe
F:\Program Files\WinRAR\WinRAR.exe
F:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.969\HijackThis\HijackThis-CN.exe

O2 - BHO: SnapFlash Class - {A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E} - F:\Program Files\Common Files\justDo\Jd2002.dll
O3 - IE工具栏增项: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - F:\PROGRA~1\FLASHGET\fgiebar.dll
O4 - 启动项HKLM\\Run: [IMJPMIG8.1] "F:\WINNT\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - 启动项HKLM\\Run: [IMEKRMIG6.1] F:\WINNT\ime\imkr6_1\IMEKRMIG.EXE
O4 - 启动项HKLM\\Run: [SoundMan] SOUNDMAN.EXE
O4 - 启动项HKLM\\Run: [PHIME2002ASync] F:\WINNT\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 启动项HKLM\\Run: [PHIME2002A] F:\WINNT\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 启动项HKLM\\Run: [MSPY2002] F:\WINNT\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINNT\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - F:\Program Files\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - F:\Program Files\FlashGet\jc_all.htm
O8 - IE右键菜单中的新增项目: 用 Flash 抓捕器保存 Flash - res://C:\Program Files\Common Files\justDo\IECatcher.DLL/FlashCatcher.htm
O9 - 浏览器额外的按钮: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\WINNT\System32\msjava.dll
O9 - 浏览器额外的“工具”菜单项: Sun Java 控制台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\WINNT\System32\msjava.dll
O9 - 浏览器额外的按钮: Flash 抓捕器 - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - F:\Program Files\Common Files\justDo\IECatcher.DLL
O9 - 浏览器额外的“工具”菜单项: Flash 抓捕器 - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - F:\Program Files\Common Files\justDo\IECatcher.DLL
O9 - 浏览器额外的按钮: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - F:\PROGRA~1\FLASHGET\flashget.exe
O9 - 浏览器额外的“工具”菜单项: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - F:\PROGRA~1\FLASHGET\flashget.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1142399370703
O17 - HKLM\System\CCS\Services\Tcpip\..\{6CF3E7C9-EE5E-455D-B35D-10F4DA941495}: NameServer = 202.99.192.66 202.99.192.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{6CF3E7C9-EE5E-455D-B35D-10F4DA941495}: NameServer = 202.99.192.66 202.99.192.68
O18 - 列举现有的协议: dynascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - F:\WINNT\system32\mshtml.dll
O20 - Winlogon Notify: dimsntfy - F:\WINNT\SYSTEM32\dimsntfy.dll
O23 - NT 服务: AutoComplete Service (Autocomplete) - Acesoft - F:\Program Files\Tracks Eraser Pro\autocomp.exe
O23 - NT 服务: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - f:\program files\rising\rfw\rfwproxy.exe
O23 - NT 服务: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - f:\program files\rising\rfw\rfwsrv.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - F:\Program Files\rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - F:\Program Files\rising\Rav\Ravmond.exe

最后编辑2006-04-18 01:32:22